1、原理

Easy IP:实现原理和NAPT相同,同时转换IP地址、传输层端口,区别在于Easy IP没有地址池的概念,使用接口地址作为NAT转换的公有地址

适用场合:需要具有IP地址

2、网络拓扑图

EASY IP 配置实例_Standard

3、具体配置

sw1

<sw1>display current-configuration  

#

sysname sw1

#

vlan batch 10 20 30 999

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

dhcp enable

#

diffserv domain default

#

drop-profile default

#

ip pool dhcpvlan10

gateway-list 20.1.1.1

network 20.1.1.0 mask 255.255.255.0

lease day 10 hour 0 minute 0

dns-list 8.8.8.8

#

ip pool dhcpvlan20

gateway-list 30.1.1.1

network 30.1.1.0 mask 255.255.255.0

lease day 10 hour 0 minute 0

dns-list 8.8.8.8

#

aaa

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default

domain default_admin

local-user admin password simple admin

local-user admin service-type http

#

interface Vlanif1

#

interface Vlanif10

ip address 20.1.1.1 255.255.255.0

dhcp select global

#

interface Vlanif20

ip address 30.1.1.1 255.255.255.0

dhcp select global

#

interface Vlanif999

ip address 10.1.1.1 255.255.255.0

#

interface MEth0/0/1

#

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 2 to 4094

#

interface GigabitEthernet0/0/2

port link-type access

port default vlan 999

#

interface GigabitEthernet0/0/3

#

interface GigabitEthernet0/0/4

#

interface GigabitEthernet0/0/5

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

ip route-static 0.0.0.0 0.0.0.0 10.1.1.2

#

user-interface con 0

user-interface vty 0 4

#

return

<sw1>

R1:

<r1>display current-configuration  

[V200R003C00]

#

sysname r1

#

snmp-agent local-engineid 800007DB03000000000000

snmp-agent  

#

clock timezone China-Standard-Time minus 08:00:00

#

portal local-server load portalpage.zip

#

drop illegal-mac alarm

#

set cpu-usage threshold 80 restore 75

#

acl number 2000  

rule 5 permit source 10.1.1.0 0.0.0.255  

rule 10 permit source 20.1.1.0 0.0.0.255  

rule 15 permit source 30.1.1.0 0.0.0.255  

#

aaa  

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default  

domain default_admin  

local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$

local-user admin service-type http

#

firewall zone Local

priority 15

#

interface GigabitEthernet0/0/0

ip address 10.1.1.2 255.255.255.0  

#

interface GigabitEthernet0/0/1

ip address 100.1.1.1 255.255.255.0  

nat outbound 2000

#

interface GigabitEthernet0/0/2

#

interface NULL0

#

ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/0 10.1.1.1

ip route-static 0.0.0.0 0.0.0.0 100.1.1.2

#

user-interface con 0

authentication-mode password

user-interface vty 0 4

user-interface vty 16 20

#

wlan ac

#

return

<r1>

4、结果

PC>ping 100.1.1.2//外网


Ping 100.1.1.2: 32 data bytes, Press Ctrl_C to break

From 100.1.1.2: bytes=32 seq=1 ttl=253 time=62 ms

From 100.1.1.2: bytes=32 seq=2 ttl=253 time=63 ms

From 100.1.1.2: bytes=32 seq=3 ttl=253 time=62 ms

From 100.1.1.2: bytes=32 seq=4 ttl=253 time=47 ms

From 100.1.1.2: bytes=32 seq=5 ttl=253 time=78 ms


--- 100.1.1.2 ping statistics ---

 5 packet(s) transmitted

 5 packet(s) received

 0.00% packet loss

 round-trip min/avg/max = 47/62/78 ms


PC>