|
|
一、组网需求:* M7 E8 P! y. m# p9 z
某公司平台和办公网的私网用户和互联网相连,路由器上接口GigabitEthernet0/0/0的公网地址为202.169.10.1/24,对端运营商侧地址为202.169.10.2/24。8 Q( k% `6 J& z. x) a8 l
允许使用公网IP地址比较少(222.249.230.1),所以使用no-pat转换方式(只转换数据包的IP地址,并不使用端口号)平台的NAT方式替换A部门内部的主机地址{网段为192.168.(100-110).0/24},访问因特网。
- o: X4 q* L5 K7 j8 r' d允许使用公网IP地址比较少(222.249.230.1),所以使用pat转换方式(同时转换数据包中的IP地址和端口号)办公网的NAT替换内部的主机地址(网段为192.168.0.0/22),访问因特网。6 m+ w$ K5 |2 J; i
1、网络拓扑" C! X3 K# c0 P; \8 [; @+ X
略
2 L4 h1 k5 |6 k$ c- S5 E% d6 w7 x7 h! I( ~
2、配置思路6 t g* A# o+ D
配置接口IP地址、缺省路由和在WAN侧接口下配置NAT Outbound,实现内部主机访问外网服务功能。: Z `# l: F; w( g
二、操作步骤1 l% J; [- N0 r& a5 h D
1、配置云平台、办公网主机IP地址,网关分别是192.168.(100-110).254、192.168.0.1
4 H* p# y: q' r! ?0 j2、在SWA上配置vlan1 v5 D$ a% n- U, M" y( \
<Huawei>system-view
5 X3 A# I& Q( v3 m[Huawei]sysname SW) \( i |8 V' _" Z
[SW]vlan (100-110), m7 {5 {/ D5 p- H4 K2 b* p$ P
[SW-vlan(100-110)]q- i6 |% y# O+ p' r
[SW]interface Ethernet0/0/1
; M9 @) N2 o* r& L1 H7 c* j2 d7 i[SW-Ethernet0/0/1]port link-type access9 q3 C# }3 ]* q
[SW-Ethernet0/0/1]port default vlan 100
9 m# v: `+ J+ C1 h4 H9 A[SW-Ethernet0/0/1]q5 o5 |% m5 P* X* b
[SW]interface Ethernet 0/0/25 ?, _8 Z _! h! J
[SW-Ethernet0/0/2]port link-type trunk0 \) a: A, q* O; l0 h$ v( _
[SW-Ethernet0/0/2]port trunk allow-pass vlan all% t% h3 f, G3 ?0 Z' }
[SW-Ethernet0/0/2]q
6 B" u1 B+ ~/ t. a# T3、在SWB上配置vlan, T" I7 ]2 ~- r& q) Y: o$ V
[Huawei]sysname SW1: z, k/ L4 s, Q9 J8 ?
[SW1]vlan 200
) n; `# S9 C+ [! t8 O/ p- @[SW1-vlan200]q n1 u1 Y4 ?* Y" r8 x2 a9 @% @4 b% L
[SW1]interface Ethernet0/0/19 S( q! l0 n2 n/ Q; m- S" o! f
[SW1-Ethernet0/0/1]port link-type access
- u( H* s3 ^2 Z% i9 F( g& Y[SW1-Ethernet0/0/1]port default vlan 200# v6 y: @! J3 ^ t5 n
[SW1-Ethernet0/0/1]q
5 L! w6 h5 n" d& Z) I Q; u" A[SW1]interface Ethernet 0/0/2
% h* z% G/ x. i! \1 f# a[SW1-Ethernet0/0/2]port link-type trunk
4 Z, y1 a( V! n2 S3 G[SW1-Ethernet0/0/2]port trunk allow-pass vlan all
7 e4 D3 k6 e$ m) r. T: U" V- C* y[SW1-Ethernet0/0/2]q
; s2 G/ o Z$ F% _+ V8 [% E4、在Router上配置接口IP地址
3 {6 l- ?1 a& ^! Z h5 Z<Huawei>system-view
1 k+ m* H- ~- z3 k8 U[Huawei]sysname Router
4 W! D9 S1 U% r/ M+ M2 K6 e8 h[Router]vlan batch 100 200# q$ l% _% q7 b9 G! |
[Router]interface Vlanif 100$ J( e5 q+ t5 Z4 T
[Router-Vlanif100]ip address 192.168.20.1 24
9 C$ z) M0 `& e1 u4 r. ~6 o1 z[Router-Vlanif100]q# B6 I1 A7 }+ Q0 @1 g7 S& ~
[Router]interface Vlanif 200
2 }3 U( V$ N! u$ c$ _[Router-Vlanif200]ip address 10.0.0.1 24 d9 w( D# ]+ K/ q5 f: Y# R
