´ÊÓï½âÊÍ
N£Á£Ô£¨Network Address Translation£¬ÍøÂçµØַת»»£©ÊÇÒ»ÖÖÍøÂç¼¼Êõ£¬Ëü¿ÉÒÔ½«Ò»¸öÍøÂçÖеÄÒ»¸ö»ò¶à¸öÄÚ²¿IPµØַת»»ÎªÒ»¸öÍⲿIPµØÖ·£¬ÒÔʵÏÖÍøÂçµÄÒþ²Ø¡£ N£Á£Ô¼¼Êõ×î³õÊÇΪÁ˽â¾öIPv4µØÖ·¶ÌȱµÄÎÊÌâ¶ø·¢Ã÷µÄ£¬Ëü¿ÉÒÔ°ïÖúÆóҵʹÓÃÒ»¸ö¹«¹²IPµØÖ·À´Á¬½Ó¶à¸öÄÚ²¿É豸£¬´Ó¶ø½ÚÊ¡IPµØÖ·¡£N£Á£Ô¼¼ÊõÒ²¿ÉÒÔÓÃÓÚʵÏÖÍøÂç¸ôÀ룬ÒÔ·ÀÖ¹ÍⲿÍøÂç¹¥»÷ºÍ¶ñÒâÈí¼þ¡£ N£Á£Ô¼¼ÊõµÄÖ÷ÒªÓ¦ÓÃÊÇÔÚ·ÓÉÆ÷ÉÏ£¬Ëü¿ÉÒÔ½«ÄÚ²¿ÍøÂçÖеÄÒ»¸ö»ò¶à¸öIPµØַת»»ÎªÒ»¸öÍⲿIPµØÖ·£¬ÒÔʵÏÖÍøÂçµÄÒþ²Ø¡£Â·ÓÉÆ÷»á¸ù¾ÝÊÕµ½µÄÊý¾Ý°üµÄÔ´IPµØÖ·ºÍ¶Ë¿ÚºÅÀ´È·¶¨½«Êý¾Ý°ü·¢Ë͵½ÄĸöÄÚ²¿IPµØÖ·¡£µ±Â·ÓÉÆ÷½«Êý¾Ý°ü·¢Ë͵½ÍⲿÍøÂçʱ£¬Ëü»á½«Ô´IPµØÖ·Ì滻ΪÍⲿIPµØÖ·£¬ÒÔʵÏÖÍøÂçµÄÒþ²Ø¡£ N£Á£Ô¼¼Êõ»¹¿ÉÒÔÓÃÓÚʵÏÖÍøÂç¸ôÀ룬Ëü¿ÉÒÔ·ÀÖ¹ÍⲿÍøÂç¹¥»÷ºÍ¶ñÒâÈí¼þ¡£N£Á£Ô¼¼Êõ¿ÉÒÔͨ¹ýÏÞÖÆÄÚ²¿ÍøÂçÖеÄÉ豸·ÃÎÊÍⲿÍøÂçÀ´·ÀÖ¹¹¥»÷ºÍ¶ñÒâÈí¼þ¡£N£Á£Ô¼¼Êõ»¹¿ÉÒÔÓÃÓÚʵÏÖ·ÃÎÊ¿ØÖÆ£¬¿ÉÒÔÏÞÖÆÄÚ²¿ÍøÂçÖеÄÉ豸·ÃÎÊÌض¨µÄÍⲿÍøÂç×ÊÔ´¡£ ×ÜÖ®£¬N£Á£Ô¼¼ÊõÊÇÒ»Öַdz£ÓÐÓõÄÍøÂç¼¼Êõ£¬Ëü¿ÉÒÔ°ïÖúÆóÒµ½ÚÊ¡IPµØÖ·£¬ÊµÏÖÍøÂçÒþ²ØºÍÍøÂç¸ôÀ룬ÒÔ¼°ÊµÏÖ·ÃÎÊ¿ØÖÆ¡£ ÍøÂçµØַת»»(NAT)¸ÅÊö ÍøÂçµØַת»»(NAT,Network Address Traslation)±»¹ã·ºÓ¦ÓÃÓÚ¸÷ÖÖÀàÐÍInternet½ÓÈ뷽ʽºÍ±¸ÖÖÀàÐ͵ÄÍøÂçÖС£ÔÒòºÜ¼òµ¥£¬NAT²»½öÍêÃÀµØ½â¾öÁËlPµØÖ·²»×ãµÄÎÊÌ⣬¶øÇÒ»¹Äܹ»ÓÐЧµØ±ÜÃâÀ´×ÔÍøÂçÍⲿµÄ¹¥»÷£¬Òþ²Ø²¢±£»¤ÍøÂçÄÚ²¿µÄ¼ÆËã»ú¡£ ËäÈ»NAT¿ÉÒÔ½èÖúÓÚijЩ´úÀí·þÎñÆ÷δʵÏÖ£¬µ«¿¼Âǵ½ÔËËã³É±¾ºÍÍøÂçÐÔÄÜ£¬ºÜ¶àʱºò¶¼ÊÇÔÚ·ÓÉÆ÷ÉÏÀ´ÊµÏֵġ£ Ëæ׎ÓÈëInternetµÄ¼ÆËã»úÊýÁ¿µÄ²»¶ÏÃÍÔö£¬IPµØÖ·×ÊÔ´Ò²¾ÍÓú¼ÓÏÔµÃ×½½ó¼ûÖâ¡£ÊÂʵÉÏ£¬³ýÁËÖйú½ÌÓýºÍ¿ÆÑмÆËã»úÍø(CERNET)Í⣬һ°ãÓû§¼¸ºõÉêÇë²»µ½Õû¶ÎµÄCÀàIPµØÖ·¡£ÔÚÆäËûISPÄÇÀ¼´Ê¹ÊÇÓµÓм¸°Ų̀¼ÆËã»úµÄ´óÐ;ÖÓòÍøÓû§£¬µ±ËûÃÇÉêÇëIPµØַʱ£¬Ëù·ÖÅäµÄµØÖ·Ò²²»¹ýÖ»Óм¸¸ö»òÊ®¼¸¸öIPµØÖ·¡£ÏÔÈ»£¬ÕâÑùÉÙµÄIPµØÖ·¸ù±¾ÎÞ·¨Âú×ãÍøÂçÓû§µÄÐèÇó£¬ÓÚÊÇÒ²¾Í²úÉúÁËNAT¼¼Êõ¡£ l.NAT¼ò½é ½èÖúÓÚNAT£¬Ë½ÓÐ(±£Áô)µØÖ·µÄ"ÄÚ²¿"ÍøÂçͨ¹ý·ÓÉÆ÷·¢ËÍÊý¾Ý°üʱ£¬Ë½ÓеØÖ·±»×ª»»³ÉºÏ·¨µÄIPµØÖ·£¬Ò»¸ö¾ÖÓòÍøÖ»ÐèʹÓÃÉÙÁ¿IPµØÖ·(ÉõÖÁÊÇ1¸ö)¼´¿ÉʵÏÖ˽ÓеØÖ·ÍøÂçÄÚËùÓмÆËã»úÓëInternetµÄͨÐÅÐèÇó¡£ NAT½«×Ô¶¯ÐÞ¸ÄIP±¨ÎÄÍ·ÉêµÄÔ´IPµØÖ·ºÍÄ¿µÄIPµØÖ·£¬IpµØַУÑéÔòÔÚNAT´¦Àí¹ý³ÌÖÐ×Ô¶¯Íê³É¡£ÓÐЩӦÓóÌÐò½«Ô´IPµØַǶÈëµ½IP±¨ÎĵÄÊý¾Ý²¿·ÖÖУ¬ËùÒÔ»¹ÐèҪͬʱ¶Ô±¨ÎĽøÐÐÐ޸ģ¬ÒÔÆ¥ÅäIPÍ·ÖÐÒѾÐ޸ĹýµÄÔ´IPµØÖ·¡£·ñÔò£¬ÔÚ±¨ÎÄÊý¾Ý¶¼·Ö±ÀǶÈëIPµØÖ·µÄÓ¦ÓóÌÐò¾Í²»ÄÜÕý³£¹¤×÷¡£ 2.NATʵÏÖ·½Ê½ NATµÄʵÏÖ·½Ê½ÓÐÈýÖÖ£¬¼´¾²Ì¬×ª»»¡¢¶¯Ì¬×ª»»ºÍ¶Ë¿Ú¶à·¸´Óᣠ¾²Ì¬×ª»»ÊÇÖ¸½«ÄÚ²¿ÍøÂçµÄ˽ÓÐIPµØַת»»Îª¹«ÓÐIPµØÖ·£¬IPµØÖ·¶ÔÊÇÒ»¶ÔÒ»µÄ£¬ÊÇÒ»³É²»±äµÄ£¬Ä³¸ö˽ÓÐIPµØַֻת»»ÎªÄ³¸ö¹«ÓÐIPµØÖ·¡£½èÖúÓÚ¾²Ì¬×ª»»£¬¿ÉÒÔʵÏÖÍⲿÍøÂç¶ÔÄÚ²¿ÍøÂçÖÐijЩÌض¨É豸(Èç·þÎñÆ÷)µÄ·ÃÎÊ¡£ ¶¯Ì¬×ª»»ÊÇÖ¸½«ÄÚ²¿ÍøÂçµÄ˽ÓÐIPµØַת»»Îª¹«ÓÃIPµØַʱ£¬IPµØÖ·¶ÔÊDz»È·¶¨µÄ£¬¶øÊÇËæ»úµÄ£¬ËùÓб»ÊÚȨ·ÃÎÊÉÏInternetµÄ˽ÓÐIPµØÖ·¿ÉËæ»úת»»ÎªÈκÎÖ¸¶¨µÄºÏ·¨IPµØÖ·¡£Ò²¾ÍÊÇ˵£¬Ö»ÒªÖ¸¶¨ÄÄЩÄÚ²¿µØÖ·¿ÉÒÔ½øÐÐת»»£¬ÒÔ¼°ÓÃÄÄЩºÏ·¨µØÖ·×÷ΪÍⲿµØַʱ£¬¾Í¿ÉÒÔ½øÐж¯Ì¬×ª»»¡£¶¯Ì¬×ª»»¿ÉÒÔʹÓöà¸öºÏ·¨ÍⲿµØÖ·¼¯¡£µ±ISPÌṩµÄºÏ·¨IPµØÖ·ÂÔÉÙÓÚÍøÂçÄÚ²¿µÄ¼ÆËã»úÊýÁ¿Ê±¡£¿ÉÒÔ²ÉÓö¯Ì¬×ª»»µÄ·½Ê½¡£ ¶Ë¿Ú¶à·¸´ÓÃÊÇÖ¸¸Ä±äÍâ³öÊý¾Ý°üµÄÔ´¶Ë¿Ú²¢½øÐж˿Úת»»£¬¼´¶Ë¿ÚµØַת»»(PAT£¬Port Address Translation).