- 积分
- 16843
在线时间 小时
最后登录1970-1-1
|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?开始注册
x
一、组网需求:
" l5 I9 H+ q( m$ a某公司平台和办公网的私网用户和互联网相连,路由器上接口GigabitEthernet0/0/0的公网地址为202.169.10.1/24,对端运营商侧地址为202.169.10.2/24。5 U6 k N0 A: W! Q1 O z! y4 j
允许使用公网IP地址比较少(222.249.230.1),所以使用no-pat转换方式(只转换数据包的IP地址,并不使用端口号)平台的NAT方式替换A部门内部的主机地址{网段为192.168.(100-110).0/24},访问因特网。3 I9 d [- ^+ J) E% E4 d
允许使用公网IP地址比较少(222.249.230.1),所以使用pat转换方式(同时转换数据包中的IP地址和端口号)办公网的NAT替换内部的主机地址(网段为192.168.0.0/22),访问因特网。8 O$ h( _; n# P# c' d- L
1、网络拓扑
/ [/ b3 Q, K* y. p' N. A/ b略
+ S. f8 {" [% I& B4 v+ l+ ^$ z+ E3 }- X
" | M) g$ |! ], d% w" S1 Q2、配置思路
7 ?7 k I2 D3 r5 E, U配置接口IP地址、缺省路由和在WAN侧接口下配置NAT Outbound,实现内部主机访问外网服务功能。
% a5 x3 |- }3 ?+ r( r4 q$ _二、操作步骤" T# V6 q+ Z) \. _. Z1 g& O- M; k5 b6 A& K
1、配置云平台、办公网主机IP地址,网关分别是192.168.(100-110).254、192.168.0.1
3 u0 d3 w+ {; \* j2、在SWA上配置vlan
3 a$ H- t% W- [! i1 i T& y2 @<Huawei>system-view- F A! Q! `* n( n
[Huawei]sysname SW
1 D. y) ?0 i4 @; t- P6 F[SW]vlan (100-110)
5 q1 J6 z+ t) F4 y* u8 Y. G; q[SW-vlan(100-110)]q8 }9 Z: G" }2 G
[SW]interface Ethernet0/0/1
0 [% q ~9 b" p' k ^[SW-Ethernet0/0/1]port link-type access
5 y3 q8 q2 z: }. Q* o2 {" f[SW-Ethernet0/0/1]port default vlan 100- e9 ]) ^: E6 x; p+ ~
[SW-Ethernet0/0/1]q7 E' ]7 K S. n+ j4 p
[SW]interface Ethernet 0/0/2
3 o, s* p# x$ j7 b[SW-Ethernet0/0/2]port link-type trunk9 Q1 C. x! u% Q
[SW-Ethernet0/0/2]port trunk allow-pass vlan all
$ K* |3 {' B, b2 ]3 @% l$ q! I3 ^[SW-Ethernet0/0/2]q; W4 L+ y' m3 L2 N' U: y5 l
3、在SWB上配置vlan
- N4 j9 J3 K" r9 O[Huawei]sysname SW1
& o" ^& I7 W0 F, o5 r$ c" m" l[SW1]vlan 200& ^' e2 O6 A; Q6 e$ v3 y8 @! a
[SW1-vlan200]q# a4 [" G2 x' A- R% {! U
[SW1]interface Ethernet0/0/1
$ ^ X1 G. x3 P, o[SW1-Ethernet0/0/1]port link-type access : _! M! P4 D3 E# y: r! q# V" E
[SW1-Ethernet0/0/1]port default vlan 200! n7 s4 j% _ o n$ s) [$ |$ |1 x
[SW1-Ethernet0/0/1]q
. A$ \; X: u7 L0 J' I[SW1]interface Ethernet 0/0/2. D# i! O- D8 r& {' A9 Z& H
[SW1-Ethernet0/0/2]port link-type trunk
~2 B. E4 A9 W" Y5 T+ j6 D& S[SW1-Ethernet0/0/2]port trunk allow-pass vlan all 8 k$ S6 O2 k7 F- h0 i" N: [9 x
[SW1-Ethernet0/0/2]q
" p( k9 n0 Y5 V \* m4、在Router上配置接口IP地址
' Y* ]* L; G+ g0 [% Q<Huawei>system-view ( X7 y! M; p9 D9 B# Q5 h. Q
[Huawei]sysname Router
; H( o. O! J8 S# ][Router]vlan batch 100 200. N6 |4 e' w: [; c) k) Y& a) r
[Router]interface Vlanif 1008 }- _& U$ |" r
[Router-Vlanif100]ip address 192.168.20.1 24' J3 r( z0 B0 j7 a# z4 }' }
