1 案例:静态NAT 配置
1.1 问题
将内部地址10.1.1.11、10.1.1.12静态转换为公网地址200.1.1.11、200.1.1.12,以便访问外网(Server1)或被外网(Server1)访问,并抓包分析
验证静态NAT是双向转换
1.2 方案
搭建实验环境,如图-1所示。
图-1
1.3 步骤
实现此案例需要按照如下步骤进行。[hidecontent type=”payshow”]
- Server2:
- 10.1.1.11
- 255.255.255.0
- 10.1.1.254
- Server3:
- 10.1.1.12
- 255.255.255.0
- 10.1.1.254
- <Huawei>undo terminal
- <Huawei>system–view
- [Huawei]sysname SW
- [SW]vlan 10 // 创建 VLAN 10
- [SW–vlan10]quit
- [SW]interface gi0/0/3 // 连接内网 R1的接口
- [SW–GigabitEthernet0/0/3]port link access
- [SW–GigabitEthernet0/0/3]port default vlan 10
- [SW–GigabitEthernet0/0/3]quit
- [SW]interface gi0/0/12 // 连接内网 Server-2的接口
- [SW–GigabitEthernet0/0/12]port link access
- [SW–GigabitEthernet0/0/12]port default vlan 10
- [SW–GigabitEthernet0/0/12]quit
- [SW]interface gi0/0/13 // 连接内网 Server-3的接口
- [SW–GigabitEthernet0/0/13]port link access
- [SW–GigabitEthernet0/0/13]port default vlan 10
- [SW–GigabitEthernet0/0/13]quit
- <Huawei>undo terminal
- <Huawei>system–view
- [Huawei]sysname R1
- [R1]interface gi0/0/0 // 连接内网的接口
- [R1–GigabitEthernet0/0/0]ip address 10.1.1.254 24
- [R1–GigabitEthernet0/0/0]quit
- [R1]interface gi0/0/1 // 连接外网的接口
- [R1–GigabitEthernet0/0/1]ip address 200.1.1.13 28
- [R1–GigabitEthernet0/0/1]quit
- [R1]ip route–static 0.0.0.0 0 200.1.1.14 // 去往外网的默认路由
- Server1:
- 210.1.1.1
- 255.255.255.0
- 210.1.1.254
- <Huawei>undo terminal
- <Huawei>system–view
- [Huawei]sysname R2
- [R2]interface gi0/0/0 // 连接Server-1的接口
- [R2–GigabitEthernet0/0/0]ip address 210.1.1.254 24
- [R2–GigabitEthernet0/0/0]quit
- [R2]interface gi0/0/1 // 连接外网的接口
- [R2–GigabitEthernet0/0/1]ip address 200.1.1.14 28
- [R2–GigabitEthernet0/0/1]quit
- [R1]interface GigabitEthernet 0/0/1
- [R1–GigabitEthernet0/0/1]nat static global 200.1.1.11 inside 10.1.1.11
- [R1–GigabitEthernet0/0/1]nat static global 200.1.1.12 inside 10.1.1.12
图-2
分别在Server2和Server3上ping Server1可以通
在路由器G0/0/1口抓包,源地址已做转换,如图-3所示
Server1 ping Server2(200.1.1.11)能通,说明静态NAT是双向的
在R1 Gi0/0/0 口抓包,目的地址已做转换,如图-4所示
图-4
2 案例:动态NAT配置
2.1 问题
将内部网络 10.1.1.0/24 转换为公网地址 200.1.1.1 ~ 200.1.1.11/28 上网(访问Server-1)
2.2 方案
搭建实验环境,如图-2所示。
图-2
2.3 步骤
实现此案例需要按照如下步骤进行。
- 地址:10.1.1.1
- 掩码:255.255.255.0
- 网关:10.1.1.254
- 地址:10.1.1.2
- 掩码:255.255.255.0
- 网关:10.1.1.254
- <Huawei>system–view
- [Huawei]sysname SW1
- [SW1] vlan 10
- [SW1–vlan10]quit
- [SW1]interface GigabitEthernet0/0/1
- [SW1–GigabitEthernet0/0/1] port link–type access
- [SW1–GigabitEthernet0/0/1] port default vlan 10
- [SW1–GigabitEthernet0/0/1] quit
- [SW1]interface GigabitEthernet0/0/2
- [SW1–GigabitEthernet0/0/2] port link–type access
- [SW1–GigabitEthernet0/0/2] port default vlan 10
- [SW1–GigabitEthernet0/0/2] quit
- [SW1]interface GigabitEthernet0/0/3
- [SW1–GigabitEthernet0/0/3] port link–type access
- [SW1–GigabitEthernet0/0/3] port default vlan 10
- [SW1–GigabitEthernet0/0/3] quit
- <Huawei>system–view
- [Huawei]sysname R1
