一.配置静态NAT

1.给PC1,PC2,配置ip地址

2.给R1,R2配置接口IP

[r2]interface GigabitEthernet 0/0/0 [r2-GigabitEthernet0/0/1]ip address 192.168.1.254 24 [r2-GigabitEthernet0/0/1]quit [r2]interface GigabitEthernet 0/0/1 [r2-GigabitEthernet0/0/1]ip address 201.10.10.1 24

[r2]interface GigabitEthernet 0/0/1 [r2-GigabitEthernet0/0/1]ip address 201.10.10.2 24

3.在R1上配置静态NAT

[r1-GigabitEthernet0/0/1]nat static global 202.10.10.4 inside 192.168.1.1 [r1-GigabitEthernet0/0/1]nat static global 202.10.10.4 inside 192.168.1.2

4.查看配置结果

二.配置动态NAT

[r1]nat address-group 1 202.10.10.1 220.10.10.200

[r1]acl [r1]acl 2000 [r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]quit

[r1]interface g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat

验证配置 <r1>display nat address-group 1

配置动态NAT 第一步定义公网地址范围 第二步定义私网地址范围 第三步在公网接口将公网地址池和私网地址池关联在一起

三.easyIP的配置 [r1]acl [r1]acl 2000 [r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]quit

[r1]interface g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000

工作方式和NAPT一样,转换后的公网IP为路由器出口的公网IP

四.NAPT的配置 1.配置NAPT

[r1]nat address-group 1 202.10.10.1 220.10.10.1

[r1]acl [r1]acl 2000 [r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]quit

[r1]interface g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1

NAPT的配置方式和动态NAT类似,只是在最后调用公网和私网地址池时 不加no-pat参数即可