[Router-Vlanif100]q
, W8 j2 x. M; t9 J& U3 T[Router]interface Vlanif 2006 v! T( H# g( f5 E0 X
[Router-Vlanif200]ip address 10.0.0.1 248 A: m. d# \, @& \/ j( s
[Router-Vlanif200]q
! z+ J. T& m: F) o[Router]interface Ethernet 0/0/0
# K9 u. @/ O9 m/ D, E$ T/ X4 g4 `[Router-Ethernet0/0/0]port link-type trunk + A" t R& D* g9 J. t/ \" X! A
[Router-Ethernet0/0/0]port trunk allow-pass vlan all
) N {/ n; U; _! p[Router-Ethernet0/0/0]q4 W# A) E/ g# t8 ~5 R* A4 t2 ?0 B+ z
[Router]interface Ethernet 0/0/1
{8 f9 J2 @7 I+ T4 [" `8 b5 [[Router-Ethernet0/0/1]port link-type trunk
5 h$ B. y; H- s1 M- B. @8 G" O[Router-Ethernet0/0/1]port trunk allow-pass vlan all9 x) N9 p6 l V! W _
[Router-Ethernet0/0/1]q d* i0 U8 _1 e2 \
[Router]interface GigabitEthernet 0/0/0
H- N6 o+ _( p) _7 \ T0 e[Router-GigabitEthernet0/0/0]ip address 202.169.10.1 24
6 W* j B" E0 z; F. Q, v Y: p! f[Router-GigabitEthernet0/0/0]q
+ Q) h3 A6 h# k# y这时候主机就可以ping通网关了' Y; j; a4 t3 d) |
5、在Router上配置缺省路由,指定下一跳为202.169.10.2
X9 ], y- N" s- U3 p[Router]ip route-static 0.0.0.0 0.0.0.0 202.169.10.2! V# h; {8 o' ~
6、在Router上配置NAT Outbound(记住在出接口上应用)
" `: \ o$ Z5 O8 g, B- o- n9 ~[Router]nat address-group 1 202.169.10.100 202.169.10.2002 c* t) D- ?3 @" T( C. Z
[Router]nat address-group 2 202.169.10.201 202.169.10.202
( y2 R5 U) X/ X* H, L! x! ][Router]acl number 3001
" P8 w/ ^/ M' d. ]! }' A+ P, X0 z0 `[Router-acl-adv-3001]rule 5 permit ip source 192.168.20.0 0.0.0.255% \2 R9 k5 k$ e, r1 J
[Router-acl-adv-3001]q7 v' G' l, l6 {4 i; I: a
[Router]acl number 3002
8 ?% ^* g: p0 ]9 e7 Q0 Y8 c: G: m+ E[Router-acl-adv-3002]rule 5 permit ip source 10.0.0.0 0.0.0.255
; `* r2 \7 w# g" ~* S[Router-acl-adv-3002]q8 G1 q2 M9 v( I9 ]
[Router]interface GigabitEthernet 0/0/0
7 A, d1 C3 ^$ ~2 f: |- _[Router-GigabitEthernet0/0/0]nat outbound 3001 address-group 1 no-pat7 F5 q1 C$ S; {6 ]
[Router-GigabitEthernet0/0/0]nat outbound 3002 address-group 21 e; M& R- J& q; v
[Router-GigabitEthernet0/0/0]q
, g# Q* h% u6 W+ U" L6 h+ J/ C" Z[Router]ip soft-forward enhance enable( o. S$ q3 {5 g5 E
如果需要在Router上执行ping -a source-ip-address命令通过指定发送ICMP ECHO-REQUEST报文的源IP地址来验证内网用户可以访问因特网,需要配置命令ip soft-forward enhance enable使能设备产生的控制报文的增强转发功能,这样,私网的源地址才能通过NAT转换为公网地址。. W7 k ^8 ]" m1 D
7、查看结果
/ h4 G* A6 h6 c% [* Y9 Y2 q[Router]display nat outbound / |2 G; ?- o( ^3 h2 R$ y# c
NAT Outbound Information:9 x/ }* n* ?" r0 \/ Z7 n- ^
--------------------------------------------------------------------------