²ÉÓö˿ڶà·¸´Ó÷½Ê½¡£ÄÚ²¿ÍøÂçµÄËùÓÐÖ÷»ú¾ù¿É¹²ÏíÒ»¸öºÏ·¨ÍⲿIPµØַʵÏÖ¶ÔInternetµÄ·ÃÎÊ£¬´Ó¶ø¿ÉÒÔ×î´óÏ޶ȵؽÚÔ¼IPµØÖ·×ÊÔ´¡£Í¬Ê±£¬ÓÖ¿ÉÒþ²ØÍøÂçÄÚ²¿µÄËùÓÐÖ÷»ú£¬ÓÐЧ±ÜÃâÀ´×ÔinternetµÄ¹¥»÷¡£Òò´Ë£¬Ä¿Ç°ÍøÂçÖÐÓ¦ÓÃ×î¶àµÄ¾ÍÊǶ˿ڶà·¸´Ó÷½Ê½¡£ 3.ÍøÂçµØַת»»(NAT)µÄʵÏÖ ÔÚÅäÖÃÍøÂçµØַת»»µÄ¹ý³Ì֮ǰ£¬Ê×ÏȱØÐë¸ãÇå³þÄÚ²¿½Ó¿ÚºÍÍⲿ½Ó¡õ£¬ÒÔ¼°ÔÚÄĸöÍⲿ½Ó¿ÚÉÏÆôÓÃNAT¡£Í¨³£Çé¿öÏ£¬Á¬½Óµ½Óû§ÄÚ²¿ÍøÂçµÄ½Ó¿ÚÊÇNATÄÚ²¿½Ó¿Ú£¬¶øÁ¬½Óµ½ÍⲿÍøÂç(ÈçInternet)µÄ½Ó¿ÚÊÇNATÍⲿ½Ó¡õ¡£ 1).¾²Ì¬µØַת»»µÄʵÏÖ ¼ÙÉèÄÚ²¿¾ÖÓòÍøʹÓõÄlPµØÖ·¶ÎΪ192.168.0.1~192.168.0.254£¬Â·ÓÉÆ÷¾ÖÓòÍø¶Ë¡õ(¼´Ä¬ÈÏÍø¹Ø)µÄIPµØַΪ192.168.0.1£¬×ÓÍøÑÚÂëΪ255.255.255.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª61.159.62.128~61.159.62.135£¬Â·ÓÉÆ÷ÔÚ¹ãÓòÍøÖеÄIPµØַΪ61.159.62.129£¬×ÓÍøÑÚÂëΪ255.255.255.248¿ÉÓÃÓÚת»»µÄIPµØÖ··¶Î§Îª61.159.63.130~61.159.62.134¡£ÒªÇó½«ÄÚ²¿ÍøÖ¹192.168.0.2~192.168.0.6·Ö±ðת»»ÎªºÏ·¨IPµØÖ·61.159.62.130~61.159.62.134¡£ µÚÒ»²½£¬ÉèÖÃÍⲿ¶Ë¿Ú¡£ interface serial 0 ip address 61.159.62.129.255.255.255.248 ip nat outside µÚ¶þ²½£¬ÉèÖÃÄÚ²¿¶Ë¿Ú¡£ interface ethernet 0 ip address 192.168.0.1.255.255.255.0 ip nat inside µÚÈý²½£¬ÔÚÄÚ²¿±¾µØÓëÄÚ²¿ºÏ·¨µØÖ·Ö®¼ä½¨Á¢¾²Ì¬µØַת»»¡£ ip nat inside source static ÄÚ²¿±¾µØµØÖ·ÄÚ²¿ºÏ·¨µØÖ· ʾÀý£º ip nat inside source static 192.168.0.2 61.159.62.130//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.2ת»»ÎªºÏ·¨IPµØÖ·61.159.62.130 ip nat inside source static 192.168.0.3 61.159.62.131//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.3ת»»ÎªºÏ·¨IPµØÖ·61.159.62.131 ip nat inside source static 