靜態NAT+動態NAT+PAT配置服務器
拓撲圖網絡
整體配置:ide
配置路由器ip地址及實現外網互通測試
Router0spa
Router>enableorm
Router#confrouter
Router(config)#int f0/0server
Router(config-if)#ip address 192.168.1.1 255.255.255.0xml
Router(config-if)#no shutdownblog
Router(config-if)#int s2/0
Router(config-if)#ip address 192.168.2.1 255.255.255.0
Router(config-if)#clock rate 128000
Router(config-if)#no shutdown
Router(config)#
Router(config)#router rip
Router(config-router)#version 2
Router(config-router)#network 192.168.2.0
Router(config-router)#exit
Router1配置
Router>enable
Router#conf
Router(config)#int f0/0
Router(config-if)#ip address 192.168.3.1 255.255.255.0
Router(config-if)#no shutdown
Router(config-if)#int s2/0
Router(config-if)#ip address 192.168.2.2 255.255.255.0
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#router rip
Router(config-router)#version 2
Router(config-router)#network 192.168.2.0
Router(config-router)#network 192.168.3.0
Router(config-router)#exit
客戶端IP配置如圖
服務器IP地址分配
www服務器配置
客戶機測試
pc2 IP配置
如今測試server1 ping pc2
PC>ping 192.168.1.2
Pinging 192.168.1.2 with 32 bytes of data:
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
能夠看出是不通的
1>>>>靜態NAT代碼配置
要求:將服務器的IP地址映射到路由器192.168.2.1端口上,路由器3至關於外部網絡
在router1上配置以下
Router(config-router)#ip nat inside source static 192.168.1.2 192.168.2.1
Router(config)#int f0/0
Router(config-if)#ip nat inside
Router(config-if)#int s2/0
Router(config-if)#ip nat outside
測試
2>>>>>動態nat配置
如今在router1上配置動態nat,使內網能夠ping通外網,但外網不能ping通內網
Router(config)#ip nat pool nat 192.168.2.3 192.168.2.6 netmask 255.255.255.0
Router(config)#ip nat inside source list 1 pool nat
Router(config)#access-list 1 permit 192.168.1.0 0.0.0.255
Router(config)#int f0/0
Router(config-if)#ip nat inside
Router(config-if)#int s2/0
Router(config-if)#ip nat outside
Router(config-if)#exit
Router(config)#
測試
server1 ping pc2
PC>ping 192.168.3.2
Pinging 192.168.3.2 with 32 bytes of data:
Reply from 192.168.3.2: bytes=32 time=78ms TTL=126
Reply from 192.168.3.2: bytes=32 time=94ms TTL=126
Reply from 192.168.3.2: bytes=32 time=94ms TTL=126
Reply from 192.168.3.2: bytes=32 time=93ms TTL=126
pc2 ping server1
PC>ping 192.168.1.2
Pinging 192.168.1.2 with 32 bytes of data:
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
測試成功
3>>>>>PAT配置
如今在router1上配置PAT,使內網能夠ping通外網,但外網不能ping通內網
Router#
Router#conf
Router(config)#ip nat pool nat 192.168.2.3 192.168.2.5 netmask 255.255.255.0
Router(config)#ip nat inside source list 1 pool nat overload
Router(config)#access-list 1 permit 192.168.1.0 0.0.0.255
Router(config)#int f0/0
Router(config-if)#ip nat inside
Router(config-if)#int s2/0
Router(config-if)#ip nat outside
Router(config-if)#exit
Router(config)#end
測試
server1 ping pc2
PC>ping 192.168.3.2
Pinging 192.168.3.2 with 32 bytes of data:
Reply from 192.168.3.2: bytes=32 time=78ms TTL=126
Reply from 192.168.3.2: bytes=32 time=94ms TTL=126
Reply from 192.168.3.2: bytes=32 time=94ms TTL=126
Reply from 192.168.3.2: bytes=32 time=93ms TTL=126
pc2 ping server1
PC>ping 192.168.1.2
Pinging 192.168.1.2 with 32 bytes of data:
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
Reply from 192.168.3.1: Destination host unreachable.
測試成功