1. 程式人生 > >動態PNAT配置

動態PNAT配置

ati shutdown ip route auto onf marker 實驗 enter address

實驗名稱:思科路由動態PNAT配置
實驗拓撲:
實驗環境:1、3臺路由器,
2、一臺交換機
Router 0 邊界路由器(內網和外網)
Router 1 邊界路由器(公網的內網和外網)
Pouter 2 內網路由器 (公網的內部網絡)
3、兩臺PC
Pc2 pc3

實驗思路:先把三臺路由器的地址配置好,
Router0 g0/0口是內網網關 192.168.1.254/24
Router0 g0/1口是公網地址 100.1.1.1/24

                                 Router1   g0/0是公網外網地址 100.1.1.2/24
                                 Router1   g0/1 是公網內網網關 200.1.1.1/24

                                 Router2 g0/0 是公網內網地址  200.1.1.2/24

實驗步驟:
1、 配置PC機地址:
Pc2:
IP : 192.168.10.1/24
網關:192.168.10.254
Pc3
IP : 192.168.10.2/24
網關:192.168.10.254
2、 配置Router 0
Continue with configuration dialog? [yes/no]: no

Press RETURN to get started!

Router>enable
Router#
Router#configure
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.

Router(config)#int g0/0
Router(config-if)#no shtdown
^
% Invalid input detected at ‘^‘ marker.
Router(config-if)#
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up

Router(config-if)#ip address 192.168.10.254 255.255.255.0
Router(config-if)#e
Router(config)#int g0/1
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to up

Router(config-if)#ip address 100.1.1.1 255.255.255.0
Router(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to up

Router(config-if)#e
Router(config)#int g0/0
Router(config-if)#ip nat i
Router(config-if)#ip nat inside
Router(config-if)#e
Router(config)#int g0/1
Router(config-if)#ip nat o
Router(config-if)#ip nat outside
Router(config-if)#
Router(config-if)#
Router(config-if)#
Router(config-if)#e
Router(config)#
Router(config)#
Router(config)#
Router(config)#
Router(config)#acce
Router(config)#access-list 1 p
Router(config)#access-list 1 permit 192.168.10.0 0.0.0.255
Router(config)#ip nat i
Router(config)#ip nat inside s
Router(config)#ip nat inside source l
Router(config)#ip nat inside source list 1 interface g0/1
Router(config)#
Router(config)#
Router(config)#ip route 0.0.0.0 0.0.0.0 100.1.1.2
Router(config)#
3、 配置Router1
Continue with configuration dialog? [yes/no]: no

Press RETURN to get started!

Router>enable
Router#configure
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int g0/0
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up

Router(config-if)#ip address 100.1.1.2 255.255.255.0
Router(config-if)#e
Router(config)#int g0/1
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to up

Router(config-if)#ip address 200.1.1.1 255.255.255.0
Router(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to up

Router(config-if)#
Router(config-if)#e
Router(config)#route rip
Router(config-router)#version 2
Router(config-router)#no auto-summary
Router(config-router)#network 200.1.1.0
Router(config-router)#network 100.1.1.0
Router(config-router)#p
Router(config-router)#passive-interface g0/0
Router(config-router)#
4、 配置Router 2
Continue with configuration dialog? [yes/no]: no

Press RETURN to get started!

Router>enable
Router#configure
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int g0/0
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up

Router(config-if)#ip address 200.1.1.2 255.255.255.0
Router(config-if)#e
Router(config)#route rip
Router(config-router)#version 2
Router(config-router)#no auto-summary
Router(config-router)#network 200.1.1.0
Router(config-router)#
5、驗證思路:
全部配置好先ping自己的網關在一步一步ping到公網的內網

動態PNAT配置