192.168.0.4 61.159.62.132//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.4ת»»ÎªºÏ·¨IPµØÖ·61.159.62.132 ip nat inside source static 192.168.0.5 61.159.62.133//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.5ת»»ÎªºÏ·¨IPµØÖ·61.159.62.133 ip nat inside source static 192.168.0.6 61.159.62.134//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.6ת»»ÎªºÏ·¨IPµØÖ·61.159.62.134 ÖÁ´Ë£¬¾²Ì¬µØַת»»ÅäÖÃÍê±Ï¡£ 2).¶¯Ì¬µØַת»»µÄʵÏÖ ¼ÙÉèÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ172.16.0.1~172.16.0.254,·ÓÉÆ÷¾ÖÓòÍø¶Ë¿Ú£¨¼´Ä¬ÈÏÍø¹Ø£©µÄIPµØַΪ172.16.100.1,×ÓÍøÑÚÂëΪ255.255.2585.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª61.159.62.128~61.159.62.191£¬Â·ÓÉÆ÷ÔÚ¹ãÓòÍøÖеÄIPµØַΪ61.159.62.129,×ÓÍøÑÚÂëΪ255.255.255.192,¿ÉÓÃÓÚת»»µÄIPµØÖ··¶Î§Îª61.159.62.130~61.159.62.190¡£ÒªÇó½«ÄÚ²¿ÍøÖ·172.16.100.1~172.16.100.254¶¯Ì¬×ª»»ÎªºÏ·¨IPµØÖ·61.159.62.130~61.159.62.190¡£ µÚÒ»²½£¬ÉèÖÃÍⲿ¶Ë¿Ú¡£ ÉèÖÃÍⲿ¶Ë¿ÚÃüÁîµÄÓï·¨ÈçÏ£º ip nat outside ʾÀý£º interface serial 0//½øÈë´®Ðж˿Úserial 0 ip address 61.159.62.129 255.255.248//½«ÆäIPµØÖ·Ö¸¶¨Îª61.159.62.129,×ÓÍøÑÚÂëΪ255.255.255.248 ip nat outside //½«´®ÐпÚserial 0ÉèÖÃΪÍâÍø¶Ë¿Ú ×¢Ò⣬¿ÉÒÔ¶¨Òå¶à¸öÍⲿ¶Ë¿Ú¡£ µÚ¶þ²½£¬ÉèÖÃÄÚ²¿¶Ë¿Ú¡£ ÉèÖÃÄÚ²¿½Ó¿ÚÃüÁîµÄÓï·¨ÈçÏ£º ip nat inside ʾÀý£º interface ethernet 0 //½øÈëÒÔÌ«Íø¶Ë¿ÚEthernet 0 ip address 172.16.100.1 255.255.255.0 // ½«ÆäIPµØÖ·Ö¸¶¨Îª172.16.100.1,×ÓÍøÑÚÂëΪ255.255.255.0 