- [R1]interface GigabitEthernet0/0/0
- [R1–GigabitEthernet0/0/0] ip address 10.1.1.254 255.255.255.0
- [R1–GigabitEthernet0/0/0] quit
- [R1]interface GigabitEthernet0/0/1
- [R1–GigabitEthernet0/0/1] ip address 200.1.1.13 255.255.255.240
- [R1–GigabitEthernet0/0/1] quit
- [R1] ip route–static 0.0.0.0 0.0.0.0 200.1.1.14
- [R1]acl 2000
- [R1–acl–basic-2000] rule 10 permit source 10.1.1.0 0.0.0.255
- [R1–acl–basic-2000] quit
- [R1] nat address–group 1 200.1.1.1 200.1.1.10
- [R1]interface GigabitEthernet0/0/1
- [R1–GigabitEthernet0/0/1] nat outbound 2000 address–group 1 no–pat
- [R1–GigabitEthernet0/0/1] quit
- <Huawei>system–view
- [Huawei]sysname ISP
- [ISP]interface GigabitEthernet0/0/0
- [ISP–GigabitEthernet0/0/0] ip address 210.1.1.254 255.255.255.0
- [ISP–GigabitEthernet0/0/0] quit
- [ISP]interface GigabitEthernet0/0/1
- [ISP–GigabitEthernet0/0/1] ip address 200.1.1.14 255.255.255.240
- [ISP–GigabitEthernet0/0/1] quit
- 地址 – 210.1.1.1
- 掩码 – 255.255.255.0
- 网关 – 210.1.1.254
- [R1]display nat outbound
- NAT Outbound Information:
- ————————————————————————–
- Interface Acl Address–group/IP/Interface Type
- ————————————————————————–
- GigabitEthernet0/0/2 2000 1 no–pat
- ————————————————————————–
- Total : 1
- [R1]dis nat session all
- NAT Session Table Information:
- Protocol : ICMP(1)
- SrcAddr Vpn : 10.1.1.1
- DestAddr Vpn : 210.1.1.1
- Type Code IcmpId : 0 8 43982
- NAT–Info
- New SrcAddr : 200.1.1.5
- New DestAddr : —-
- New IcmpId : —-
- Total : 1
在路由器R1 的 Gi0/0/1口抓包,源地址已做转换,如图-3所示
图-3
图-4
3 案例:动态PNAT 配置
3.1 问题
公司要求将内部网络10.1.1.0/24转换为一个公网地址200.1.1.10/28上网(访问Server1)
3.2 方案
搭建实验环境,如图-5所示。
图-5
3.3 步骤
实现此案例需要按照如下步骤进行。
- 地址:10.1.1.1
- 掩码:255.255.255.0
- 网关:10.1.1.254
- 地址:10.1.1.2
- 掩码:255.255.255.0
- 网关:10.1.1.254
- <Huawei>system–view
- [Huawei]sysname SW1
- [SW1] vlan 10
- [SW1–vlan10]quit
- [SW1]interface GigabitEthernet0/0/1
- [SW1–GigabitEthernet0/0/1] port link–type access
- [SW1–GigabitEthernet0/0/1] port default vlan 10
- [SW1–GigabitEthernet0/0/1] quit
- [SW1]interface GigabitEthernet0/0/2
- [SW1–GigabitEthernet0/0/2] port link–type access
- [SW1–GigabitEthernet0/0/2] port default vlan 10
- [SW1–GigabitEthernet0/0/2] quit
- [SW1]interface GigabitEthernet0/0/3
- [SW1–GigabitEthernet0/0/3] port link–type access
- [SW1–GigabitEthernet0/0/3] port default vlan 10
- [SW1–GigabitEthernet0/0/3] quit
- <Huawei>system–view
- [Huawei]sysname R1
- [R1]interface GigabitEthernet0/0/0
- [R1–GigabitEthernet0/0/0] ip address 10.1.1.254 255.255.255.0
- [R1–GigabitEthernet0/0/0] quit
- [R1]interface GigabitEthernet0/0/1
- [R1–GigabitEthernet0/0/1] ip address 200.1.1.13 255.255.255.240
- [R1–GigabitEthernet0/0/1] quit
- [R1] ip route–static 0.0.0.0 0.0.0.0 200.1.1.14
- [R1]acl 2000
- [R1–acl–basic-2000] rule 10 permit source 10.1.1.0 0.0.0.255
- [R1–acl–basic-2000] quit
- [R1] nat address–group 1 200.1.1.10 200.1.1.10
- [R1]interface GigabitEthernet0/0/1