) O4 o6 M: g# U8 a Interface Acl Address-group/IP/Interface Type
8 z! O% `+ T. q7 y- x --------------------------------------------------------------------------4 [" s5 N- U# a3 @1 M4 R
GigabitEthernet0/0/0 3001 1 no-pat
2 s8 x$ g r1 i% ~) W GigabitEthernet0/0/0 3002 2 pat! P+ L, J0 W& v. ?3 T
--------------------------------------------------------------------------
* u! E- t/ T: C8 J0 n Total : 25 U9 u& p! m9 I4 y8 z
[Router]ping -a 192.168.20.1 202.169.10.2, z+ i- X) X4 i) h. w$ g
PING 202.169.10.2: 56 data bytes, press CTRL_C to break
7 j% A8 u: u8 ^- M d5 E! B1 M& ^ Reply from 202.169.10.2: bytes=56 Sequence=1 ttl=255 time=10 ms# w! O0 f' A( V& ^: `; t9 j
Reply from 202.169.10.2: bytes=56 Sequence=2 ttl=255 time=10 ms
/ i' P4 N0 _+ o7 E; w Reply from 202.169.10.2: bytes=56 Sequence=3 ttl=255 time=10 ms9 B3 f3 o7 r. u" X- k
Reply from 202.169.10.2: bytes=56 Sequence=4 ttl=255 time=10 ms- R3 S9 N% i; u1 h+ p# m
Reply from 202.169.10.2: bytes=56 Sequence=5 ttl=255 time=10 ms8 c2 Z" m( l; P ?0 V# }4 c
5 z V7 b7 p0 R --- 202.169.10.2 ping statistics ---
2 `# ?, K$ z' Z1 ` 5 packet(s) transmitted: e) W) h3 n) _0 A
5 packet(s) received
' q' L5 E8 x: ~2 o+ z1 E" \& L 0.00% packet loss
) B2 E o. ]% }0 y0 q round-trip min/avg/max = 10/10/10 ms0 I' n4 v( Y4 Q3 ?
% l+ r+ |! X: H: `$ t+ e: y1 W[Router]ping -a 10.0.0.1 202.169.10.23 k5 H0 ]3 j* U' }9 }
PING 202.169.10.2: 56 data bytes, press CTRL_C to break0 [. P/ X% Z N/ S. R
Reply from 202.169.10.2: bytes=56 Sequence=1 ttl=255 time=10 ms
4 _$ ~/ {& w& u+ d9 I2 ?+ `/ d9 u Reply from 202.169.10.2: bytes=56 Sequence=2 ttl=255 time=10 ms j9 Z) Q% \$ ?: G9 j" j
Reply from 202.169.10.2: bytes=56 Sequence=3 ttl=255 time=10 ms
3 T! W& c' T7 j; b5 }5 T Reply from 202.169.10.2: bytes=56 Sequence=4 ttl=255 time=10 ms( |# m2 Z o3 A: S. s4 [8 Y) x
Reply from 202.169.10.2: bytes=56 Sequence=5 ttl=255 time=10 ms1 U' e9 W. F8 T8 F% d! ]
! e- `/ k! B2 Y3 E+ X5 {. x3 M. k- t
--- 202.169.10.2 ping statistics ---% M" Y! H3 {4 z
5 packet(s) transmitted
( x1 j, f9 d% P 5 packet(s) received8 y; l- B2 D; W7 p
0.00% packet loss4 D5 M/ p+ b* [; j1 L
round-trip min/avg/max = 10/10/10 ms Y8 n9 R. ]' ~ Y
8、查看NAT映射表项" b: l( e0 v& r4 {& w/ a- z# e; V# Q
[Router]display nat session all verbose$ V: n0 B! [7 {$ R: B5 b+ M! \
————————————————
' `7 C- V6 T- B版权声明:本文为CSDN博主「友人a笔记」的原创文章,遵循CC 4.0 BY-SA版权协议,转载请附上原文出处链接及本声明。1 q' m# B1 u- c6 E
原文链接:https://blog.csdn.net/tladagio/article/details/80725043
! m! T: ^; p* S f2 C |
|