ip nat inside //½«Ethernet 0 ÉèÖÃΪÄÚÍø¶Ë¿Ú¡£ ×¢Ò⣬¿ÉÒÔ¶¨Òå¶à¸öÄÚ²¿¶Ë¿Ú¡£ µÚÈý²½£¬¶¨ÒåºÏ·¨IPµØÖ·³Ø¡£ ¶¨ÒåºÏ·¨IPµØÖ·³ØÃüÁîµÄÓï·¨ÈçÏ£º ip nat pool µØÖ·³ØÃû³Æ ÆðʼIPµØÖ· ÖÕÖ¹IPµØÖ· ×ÓÍøÑÚÂë ÆäÖУ¬µØÖ·³ØÃû×Ö¿ÉÒÔÈÎÒâÉ趨¡£ ʾÀý£º ip nat pool net 61.159.62.130 61.159.62.190 netmask 255.255.255.192//Ö¸Ã÷µØÖ·»º³å³ØµÄÃû³ÆΪnet,IPµØÖ··¶Î§Îª61.159.62.130~61.159.62.190,×ÓÍøÑÚÂëΪ255.255.255.192¡£ÐèҪעÒâµÄÊÇ£¬¼´Ê¹ÑÚÂëΪ255.255.255.0£¬Ò²»áÓÉÆðʼIPµØÖ·ºÍÖÕÖ¹IPµØÖ·¶ÔIPµØÖ·³Ø½øÐÐÏÞÖÆ¡£ »òip nat pool test 61.159.62.130 61.159.62.190 prefix-length 26 ×¢Ò⣬Èç¹ûÓжà¸öºÏ·¨IPµØÖ··¶Î§£¬¿ÉÒÔ·Ö±ðÌí¼Ó¡£ÀýÈ磬Èç¹û»¹ÓÐÒ»¶ÎºÏ·¨IPµØÖ··¶Î§Îª"211.82.216.1~211.82.216.254"£¬ÄÇô£¬¿ÉÒÔÔÙͨ¹ýÏÂÊöÃüÁÆäÌí¼ÓÖÁ»º³å³ØÖС£ ip nat pool cernet 211.82.216.1 211.82.216.254 netmask 255.255.255.0 »ò ip nat pool test 211.82.216.1 211.82.216.254 prefix-length 24 µÚËIJ½£¬¶¨ÒåÄÚ²¿ÍøÂçÖÐÔÊÐí·ÃÎÊInternetµÄ·ÃÎÊÁÐ±í¡£ ¶¨ÒåÄÚ²¿·ÃÎÊÁбíÃüÁîµÄÓï·¨ÈçÏ£º access-listl ±êºÅ permit Ô´µØÖ· ͨÅä·û£¨ÆäÖУ¬±êºÅΪ1~99Ö®¼äµÄÕûÊý£© access-listl permit 172.16.100.0 0.0.0.255 //ÔÊÐí·ÃÎÊInternetµÄÍø¶ÎΪ172.16.100.0~172.16.100.255£¬Ö÷»úÑÚÂëΪ0.0.0.255¡£ÐèҪעÒâµÄÊÇ£¬ÔÚÕâÀï²ÉÓõÄÊÇÖ÷»úÑÚÂ룬¶ø·Ç×ÓÍøÑÚÂë¡£×ÓÍøÑÚÂëÓëÖ÷»úÑÚÂëµÄ¹ØϵΪ£ºÖ÷»úÑÚÂë+×ÓÍøÑÚÂë=255.255.255.255¡£ÀýÈ磬×ÓÍøÑÚÂëΪ255.255.0.0£¬ÔòÖ÷»úÑÚÂëΪ0.0.255.255£»×ÓÍøÑÚÂëΪ255.0.0.0,ÔòÖ÷»úÑÚÂëΪ0.255.255.255;×ÓÍøÑÚÂëΪ255.252.0.0,ÔòÖ÷»úÑÚÂëΪ0.3.255.255;×ÓÍøÑÚÂëΪ255.255.255.192£¬¸ÕÖ÷»úÑÚÂëΪ 