一.配置静态NAT
1.给PC1,PC2,配置ip地址
2.给R1,R2配置接口IP
[r2]interface GigabitEthernet 0/0/0 [r2-GigabitEthernet0/0/1]ip address 192.168.1.254 24 [r2-GigabitEthernet0/0/1]quit [r2]interface GigabitEthernet 0/0/1 [r2-GigabitEthernet0/0/1]ip address 201.10.10.1 24
[r2]interface GigabitEthernet 0/0/1 [r2-GigabitEthernet0/0/1]ip address 201.10.10.2 24
3.在R1上配置静态NAT
[r1-GigabitEthernet0/0/1]nat static global 202.10.10.4 inside 192.168.1.1 [r1-GigabitEthernet0/0/1]nat static global 202.10.10.4 inside 192.168.1.2
4.查看配置结果
二.配置动态NAT
[r1]nat address-group 1 202.10.10.1 220.10.10.200
[r1]acl [r1]acl 2000 [r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]quit
[r1]interface g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat
验证配置 <r1>display nat address-group 1
配置动态NAT 第一步定义公网地址范围 第二步定义私网地址范围 第三步在公网接口将公网地址池和私网地址池关联在一起
三.easyIP的配置 [r1]acl [r1]acl 2000 [r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]quit
[r1]interface g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000
工作方式和NAPT一样,转换后的公网IP为路由器出口的公网IP
四.NAPT的配置 1.配置NAPT
[r1]nat address-group 1 202.10.10.1 220.10.10.1
[r1]acl [r1]acl 2000 [r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]quit
[r1]interface g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1
NAPT的配置方式和动态NAT类似,只是在最后调用公网和私网地址池时 不加no-pat参数即可