A-A+
cisco路由器的源地址、目标地址转换的具体案例
几台思科路由器组成一个链式的网络,中间两台双向NAT路由器,就需要把源地址和目标地址进行转换,下面是具体的配置案例,从中可以学到一些新知识。这类ip地址转换的方法,现实的机房维护工作会非常经常的用到的。
- interface Ethernet0/0
- ip address 12.1.1.2 255.255.255.0
- ip nat outside
- ip virtual-reassembly
- half-duplex
- !
- interface Ethernet0/1
- ip address 25.1.1.2 255.255.255.0
- ip nat inside
- ip virtual-reassembly
- full-duplex
- !
- interface Ethernet0/2
- no ip address
- shutdown
- half-duplex
- !
- interface Ethernet0/3
- no ip address
- shutdown
- half-duplex
- !
- no ip http server
- no ip http secure-server
- !
- ip forward-protocol nd
- ip route 25.1.1.88 255.255.255.255 12.1.1.1 //此为重点,配置目标地址NAT的路由指向转换目的的方向
- ip route 172.16.1.0 255.255.255.0 25.1.1.5
- ip route 172.16.2.0 255.255.255.0 25.1.1.5
- ip route 172.16.3.0 255.255.255.0 25.1.1.5
- ip route 192.168.1.1 255.255.255.255 12.1.1.1
- !
- ip nat inside source list 1 interface Ethernet0/0 overload//源地址NAT
- ip nat outside source static tcp 192.168.1.1 23 25.1.1.88 6501 extendable//目标地址NAT,将访问25.1.1.88目标地址的流量转换为192.168.1.1
- !
- access-list 1 permit 172.16.1.0 0.0.0.255
- access-list 1 permit 172.16.2.0 0.0.0.255
- access-list 1 permit 172.16.3.0 0.0.0.255