0.0.0.63¡£ ÁíÍ⣬Èç¹ûÏ뽫¶à¸öIPµØÖ·¶Îת»»ÎªºÏ·¨IPµØÖ·£¬¿ÉÒÔÌí¼Ó¶à¸ö·ÃÎÊÁÐ±í¡£ÀýÈ磬µ±Óû½«172.16.98.0~172.16.98.255ºÍ172.16.99.0~172.16.99.255ת»»ÎªºÏ·¨IPµØַʱ£¬Ó¦µ±Ìí¼ÓÏÂÊöÃüÁ access-list2 permit 172.16.98.0~0.0.0.255 access-list2 permit 172.16.99.0~0.0.0.255 µÚÎå²½£¬ÊµÏÖÍøÂçµØַת»»¡£ ÔÚÈ«¾ÖÉèÖÃģʽÏ£¬½«ÓÉaccess-listÖ¸¶¨µÄÄÚ²¿±¾µØµØÖ·ÓëÖ¸¶¨µÄÄÚ²¿ºÏ·¨µØÖ·³Ø½øÐеØַת»»¡£ÃüÁîÓï·¨ÈçÏ£º ip nat inside source list ·ÃÎÊÁбí±êºÅ pool ÄÚ²¿ºÏ·¨µØÖ·³ØÃû×Ö Ê¾Àý£º ip nat inside source list 1 pool chinanet Èç¹ûÓжà¸öÄÚ²¿·ÃÎÊÁÐ±í£¬¿ÉÒÔÒ»Ò»Ìí¼Ó£¬ÒÔʵÏÖÍøÂçµØַת»»£¬Èç ip nat insde source list 2 pool chinanet ip nat insde source list 2 pool chinanet Èç¹ûÓжà¸öµØÖ·³Ø£¬Ò²¿ÉÒÔÒ»Ò»Ìí¼Ó£¬ÒÔÔö¼ÓºÏ·¨µØÖ·³Ø·¶Î§£¬Èç ip nat insde source list 2 pool cernet ip nat insde source list 2 pool cernet ip nat insde source list 2 pool cernet ÖÁ´Ë£¬¶¯Ì¬µØַת»»ÉèÖÃÍê±Ï¡£ 3).¶Ë¿Ú¸´Óö¯Ì¬µØַת»» ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ10.100.100.1~10.100.100.254,·ÓÉÆ÷¾ÖÓòÍø¶Ë¿Ú£¨¼´Ä¬ÈÏÍø¹Ø£©µÄIPµØַΪ10.100.100.1£¬×ÓÍøÑÚÂëΪ255.255.255.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.99.160.0~202.99.160.3,·ÓÉÆ÷¹ãÓòÍøÖеÄIPµØַΪ202.99.160.1,×ÓÍøÑÚÂëΪ255.255.255.252£¬¿ÉÓÃÓÚת»»µÄIPµØַΪ202.99.160.2¡£ÒªÇó½«ÄÚ²¿ÍøÖ·10.100.100.1~10.100.100.254 ת»»ÎªºÏ·¨IPµØÖ·202.99.160.2¡£ µÚÒ»²½£¬ÉèÖÃÍⲿ¶Ë¿Ú¡£ interface serial 0 ip address 202.99.160.1 255.255.255.252 in nat outside µÚ¶þ²½£¬ÉèÖÃÄÚ²¿¶Ë¿Ú¡£ interface