[Router-Vlanif200]q
' l" {0 Z3 k. l: r$ j7 g! u' ?' V[Router]interface Ethernet 0/0/08 |% A( r1 A6 C( U% `5 F# o, t
[Router-Ethernet0/0/0]port link-type trunk
I7 k0 m1 t. r6 U$ H[Router-Ethernet0/0/0]port trunk allow-pass vlan all
" _7 i1 u, }7 n: Q) v5 T) O* v7 W, B+ B8 p[Router-Ethernet0/0/0]q
. _. G: ]1 Q: w7 c' u[Router]interface Ethernet 0/0/1* {- Z0 W/ [9 n; G/ K- k* U; [
[Router-Ethernet0/0/1]port link-type trunk
9 ~$ T- J, z \" _5 k! Q) s[Router-Ethernet0/0/1]port trunk allow-pass vlan all# F$ W& t6 O' ^% {; p
[Router-Ethernet0/0/1]q! G" [: Q; R$ s$ v z
[Router]interface GigabitEthernet 0/0/0* l$ h5 v0 L1 W8 [+ c% b6 O* W7 N
[Router-GigabitEthernet0/0/0]ip address 202.169.10.1 24
0 f+ X4 M+ z1 d5 }- V# m6 D; ][Router-GigabitEthernet0/0/0]q2 @5 r# k( u/ m V4 c F! F# F
这时候主机就可以ping通网关了9 |; [! P" I' C- d& Q: V
5、在Router上配置缺省路由,指定下一跳为202.169.10.26 P2 j3 k) O% v2 W3 _4 e9 U: \8 |9 |
[Router]ip route-static 0.0.0.0 0.0.0.0 202.169.10.23 ?5 @% Z3 ]% r, } D
6、在Router上配置NAT Outbound(记住在出接口上应用)
' j- w; d' Z& f' S2 n+ F) ^- F[Router]nat address-group 1 202.169.10.100 202.169.10.200$ k* v1 | t3 C8 s' y$ h2 }; W
[Router]nat address-group 2 202.169.10.201 202.169.10.2029 M/ R3 E9 w5 f5 r6 g& |# ?
[Router]acl number 3001
6 T) Z9 {3 f1 H( `[Router-acl-adv-3001]rule 5 permit ip source 192.168.20.0 0.0.0.2559 _& P$ D* |+ B* R% @. r9 f( P
[Router-acl-adv-3001]q+ M e# a* m" `$ I
[Router]acl number 3002
: V/ I; u: ~; e- x$ M) J% X5 U[Router-acl-adv-3002]rule 5 permit ip source 10.0.0.0 0.0.0.255: N) f* x9 K D
[Router-acl-adv-3002]q
" N; Q2 ]- x1 X0 g[Router]interface GigabitEthernet 0/0/0
$ N! b: {$ t* q% N, J[Router-GigabitEthernet0/0/0]nat outbound 3001 address-group 1 no-pat0 `4 W9 _& @3 D
[Router-GigabitEthernet0/0/0]nat outbound 3002 address-group 2
( ?9 M* n2 D9 ?( E5 e[Router-GigabitEthernet0/0/0]q; s2 U: S" |; U" \& Q" K& C8 C- m
[Router]ip soft-forward enhance enable, O1 J* B+ h5 o# r5 y6 B0 R" v
如果需要在Router上执行ping -a source-ip-address命令通过指定发送ICMP ECHO-REQUEST报文的源IP地址来验证内网用户可以访问因特网,需要配置命令ip soft-forward enhance enable使能设备产生的控制报文的增强转发功能,这样,私网的源地址才能通过NAT转换为公网地址。5 |+ n; q: K: Z
7、查看结果% O1 h6 J: S# I; z$ [
[Router]display nat outbound
# a- t+ M8 a) l8 p8 |- y+ R NAT Outbound Information:- I' X+ S3 w$ _* a/ A
--------------------------------------------------------------------------3 a8 `0 I( e5 k4 J
Interface Acl Address-group/IP/Interface Type5 a! m( k9 c% m
