有志者,事竟成,破釜沉舟,百二秦关终属楚;有心人,天不负,卧薪尝胆,三千越甲可吞吴。
AR1配置
interface GigabitEthernet0/0/0
ip address 192.168.1.254 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 100.1.12.254 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 100.1.12.1
AR2配置
interface GigabitEthernet0/0/0
ip address 100.1.12.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 100.1.2.254 255.255.255.0
#
ip route-static 200.1.12.0 255.255.255.0 100.1.12.254
#
五种nat配置前面相同
静态配置
[AR1-GigabitEthernet0/0/1]nat static global 200.1.12.1 inside 192.168.1.1
效果
NAPT配置
#
acl number 2000
rule 5 permit source 192.168.1.0 0.0.0.255
#
nat address-group 1 200.1.12.1 200.1.12.6
#
interface GigabitEthernet0/0/1
ip address 100.1.12.254 255.255.255.0
nat outbound 2000 address-group 1
效果
动态nat
#
acl number 2000
rule 5 permit source 192.168.1.0 0.0.0.255
#
nat address-group 1 200.1.12.1 200.1.12.6
#
interface GigabitEthernet0/0/1
ip address 100.1.12.254 255.255.255.0
nat outbound 2000 address-group 1 no-pat
效果
Easy IP
acl number 2000
rule 5 permit source 192.168.1.0 0.0.0.255
#
interface GigabitEthernet0/0/1
ip address 100.1.12.254 255.255.255.0
nat outbound 2000
#
效果
nat server
AR1配置
出口g0/0/1路由配置
nat server protocol tcp global 200.1.12.6 ftp inside 192.168.1.3 ftp
系统视图配置
nat alg ftp enable
开启ftp服务
实验效果