PC及服务器设置如下:
Switch-2:
Switch-2(config)#ip routing
Switch-2(config)#ip route 0.0.0.0 0.0.0.0 172.17.20.3
Switch-2(config)#vlan 100
Switch-2(config-vlan)#exi
Switch-2(config)#interface range fastEthernet 0/1 -3
Switch-2(config-if-range)#switchport access vlan 100
Switch-2(config-if-range)#switchport mode access
Switch-2(config-if-range)#no sh
Switch-2(config-if-range)#exit
Switch-2(config)#interface vlan 100
Switch-2(config-if)#ip address 172.17.20.254 255.255.255.0
Switch-2(config-if)#no sh
Router-2:
Router-2(config)#ip route 172.17.10.0 255.255.255.0 10.255.255.189
Router-2(config)#ip access-list standard inside
Router-2(config-std-nacl)#deny host 172.17.20.2
Router-2(config-std-nacl)#permit 172.17.20.0 0.0.0.255
Router-2(config-std-nacl)#exit
Router-2(config)#ip nat inside source list inside interface fastEthernet 0/1 overload
Router-2(config)#ip nat inside source static tcp 172.17.20.2 80 10.255.255.190 80
Router-2(config)#interface fastEthernet 0/0
Router-2(config-if)#ip addr 172.17.20.3 255.255.255.0
Router-2(config-if)#ip nat inside
Router-2(config-if)#no sh
Router-2(config-if)#exit
Router-2(config)#interface fastEthernet 0/1
Router-2(config-if)#ip addr 10.255.255.190 255.255.255.252
Router-2(config-if)#ip nat outside
Router-2(config-if)#no sh
Router-2(config-if)#exit
Router-1:
Router-1(config)#access-list 10 permit 10.255.255.188 0.0.0.3
Router-1(config)#ip nat inside source list 10 interface fastEthernet 0/0 overload
Router-1(config)#ip nat inside source static tcp 10.255.255.190 80 172.17.10.3 80
Router-1(config)#interface fastEthernet 0/1
Router-1(config-if)#ip addr 10.255.255.189 255.255.255.252
Router-1(config-if)#ip nat inside
Router-1(config-if)#no sh
Router-1(config-if)#exit
Router-1(config)#interface fastEthernet 0/0
Router-1(config-if)#ip addr 172.17.10.3 255.255.255.0
Router-1(config-if)#ip nat outside
Router-1(config-if)#no sh
Switch-1:
Switch-1(config)#ip routing
Switch-1(config)#vlan 100
Switch-1(config-vlan)#exit
Switch-1(config)#interface range fastEthernet 0/1 -3
Switch-1(config-if-range)#switchport access vlan 100
Switch-1(config-if-range)#switchport mode access
Switch-1(config-if-range)#no sh
Switch-1(config-if-range)#exit
Switch-1(config)#interface vlan 100
Switch-1(config-if)#ip addr 172.17.10.254 255.255.255.0
Switch-1(config-if)#no sh
验证:
PKT file address:http://down.51cto.com/data/807660


