- [R1–GigabitEthernet0/0/1] nat outbound 2000 address–group 1
- [R1–GigabitEthernet0/0/1] quit
- <Huawei>system–view
- [Huawei]sysname ISP
- [ISP]interface GigabitEthernet0/0/0
- [ISP–GigabitEthernet0/0/0] ip address 210.1.1.254 255.255.255.0
- [ISP–GigabitEthernet0/0/0] quit
- [ISP]interface GigabitEthernet0/0/1
- [ISP–GigabitEthernet0/0/1] ip address 200.1.1.14 255.255.255.240
- [ISP–GigabitEthernet0/0/1] quit
- 地址 – 210.1.1.1
- 掩码 – 255.255.255.0
- 网关 – 210.1.1.254
- [R1]display nat address–group
- NAT Address–Group Information:
- ————————————–
- Index Start–address End–address
- ————————————–
- 1 200.1.1.10 200.1.1.10
- ————————————–
- Total : 1
- [R1]display nat outbound
- NAT Outbound Information:
- ————————————————————————–
- Interface Acl Address–group/IP/Interface Type
- ————————————————————————–
- GigabitEthernet0/0/1 2000 1 pat
- ————————————————————————–
- Total : 1
在路由器Gi0/0/1口抓包,可以看到源地址已经转换,如图-6所示
图-6
4 案例:Easy IP 配置
4.1 问题
4.2 方案
搭建实验环境,如图-7所示。
图-7
4.3 步骤
实现此案例需要按照如下步骤进行。
- PC-1:
- 10.1.1.1
- 255.255.255.0
- 10.1.1.254
- PC-2:
- 10.1.2.1
- 255.255.255.0
- 10.1.2.254
- PC-3:
- 10.1.3.78
- 255.255.255.0
- 10.1.3.254
- <Huawei>undo terminal monitor
- <Huawei>system–view
- [Huawei]sysname SW
- [SW]vlan batch 10 20 30 66
- [SW]interface gi0/0/1
- [SW–GigabitEthernet0/0/1]port link access
- [SW–GigabitEthernet0/0/1]port default vlan 10
- [SW–GigabitEthernet0/0/1]quit
- [SW]interface GigabitEthernet 0/0/2
- [SW–GigabitEthernet0/0/2]port link access
- [SW–GigabitEthernet0/0/2]port default vlan 30
- [SW–GigabitEthernet0/0/2]quit
- [SW]interface GigabitEthernet 0/0/3
- [SW–GigabitEthernet0/0/3]port default vlan 66
- [SW–GigabitEthernet0/0/3]quit
- [SW]interface GigabitEthernet 0/0/4
- [SW–GigabitEthernet0/0/4]port default vlan 20
- [SW–GigabitEthernet0/0/4]quit
- [SW]interface Vlanif 10
- [SW–Vlanif10]ip address 10.1.1.254 24
- [SW–Vlanif10]quit
- [SW]interface Vlanif 20
- [SW–Vlanif20]ip address 10.1.2.254 24
- [SW–Vlanif20]quit
- [SW]interface Vlanif 30
- [SW–Vlanif30]ip address 10.1.3.254 24
- [SW–Vlanif30]quit
- [SW]interface Vlanif 66
- [SW–Vlanif6]ip address 10.1.66.1 24
- [SW–Vlanif6]quit
- [SW]ip route–static 0.0.0.0 0 10.1.66.254
- <Huawei>undo terminal monitor
- <Huawei>system–view
- [Huawei]sysname R1
- [R1]interface GigabitEthernet 0/0/0
- [R1–GigabitEthernet0/0/0]ip address 10.1.66.254 24
- [R1–GigabitEthernet0/0/0]quit
- [R1]interface GigabitEthernet 0/0/1
- [R1–GigabitEthernet0/0/1]ip address 100.1.1.1 24
- [R1–GigabitEthernet0/0/1]quit
- [R1]ip route–static 0.0.0.0 0 100.1.1.2
- [R1]ip route–static 10.1.1.0 24 10.1.66.1
- [R1]ip route–static 10.1.2.0 24 10.1.66.1
- [R1]ip route–static 10.1.3.0 24 10.1.66.1
- <Huawei>undo terminal monitor
- <Huawei>system–view
- [Huawei]sysname R2
- [R2]interface GigabitEthernet 0/0/0
- [R2–GigabitEthernet0/0/0]ip address 200.1.1.254 24
- [R2–GigabitEthernet0/0/0]quit
