1、网络地址转换NAT四种方式及访问控制策略ACL应用NAT实验总结:在配置静态NAT/动态NAT/NAPT时映射外部地址不能使用外部接口地址,要不会出现IP冲突网络搭建配置情况LSW1interface Vlanif1 ip address 192.168.1.1 255.255.255.0#interface Vlanif2 ip address 192.168.2.1 255.255.255.0#interface Vlanif3 ip address 172.16.1.1 255.255.255.0#interface Vlanif4 ip address 172.16.2.1 255.2
2、55.255.0#interface Ethernet0/0/2 port lixxxxnk-type access port default vlan 2#interface Ethernet0/0/3 port lixxxxnk-type access port default vlan 3#interface Ethernet0/0/4 port lixxxxnk-type access port default vlan 4#ip route-static 0.0.0.0 0.0.0.0 192.168.1.254#AR1#interface GigabitEthernet0/0/0
3、ip address 192.168.1.254 255.255.255.0 #interface GigabitEthernet0/0/1 ip address 10.0.0.1 255.0.0.0 #rip 1 version 2 network 10.0.0.0#ip route-static 172.16.0.0 255.255.0.0 192.168.1.1ip route-static 192.168.0.0 255.255.0.0 192.168.1.1#AR2#interface GigabitEthernet0/0/0 ip address 10.0.0.2 255.0.0.
4、0 #interface GigabitEthernet0/0/1 ip address 20.0.0.1 255.0.0.0 #rip 1 version 2 network 20.0.0.0 network 10.0.0.0#AR3#interface GigabitEthernet0/0/0 ip address 20.0.0.2 255.0.0.0 #interface GigabitEthernet0/0/1 ip address 180.1.1.1 255.255.255.0 #rip 1 version 2 network 20.0.0.0#ip route-static 0.0
5、.0.0 0.0.0.0 10.0.0.1#ACL访问控制策略简单ACLLSW1#acl number 2000 rule 1 deny source 172.16.1.2 0#interface Ethernet0/0/5 traffic-filter outbound acl 2000#高级ACLLSW1#acl number 3000 rule 1 deny ip source 192.168.2.0 0.0.0.255 destination 20.0.0.1 0#interface Ethernet0/0/5 traffic-filter outbound acl 3000#静态NA
6、TAR1#interface GigabitEthernet0/0/1nat static global 10.0.0.3 inside 192.168.1.2 netmask 255.255.255.255nat static enable#验证静态NAT使用抓包工具可以看到静态映射访问AR3时使用的IP地址是10.0.0.3动态NATAR1# nat address-group 1 10.0.0.4 10.0.0.5#acl number 2000 rule 1 permit source 192.168.2.0 0.0.0.255#interface GigabitEthernet0/0/1nat outbound 2000 address-group 1 #验证NAPT(端口映射)AR3#interface GigabitEthernet0/0/0nat server protocol tcp global 20.0.0.3 8080 inside 180.1.1.2 www#使用AR1下的http客户端进行访问验证已成功访问Easy IPAR1#acl number 2001 rule 1 permit source 172.16.0.0 0.0.255.255 #interface GigabitEthernet0/0/1nat outbound 2001#
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1