--------------------------------------------------------------------------- c) c3 s7 g( U, r$ i: h- a
GigabitEthernet0/0/0 3001 1 no-pat
' d! d1 ^* J, f! K* `8 M- M GigabitEthernet0/0/0 3002 2 pat
* r6 I' B! o/ d1 P# P/ S: e/ g. m --------------------------------------------------------------------------
* `; [' A# f4 X" x& V! T Total : 22 |: r( ]: M( j D$ g
[Router]ping -a 192.168.20.1 202.169.10.2 j9 }' L) u7 \4 y
PING 202.169.10.2: 56 data bytes, press CTRL_C to break
- @0 k1 B5 B: N8 g% E9 p Reply from 202.169.10.2: bytes=56 Sequence=1 ttl=255 time=10 ms6 j: i1 v; \$ V! w* R8 f
Reply from 202.169.10.2: bytes=56 Sequence=2 ttl=255 time=10 ms- V" z( A0 d- S: D1 r' u
Reply from 202.169.10.2: bytes=56 Sequence=3 ttl=255 time=10 ms& {, z& E5 O9 {8 P8 S
Reply from 202.169.10.2: bytes=56 Sequence=4 ttl=255 time=10 ms7 }# P( F0 e. H" E+ Z1 {
Reply from 202.169.10.2: bytes=56 Sequence=5 ttl=255 time=10 ms
8 ?# |' I% j/ S0 [: p
+ t, _! V0 i; k& X' Y3 b --- 202.169.10.2 ping statistics ---$ g K7 ?) Z2 C ~/ v4 {0 f" h
5 packet(s) transmitted
0 z, g5 k3 r" A! V4 E 5 packet(s) received
4 ?/ T- s+ l2 m" z$ N 0.00% packet loss6 F# H y, Z7 }* N# ~* {
round-trip min/avg/max = 10/10/10 ms0 D$ O0 {8 K/ c5 n: a
) q z' x, M' ]' r1 k, U, n
[Router]ping -a 10.0.0.1 202.169.10.2, M; k) _% s0 f. ^6 x
PING 202.169.10.2: 56 data bytes, press CTRL_C to break [9 w; X X/ p( y- W
Reply from 202.169.10.2: bytes=56 Sequence=1 ttl=255 time=10 ms+ `: D, T- Z3 Q! h3 \, [
Reply from 202.169.10.2: bytes=56 Sequence=2 ttl=255 time=10 ms
+ }) R/ z. c# l% K9 l2 C$ ] Reply from 202.169.10.2: bytes=56 Sequence=3 ttl=255 time=10 ms) E) |2 Q' ~9 V: m
Reply from 202.169.10.2: bytes=56 Sequence=4 ttl=255 time=10 ms
! F+ x$ {$ D- c Reply from 202.169.10.2: bytes=56 Sequence=5 ttl=255 time=10 ms' p$ q6 B- L1 P" T/ K; ]; g( c+ Y" J
* z7 k; Q1 a4 B2 d/ L5 O
--- 202.169.10.2 ping statistics ---7 n v& o o- [ K: Z
5 packet(s) transmitted
2 @" s$ j+ }) H7 Z' s n 5 packet(s) received
$ }# y' m; f8 n, g/ y 0.00% packet loss' N8 l3 G$ `1 i- j1 b+ Y
round-trip min/avg/max = 10/10/10 ms
2 l6 I. F9 ?5 A5 B& l% R w9 A8 Y- f8、查看NAT映射表项2 Q9 J! C8 x& y& i; t
[Router]display nat session all verbose
0 V, K8 `" g1 q' c————————————————
4 K$ l; E8 O, ]- ?& p! O8 |! y4 M版权声明:本文为CSDN博主「友人a笔记」的原创文章,遵循CC 4.0 BY-SA版权协议,转载请附上原文出处链接及本声明。- ~5 {! F$ U' N5 Z/ G
原文链接:https://blog.csdn.net/tladagio/article/details/80725043( _# W& \ V4 _" S4 W1 F6 i
|
|