ethernet 0 ?ip address 10.100.100.1 255.255.255.0 ?ip nat inside µÚÈý²½£¬¶¨ÒåºÏ·¨IPµØÖ·³Ø¡£ in nat pool onlyone 202.99.160.2 202.99.160.2 netmask 255.255.255.252 // Ö¸Ã÷µØÖ·»º³å³ØµÄÃû³ÆΪonlyone,IPµØÖ··¶Î§Îª202.99.160.2,×ÓÍøÑÚÂëΪ255.255.255.252¡£ÓÉÓÚ±¾ÀýÖ»ÓÐÒ»¸öIPµØÖ·¿ÉÓã¬ËùÒÔ£¬ÆðʼIPµØÖ·ÓëÖÕÖ¹IPµØÖ·¾ùΪ202.99.160.2¡£Èç¹ûÓжà¸öIPµØÖ·£¬ÔòÓ¦µ±·Ö±ð¼üÈëÆðÖ¹µÄIPÖ±Ö·¡£ µÚËIJ½£¬¶¨ÒåÄÚ²¿·ÃÎÊÁС£ access-list 1 permit 10.100.100.0 0.0.0.255 ÔÊÐí·ÃÎÊInternetrµÄÍø¶ÎΪ10.100.100.0~10.100.100.255£¬×ÓÍøÑÚÂëΪ255.255.255.0¡£ÐèҪעÒâµÄÊÇ£¬ÔÚÕâÀï×ÓÍøÑÚÂëµÄ˳Ðò¸úƽ³£ËùдµÄ˳ÐòÏà·´£¬¼´0.255.255.255¡£ µÚÎå²½£¬ÉèÖø´Óö¯Ì¬µØַת»»¡£ ÔÚÈ«¾ÖÉèÖÃģʽÏ£¬ÉèÖÃÔÚÄÚ²¿µÄ±¾µØµØÖ·ÓëÄÚ²¿ºÏ·¨IPµØÖ·¼ä½¨Á¢¸´Óö¯Ì¬µØַת»»¡£ÃüÁîÓï·¨ÈçÏ£º ip nat inside source list·ÃÎÊÁбíºÅpoolÄÚ²¿ºÏ·¨µØÖ·³ØÃû×Öoverload ʾÀý£º ip nat inside source list1 pool onlyone overload //ÒԶ˿ڸ´Ó÷½Ê½£¬½«·ÃÎÊÁбí1ÖеÄ˽ÓÐIPµØַת»»Îªonlyone IPµØÖ·³ØÖж¨ÒåµÄºÏ·¨IPµØÖ·¡£ ÖÁ´Ë£¬¶Ë¿Ú¸´Óö¯Ì¬µØַת»»Íê³É¡£ ÍøÂçµØַת»»(NAT)-ʵÀý ʾÀýÒ»£ºÈ«²¿²ÉÓö˿ڸ´ÓõØַת»» µ±ISP·ÖÅäµÄIPµØÖ·ÊýÁ¿ºÜÉÙ£¬ÍøÂçÓÖûÓÐÆäËûÌØÊâÐèÇ󣬼´ÎÞÐèΪInternetÌṩÍøÂç·þÎñʱ£¬¿É²ÉÓö˿ÚÀûÓõØַת»»·½Ê½£¬Ê¹ÍøÂçÄڵļÆËã»ú²ÉÓÃͬһIPµØÖ··ÃÎÊInternet£¬ÔÚ½ÚÔ¼IPµØÖ·×ÊÔ´µÄͬʱ£¬ÓÖ¿ÉÓÐЧ±£»¤ÍøÂçÄÚ²¿µÄ¼ÆËã»ú¡£ ÍøÂç»·¾³Îª£º ¾ÖÓòÍø²ÉÓÃ10Mb/s¹âÏË£¬ÒÔ³ÇÓòÍø·½Ê½½ÓÈëInternet£¬Èçͼ4-2-2Ëùʾ¡£Â·ÓÉÆ÷Ñ¡ÓÃÓµÓÐ2¸ö10/100 Mb/s×ÔÊÊÓ¦¶Ë¿ÚµÄCisco 2611¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ192.168.100.1~192.101.254£¬¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ192.168.100.