分类: 系统运维
2009-06-16 21:49:19
环境:两台路由器,由串口相联。
要求:如下图所示,设置R1以太口的secondary地址为
步骤一、基本配置
R1的配置:
R1(config)#interface e0
R1(config-if)#ip address
R1(config-if)#ip address
R1(config-if)#ip address
R1(config-if)#ip address
R1(config-if)#ip address
R1(config-if)#ip address
R1(config-if)#no keepalive à关闭检测
R1(config-if)#no shutdown
R1(config-if)#interface s0
R1(config-if)#ip address 30.1.1.1 255.255.255.0
R1(config-if)#clock rate 64000
R1(config-if)#no shutdown
R2的配置:
R2(config)#interface loopback 0
R2(config-if)#ip address
R2(config-if)#interface s1
R2(config-if)#ip address 30.1.1.2 255.255.255.0
R2(config-if)#no shutdown
配置路由:
R2(config)#ip route 80.1.1.0 255.255.255.240 serial 1
R1(config)#ip route
步骤二、NAT与PAT的创建
NAT的配置:
R1(config)#access-list 10 permit host
R1(config)#access-list 10 permit host
R1(config)#ip nat pool ippool 80.1.1.2 80.1.1.9 prefix-length 28 à定义地址池
R1(config)#ip nat inside source list 10 pool ippool à将池和列表关联
PAT的配置:
R1(config)#access-list 11 permit host
R1(config)#ip nat inside source list 11 interface serial 0 overload à与接口映射
静态NAT的配置:
R1(config)#ip nat inside source static
R1(config)#interface e0
R1(config-if)#ip nat inside à加载到接口
R1(config-if)#interface s0
R1(config-if)#ip nat outside à加载到接口
步骤三、测试
R1#ping
Protocol [ip]:
Target IP address:
Extended commands [n]: y
Source address or interface:
!!!!!
R1#ping
Protocol [ip]:
Target IP address:
Extended commands [n]: y
Source address or interface:
!!!!!
R1#ping
Protocol [ip]:
Target IP address:
Extended commands [n]: y
Source address or interface:
!!!!!
R1#show ip nat translation à查看转换列表
Pro Inside global Inside local Outside local Outside global
--- 80.1.1.10
--- 80.1.1.2
--- 80.1.1.3
icmp 30.1.1.1:2832
icmp 30.1.1.1:2833
icmp 30.1.1.1:2834
icmp 30.1.1.1:2835
icmp 30.1.1.1:2836
步骤四、显示当前配置
R1的当前配置:
R1#show running-config
hostname R1
!
no ip domain-lookup
!
interface Ethernet0
ip address
ip address
ip address
ip address
ip address
ip address
ip nat inside
no keepalive
!
interface Serial0
ip address 30.1.1.1 255.255.255.0
ip nat outside
clockrate 64000
!
ip nat pool ippool 80.1.1.2 80.1.1.9 prefix-length 28
ip nat inside source list 10 pool ippool
ip nat inside source list 11 interface Serial0 overload
ip nat inside source static
ip nat inside source static tcp 10.1.1.6 80 80.1.1.8 80 extendable
ip route
ip route 192.168.155.0 255.255.255.0 30.1.1.2 /这个是我PC机的网段
ip http server
!
!
access-list 10 permit
access-list 10 permit
access-list 11 permit
!
line con 0
exec-timeout 0 0
logging synchronous
end
R2的当前配置:
r2#show running-config
hostname r2
no ip domain-lookup
!
interface Loopback0
ip address
!
interface FastEthernet0/0
ip address 192.168.155.11 255.255.255.0
duplex half
!
interface Serial1
ip address 30.1.1.2 255.255.255.0
!
ip route 80.1.1.0 255.255.255.240 Serial1
line con 0
exec-timeout 0 0
logging synchronous
end
PC上设置:
c:>route add 80.1.1.0 mask 255.255.255.0 192.168.155.11 metric 5
然后在PC上浏览80.1.1.8网址,再浏览80.1.1.7网址。看谁能够正常访问,谁不能正常访问,从而验证端口映射是否成功~!