华为路由器NAT配置示例

45次阅读
没有评论

共计 2152 个字符,预计需要花费 6 分钟才能阅读完成。

概述:

NAT 是指网络地址转换, 指内网地址访问外网, 私网地址访问公网等。

  • 静态 NAT: 内部网络的私有 IP 地址转换为公有 IP 地址,IP 地址对是一对一的,是一成不变的。
  • 动态 NAT:内部网络的私有 IP 地址转换为公用 IP 地址时,IP 地址是不确定的,是随机的,所有被授权访问上 Internet 的私有 IP 地址可随机转换为任何指定的合法 IP 地址。
  • Easy ip NAT(基于接口)

实验拓扑图如下:

  • R1 模拟出口路由器
  • ISP 模拟运营商
  • LSW1 此处为空配
  • PC1- 3 为局域网内的电脑
华为路由器 NAT 配置示例

静态 NAT:

ISP 配置

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysna ISP
[ISP]undo in en
Info: Information center is disabled.
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip ad 181.160.11.200 24
[ISP-GigabitEthernet0/0/0]

R1 配置

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn R1
[R1]undo in en
Info: Information center is disabled.
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip ad 172.16.10.254 24
[R1-GigabitEthernet0/0/0]q
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip ad 181.160.11.100 24
[R1-GigabitEthernet0/0/1]nat static global 181.160.11.11 inside 172.16.10.11 netmask 255.255.255.255
[R1-GigabitEthernet0/0/0]nat static enable

验证

华为路由器 NAT 配置示例

动态 NAT:

ISP 配置

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysna ISP
[ISP]undo in en
Info: Information center is disabled.
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip ad 181.160.11.200 24
[ISP-GigabitEthernet0/0/0]

R1 配置

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysna R1
[R1]undo in en
Info: Information center is disabled.
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip ad 172.16.10.254 24
[R1-GigabitEthernet0/0/1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip ad 181.160.11.100 24
[R1-GigabitEthernet0/0/0]q
[R1]nat address-group 1 181.160.11.11 181.160.11.21
[R1]acl 2001
[R1-acl-basic-2001]rule 1 permit source 172.16.10.0 0.0.0.255
[R1-acl-basic-2001]rule 2 deny source any
[R1-acl-basic-2001]int g0/0/0
[R1-GigabitEthernet0/0/0]nat outbound 2001 address-group 1

验证:

华为路由器 NAT 配置示例

Easy ip NAT:

ISP 配置

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysna ISP
[ISP]undo in en
Info: Information center is disabled.
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip ad 181.160.11.200 24
[ISP-GigabitEthernet0/0/0]

R1 配置

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysna R1
[R1]undo in en
Info: Information center is disabled.
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip ad 172.16.10.254 24
[R1-GigabitEthernet0/0/1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip ad 181.160.11.100 24
[R1-GigabitEthernet0/0/0]q
[R1]acl 2001
[R1-acl-basic-2001]rule 1 permit source 172.16.10.0 0.0.0.255
[R1-acl-basic-2001]rule 2 deny source any

验证

华为路由器 NAT 配置示例

正文完
 0
Nnkin
版权声明:本站原创文章,由 Nnkin 于2024-09-05发表,共计2152字。
转载说明:除特殊说明外本站文章皆由CC-4.0协议发布,转载请注明出处。
评论(没有评论)