- [R2]interface GigabitEthernet 0/0/1
- [R2–GigabitEthernet0/0/1]ip address 100.1.1.2 24
- [R2–GigabitEthernet0/0/1]quit
- Server-1:
- 200.1.1.1
- 255.255.255.0
- 200.1.1.254
- [R1]acl 2000
- [R1–acl–basic-2000]rule 10 permit source 10.1.1.0 0.0.0.255
- [R1–acl–basic-2000]rule 20 deny source 10.1.3.78 0.0.0.0
- [R1–acl–basic-2000]rule 30 permit source 10.1.3.0 0.0.0.255
- [R1–acl–basic-2000]quit
- [R1]interface GigabitEthernet 0/0/1
- [R1–GigabitEthernet0/0/1]nat outbound 2000
- [R1]display nat outbound
- NAT Outbound Information:
- ————————————————————————–
- Interface Acl Address–group/IP/Interface Type
- ————————————————————————–
- GigabitEthernet0/0/1 2000 100.1.1.1 easyip
- ————————————————————————–
- Total : 1
4)PC1/2/3测试与Server-1的互通性,如图-8所示
图-8
5 案例:配置NAT Server
5.1 问题
将内部地址10.1.1.11/24的80端口静态转换为公网地址200.1.1.11的80端口,以便被外网(Client1)访问
将内部地址10.1.1.12/24的21端口静态转换为公网地址200.1.1.11的21端口,以便被外网(Client1)访问
5.2 方案
搭建实验环境,如图-9所示。
图-9
5.3 步骤
实现此案例需要按照如下步骤进行。
- Server2:
- 10.1.1.11
- 255.255.255.0
- 10.1.1.254
- Server3:
- 10.1.1.12
- 255.255.255.0
- 10.1.1.254
- <Huawei>undo terminal
- <Huawei>system–view
- [Huawei]sysname SW
- [SW]vlan 10 // 创建 VLAN 10
- [SW–vlan10]quit
- [SW]interface gi0/0/3 // 连接内网 R1的接口
- [SW–GigabitEthernet0/0/3]port link access
- [SW–GigabitEthernet0/0/3]port default vlan 10
- [SW–GigabitEthernet0/0/3]quit
- [SW]interface gi0/0/12 // 连接内网 Server-2的接口
- [SW–GigabitEthernet0/0/12]port link access
- [SW–GigabitEthernet0/0/12]port default vlan 10
- [SW–GigabitEthernet0/0/12]quit
- [SW]interface gi0/0/13 // 连接内网 Server-3的接口
- [SW–GigabitEthernet0/0/13]port link access
- [SW–GigabitEthernet0/0/13]port default vlan 10
- [SW–GigabitEthernet0/0/13]quit
- <Huawei>undo terminal
- <Huawei>system–view
- [Huawei]sysname R1
- [R1]interface gi0/0/0 // 连接内网的接口
- [R1–GigabitEthernet0/0/0]ip address 10.1.1.254 24
- [R1–GigabitEthernet0/0/0]quit
- [R1]interface gi0/0/1 // 连接外网的接口
- [R1–GigabitEthernet0/0/1]ip address 200.1.1.13 28
- [R1–GigabitEthernet0/0/1]quit
- [R1]ip route–static 0.0.0.0 0 200.1.1.14 // 去往外网的默认路由
- Client-1:
- 1000.1.1.1
- 255.255.255.0
- 100.1.1.254
- <Huawei>undo terminal
- <Huawei>system–view
- [Huawei]sysname R2
- [R2]interface gi0/0/0 // 连接Client-1的接口
- [R2–GigabitEthernet0/0/0]ip address 100.1.1.254 24
- [R2–GigabitEthernet0/0/0]quit
- [R2]interface gi0/0/1 // 连接外网的接口
- [R2–GigabitEthernet0/0/1]ip address 200.1.1.14 28
- [R2–GigabitEthernet0/0/1]quit
- interfac gi0/0/1
- nat server protocol tcp global 200.1.1.11 80 inside 10.1.1.11 80
- nat server protocol tcp global 200.1.1.11 21 inside 10.1.1.12 21
- <R1>display nat server
- Nat Server Information:
- Interface : GigabitEthernet0/0/1
- Global IP/Port : 200.1.1.11/80(www)
- Inside IP/Port : 10.1.1.11/80(www)
- Protocol : 6(tcp)
- (……)
- Global IP/Port : 200.1.1.11/21(ftp)
- Inside IP/Port : 10.1.1.12/21(ftp)
- Protocol : 6(tcp)
- (……)