码迷,mamicode.com
首页 > 其他好文 > 详细

动态PNAT配置

时间:2018-01-13 11:15:51      阅读:218      评论:0      收藏:0      [点我收藏+]

标签:tar   1.2   ip nat   config   one   toc   turn   内网地址   end   

实验名称:思科路由动态PNAT配置
实验拓扑:
实验环境:1、3台路由器,
2、一台交换机
Router 0 边界路由器(内网和外网)
Router 1 边界路由器(公网的内网和外网)
Pouter 2 内网路由器 (公网的内部网络)
3、两台PC
Pc2 pc3

实验思路:先把三台路由器的地址配置好,
Router0 g0/0口是内网网关 192.168.1.254/24
Router0 g0/1口是公网地址 100.1.1.1/24

                                 Router1   g0/0是公网外网地址 100.1.1.2/24
                                 Router1   g0/1 是公网内网网关 200.1.1.1/24

                                 Router2 g0/0 是公网内网地址  200.1.1.2/24

实验步骤:
1、 配置PC机地址:
Pc2:
IP : 192.168.10.1/24
网关:192.168.10.254
Pc3
IP : 192.168.10.2/24
网关:192.168.10.254
2、 配置Router 0
Continue with configuration dialog? [yes/no]: no

Press RETURN to get started!

Router>enable
Router#
Router#configure
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int g0/0
Router(config-if)#no shtdown
^
% Invalid input detected at ‘^‘ marker.
Router(config-if)#
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up

Router(config-if)#ip address 192.168.10.254 255.255.255.0
Router(config-if)#e
Router(config)#int g0/1
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to up

Router(config-if)#ip address 100.1.1.1 255.255.255.0
Router(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to up

Router(config-if)#e
Router(config)#int g0/0
Router(config-if)#ip nat i
Router(config-if)#ip nat inside
Router(config-if)#e
Router(config)#int g0/1
Router(config-if)#ip nat o
Router(config-if)#ip nat outside
Router(config-if)#
Router(config-if)#
Router(config-if)#
Router(config-if)#e
Router(config)#
Router(config)#
Router(config)#
Router(config)#
Router(config)#acce
Router(config)#access-list 1 p
Router(config)#access-list 1 permit 192.168.10.0 0.0.0.255
Router(config)#ip nat i
Router(config)#ip nat inside s
Router(config)#ip nat inside source l
Router(config)#ip nat inside source list 1 interface g0/1
Router(config)#
Router(config)#
Router(config)#ip route 0.0.0.0 0.0.0.0 100.1.1.2
Router(config)#
3、 配置Router1
Continue with configuration dialog? [yes/no]: no

Press RETURN to get started!

Router>enable
Router#configure
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int g0/0
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up

Router(config-if)#ip address 100.1.1.2 255.255.255.0
Router(config-if)#e
Router(config)#int g0/1
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to up

Router(config-if)#ip address 200.1.1.1 255.255.255.0
Router(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to up

Router(config-if)#
Router(config-if)#e
Router(config)#route rip
Router(config-router)#version 2
Router(config-router)#no auto-summary
Router(config-router)#network 200.1.1.0
Router(config-router)#network 100.1.1.0
Router(config-router)#p
Router(config-router)#passive-interface g0/0
Router(config-router)#
4、 配置Router 2
Continue with configuration dialog? [yes/no]: no

Press RETURN to get started!

Router>enable
Router#configure
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int g0/0
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up

Router(config-if)#ip address 200.1.1.2 255.255.255.0
Router(config-if)#e
Router(config)#route rip
Router(config-router)#version 2
Router(config-router)#no auto-summary
Router(config-router)#network 200.1.1.0
Router(config-router)#
5、验证思路:
全部配置好先ping自己的网关在一步一步ping到公网的内网

动态PNAT配置

标签:tar   1.2   ip nat   config   one   toc   turn   内网地址   end   

原文地址:http://blog.51cto.com/13467772/2060476

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!