H3C裝置之 NAT SERVER
NATSERVER:
配置NATSERVER,通過公網對私網的一一對映,實現公網可以訪問內網:[RTA]inte0/0
[RTA-Ethernet0/0]ipadd10.0.0.25424
[RTA-Ethernet0/0]undoshutdown
[RTA-Ethernet0/1]inte0/1
[RTA-Ethernet0/1]ipadd198.76.28.124
[RTA-Ethernet0/1]undoshutdown
[RTA]rip
[RTA-rip-1]ver2
[RTA-rip-1]undosumm
[RTA-rip-1]undosummary
[RTA-rip-1]network198.76.28.0
[RTA]inte0/0
[RTA-Ethernet0/0]ipadd198.76.28.224
[RTA-Ethernet0/0]undoshutdown
[RTA-Ethernet0/1]inte0/1
[RTA-Ethernet0/1]ipadd198.76.29.124
[RTA-Ethernet0/1]undoshutdown
[RTA]rip
[RTA-rip-1]ver2
[RTA-rip-1]undosumm
[RTA-rip-1]undosummary
[RTA-rip-1]network198.76.28.0
[RTA-rip-1]network198.76.29.0
PCA:10.0.0.1255.255.255.0GT:10.0.0.254
PCB:10.0.0.2255.255.255.0GT:10.0.0.254
SERVER:198.76.29.4255.255.255.0GT:198.76.29.1
此時公網網路已經正常訪問,但是公網卻無法訪問內部私有網路,當私網有某種服務需要釋出時就無法實現,此時就用到了NATSERVER:
RTA]inte0/1
[RTA-Ethernet0/1]natserverprotocolicmpglobal198.76.28.10inside10.0.0.1匹配公網對應的私網地址和所使用的協議。
此時訪問對映的公網地址已經成功:
[RTB]ping-a198.76.29.4198.76.28.10
PING198.76.28.10:56databytes,pressCTRL_Ctobreak
Replyfrom198.76.28.10:bytes=56Sequence=1ttl=127time=24ms
Replyfrom198.76.28.10:bytes=56Sequence=2ttl=127time=10ms
Replyfrom198.76.28.10:bytes=56Sequence=3ttl=127time=10ms
Replyfrom198.76.28.10:bytes=56Sequence=4ttl=127time=1ms
Replyfrom198.76.28.10:bytes=56Sequence=5ttl=127time=20ms
---198.76.28.10pingstatistics---
5packet(s)transmitted
5packet(s)received
0.00%packetloss
round-tripmin/avg/max=1/13/24ms
[RTA]dispnatserver
NATserverinprivatenetworkinformation:
Therearecurrently1internalserver(s)
Interface:Ethernet0/0/0,Protocol:1(icmp),
[global]198.76.28.10:----[local]10.0.0.1:----可以看到通過198.76.28.10對映10.0.0.1私網地址。
此時的私網地址10.0.0.1也是可以成功訪問公網的:
C:\DocumentsandSettings\xiaofei>ping198.76.29.4
Pinging198.76.29.4with32bytesofdata:
Replyfrom198.76.29.4:bytes=32time=7msTTL=254
Replyfrom198.76.29.4:bytes=32time=16msTTL=254
Replyfrom198.76.29.4:bytes=32time=1msTTL=254
Replyfrom198.76.29.4:bytes=32time=16msTTL=254
Pingstatisticsfor198.76.29.4:
Packets:Sent=4,Received=4,Lost=0(0%loss),
Approximateroundtriptimesinmilli-seconds:
Minimum=1ms,Maximum=16ms,Average=10ms
當公網想要訪問內部的私有服務時,同樣使用NATSERVER,比如FTP,www,DNS等:
RTA]inte0/1
[RTA-Ethernet0/1]natserverprotocoltcpglobal198.76.28.10ftpinside10.0.0.1ftp
[RTA-Ethernet0/1]natserverprotocoltcpglobal198.76.28.10wwwinside10.0.0.1www
[RTA-Ethernet0/1]natserverprotocoludpglobal198.76.28.10dnsinside10.0.0.1dns
轉載於:https://blog.51cto.com/xiaoliufei/962524