跳到主要內容

NAT


Static NAT
==============================================
Router(config-if)#ip address 10.1.1.1 255.255.255.0
Router(config-if)#interface fa 0/0
Router(config-if)#ip address 192.168.1.1 255.255.255.0
Router(config-if)#exit
Router(config)#ip nat inside source static 192.168.1.2 10.1.1.1
Router(config)#interface fa 0/0
Router(config-if)#ip nat inside
Router(config-if)#interface fa 0/1
Router(config-if)#ip nat outside



Router#show ip nat translations
Pro  Inside global     Inside local       Outside local      Outside global
---  10.1.1.1          192.168.1.2        ---                ---
tcp 10.1.1.1:1026      192.168.1.2:1026   10.1.1.2:80        10.1.1.2:80



Dynamic Address Translation
=============================================

Router(config)#interface fa 0/0
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up
ip add
Router(config-if)#ip address 192.168.1.1 255.255.255.0
Router(config-if)#ip nat inside
Router(config-if)#exit
Router(config)#interface fa 0/1
Router(config-if)#ip address 10.1.1.1 255.255.255.0
Router(config-if)#ip nat outside
Router(config-if)#exit

Router(config)#access-list 1 permit 192.168.1.0 0.0.0.255
Router(config)#ip nat pool test 10.1.1.2 10.1.1.7 netmask 255.255.255.248
Router(config)#ip nat inside source list 1 pool test






Overloading an inside global address
=============================================

Router(Config)#interface fa 0/1
Router(config-if)#ip address 10.1.1.1 255.255.255.0
Router(config-if)#ip nat outside

Router(config)#interface fa 0/0
Router(config-if)#ip address 192.168.1.1 255.255.255.0
Router(config-if)#ip nat inside


Router(config)#access-list 1 permit 192.168.1.0 0.0.0.255
Router(config)#ip nat inside source list 1 interface fa 0/1 overload

**上面也可以先宣告Pool,也就是類似Dynamic Address Translation**
Router(Config)#ip nat pool test 10.1.1.1 10.1.1.1 netmask 255.255.255.0
Router(Config)#ip nat inside source list 1 pool test overload


Router#show ip nat translations
Pro  Inside global     Inside local       Outside local      Outside global
icmp 10.1.1.1:21       192.168.1.2:21     10.1.1.2:21        10.1.1.2:21
icmp 10.1.1.1:22       192.168.1.2:22     10.1.1.2:22        10.1.1.2:22
icmp 10.1.1.1:23       192.168.1.2:23     10.1.1.2:23        10.1.1.2:23
icmp 10.1.1.1:24       192.168.1.2:24     10.1.1.2:24        10.1.1.2:24
icmp 10.1.1.1:25       192.168.1.2:25     10.1.1.2:25        10.1.1.2:25

留言

這個網誌中的熱門文章

HP A5120 Switch 基本設定

沒用過HP的Switch,指令跟Cisco完全不同,花了一些時間熟悉~ 1.啟動Spanning-Tree,預設沒有開啟 (黑色粗體是我敲的指令) <HP> system-view System View: return to User View with Ctrl+Z. [HP] stp enable [HP] %Apr 26 12:03:59:826 2000 HP MSTP/6/MSTP_ENABLE: STP is now enabled on the device. %Apr 26 12:03:59:918 2000 HP MSTP/6/MSTP_FORWARDING: Instance 0's GigabitEthernet1/0/17 has been set to forwarding state. %Apr 26 12:04:00:068 2000 HP MSTP/6/MSTP_DETECTED_TC: Instance 0's GigabitEthernet1/0/17 detected a topology change. #Apr 26 12:04:00:208 2000 HP MSTP/1/PFWD: hwPortMstiStateForwarding: Instance 0's Port 0.9437200 has been set to forwarding state! 2.DHCP Snooping   (黑色粗體是我敲的指令) 假設我的DHCP Server接在24 Port,其他Port不允許有DHCP Server <HP> system-view System View: return to User View with Ctrl+Z. [HP] dhcp-snooping  DHCP Snooping is enabled. [HP] interface GigabitEthernet 1/0/24 [HP-GigabitEthernet1/0/24 ]dhcp-snooping trust 若是沒有Port 設成dhcp-snooping trust,那麼這台Switch就沒有Client可以從DHCP Serv...

2台 Vigor 2920建立 LAN To LAN VPN (IPsec)

我有兩台Vigor 2920,環境如下: Vigor B 撥出 LAN:192.168.1.0/24 Vigor A 撥入 LAN:172.16.1.0/24 設定如下: Vigor B設定 Vigor A設定 詳細設定請參考官網 http://www.draytek.com/index.php?option=com_k2&view=item&id=2666&Itemid=264&lang=tw

Draytek Vigor 2927

其實心中一直感覺用了十年的Vigor 2920n會掛掉,因為先前也有一台2920n壞過,所以心中也有個底,但突然壞了也真讓人心驚驚! 其實最近都在用Unifi的設備,但考量目前的工作環境與網路需求,就直接更換最新的Vigor 2927,雖然2920n的備份檔不能直接倒回去,不過之前的設定參數都有抓圖下來,所以很快就把設定設回去,這也算是用習慣Draytek的好處~ 下一篇會說明怎麼建立Unifi Dream Machine Pro與Vigor 2927的Site To Site VPN。