-
2004-09-04
如果不太懂地址转换(NAT)就进来看看 - [网络技术(bbs.iohy.com交流)]
版权声明:转载时请以超链接形式标明文章原始出处和作者信息及本声明
如果不太懂地址转换(NAT)就进来看看 偶然发现以前学习nat时的东西。 对这个配置有问题可以跟帖 *******************************全部采用端口************************ ISP分配的IP202.99.160.129 interface fastethernet0/0 ip address 192.168.1.1 255.255.255.0 duplex auto speed auto in nat inside no shutdown interface fastethernet0/1 ip address 192.168.2..1 255.255.255.0 duplex auto speed auto in nat outside no shutdown ip nat pool OnlyYou 202.99.160.130 202.99.160.130 netmask 255.255.255.252 //OnlyYou代表地址池的名称。 2个202.99.160.130是代表只用一个ip做转换后ip. access-list 1 permit 192.168.1.0 0.0.0.255 access-list 1 permit 192.168.2.0 0.0.0.255 ip nat inside source list1 pool OnlyYou overload ***********************动态地址转换+端口*********************** ISP分配的IP 有:202.99.160.130~190 255.255.255.192 Interface fastethernet0/1 Ip address 192.168.1.1 255.255.255.0 Ip address 192.168.2.1 255.255.255.0 secondary Duplex auto Speed auto Ip nat inside No shutdown Interface serial 0/0 Ip address 202.99.160.129 255.255.255.192 Duplex auto Speed auto Ip nat outside No shutdwon Ip nat pool OutPort 202.99.160.190 202.99.160.190 netmask 255.255.255.192 Ip nat pool OutPool 202.99.160.130 202.99.160.190 netmask 255.255.255.192 Ip nat inside source list1 pool OutPort //192.168.1.0段主机全部转成202.99.160.190 Ip nat inside source list2 pool OutPool //出于访问ftp站点等考虑:192.168.2.0和192.168.3.0段主机全部 //转成202.99.160.130到202.99.160.189中的所有地址。 Access-list1 permit 192.168.1.0 0.0.0.255 Access-list2 permit 192.168.2.0 0.0.0.255 Access-list2 permit 192.168.3.0 0.0.0.255 ***********************静态地址转换*********************** ISP分配的IP地址是:211.82.220.80~211.82.220.87 211.82.220.81 255.255.255.248 要求Intranet上的Web.E-mail.Ftp.Media可以被外部访问. Interface fastethernet0/0 Ip address 192.168.1.1 255.255.255.0 Duplex auto Speed auto Ip nat inside No shutdown Interface fastethernet0/1 Ip address 211.82.220.81 255.255.255.248 Speed auto Duplex auto Ip nat outside No shutdown Ip nat pool Outpool 211.82.220.86 211.82.20.86 netmask 255.255.255.248 Access-list 1 permit 192.168.1.2 0.0.0.255 Access-list 1 permit 192.168.1.3 0.0.0.255 Access-list 1 permit 192.168.1.4 0.0.0.255 Access-list 1 permit 192.168.1.5 0.0.0.255 Ip nat inside source list1 pool Outpool overload Ip nat inside source static 192.168.1.2 211.82.220.82 Ip nat inside source static 192.168.1.3 211.82.220.83 Ip nat inside source static 192.168.1.4 211.82.220.84 Ip nat inside source static 192.168.1.5 211.82.220.85 ******************NAT影射**************************** 如果ISP提供的IP地址比较多还可以,但如果不是的时候(如就两个时),一个用于内网地址转换,另一个用于对外网提供服务. ISP提供的内网上网IP Interface ethernet0 Ip address 192.168.1.1 255.255.255.0 Duplex auto Speed auto Ip nat inside No shutdown Interface fastethernet0/0 Ip address 211.82.220.129 255.255.255.248 Duplex auto Speed auto Ip nat outside No shutdown Access-list 1 permit 192.168.1.0 0.0.0.255 Ip nat pool Everybody 211.82.220.130 211.82.220.130 network 255.255.255.252 Ip nat inside source list1 pool Everybody overload Ip nat inside source static tcp 192.168.1.2 80 202.99.220.130 80 Ip nat inside source static tcp 192.168.1.3 21 202.99.220.130 21 Ip nat inside source static tcp 192.168.1.4 25 202.99.220.130 25 Ip nat inside source static tcp 192.168.1.5 110 202.99.220.130 110 *******************利用地址转换实现负载均衡******************** ;当有如象腾讯公司似的多服务器时,使用路由器实现负载平衡,可以使它们有平等的访问机会. Interface fastethernet0/1 Ip address 192.168.1.1 255.255.255.0 Duplex auto Speed auto Ip nat inside No shutdown Interface fastethernet0/0 Ip address 202.110.198.81 255.2555.255.248 Duplex auto Speed auto Ip nat outside Access-list 1 permit 202.110.198.82 Access-list 2 permit 202.110.198.83 Access-list 3 permit 192.168.1.0 0.0.0.255 Ip nat pool Webser 192.168.1.2 192.168.1.3 255.255.255.248 type rotary Ip nat pool Ftpser 19
http://qq4508509.yourblog.org/logs/240255.html
随机文章:
Snort入侵检测系统分析 2004-09-04黑客离我远一点 我的电脑你别Ping 2004-04-18Windows98不能正常关机解决法 2004-04-15全面认识VPN(一) 2004-04-14N000013 解开硬盘逻辑死锁的一种有效方法 2004-04-14
收藏到:Del.icio.us