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.99.160.128~202.99.160.131,Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ202.99.160.129,×ÓÍøÑÚÂëΪ255.255.255.252¡£¿ÉÓÃÓÚת»»µÄIPµØַΪ202.99.160.130¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet¡£ °¸Àý·ÖÎö£º ¼ÈȻֻÓÐÒ»¸ö¿ÉÓõĺϷ¨IPµØÖ·£¬Í¬Ê±´¦ÓÚ¾ÖÓòÍøµÄ·þÎñÆ÷ÓÖֻΪ¾ÖÓòÍøÌṩ·þÎñ£¬¶ø²»ÔÊÐíInternetÖеÄÖ÷»ú¶ÔÆä·ÃÎÊ£¬Òò´ËÍêÈ«¿ÉÒÔ²ÉÓö˿ڸ´ÓõØַת»»·½Ê½ÊµÏÖNAT£¬Ê¹µÃÍøÂçÄÚµÄËùÓмÆËã»ú¾ù¿É¶ÀÁ¢·ÃÎÊInternet¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/0 ip address 192.168.100.1 255.255.0.0 //¶¨Òå±¾µØ¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat inside // ¶¨ÒåΪ±¾µØ¶Ë¿Ú ! interface fastethernet0/1 ip address 202.99.160.129 255.255.255.252 duplx auto speed auto ip nat outside ! ip nat pool onlyone 202.99.160.130 202.99.160.130 netmadk 255.255.255.252 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪonlyone access-list 1 permit 192.168.100.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí access-list 1 permit 192.168.100.0 0.0.0.255 ip nat inside source list1 pool onlyone overload //²ÉÓö˿ڸ´Óö¯Ì¬µØַת»» ʾÀý¶þ£º¶¯Ì¬µØÖ·+¶Ë¿Ú¸´ÓõØַת»» Ðí¶àFTPÍøÕ¾¿¼Âǵ½·þÎñÆ÷ÐÔÄܺÍInternetÁ¬½Ó´ø¿íµÄÕ¼ÓÃÎÊÌ⣬¶¼ÏÞÖÆͬһIPµØÖ·µÄ¶à¸ö½ø³Ì·ÃÎÊ¡£Èç¹û²ÉÓö˿ڸ´µØַת»»·½Ê½£¬ÔòÍøÂçÄÚµÄËùÒÔ¼ÆËã»ú¶¼²ÉÓÃͬһIPµØÖ··ÃÎÊInternet,ÄÇô£¬½«Òò´Ë¶ø±»½ûÖ¹¶Ô¸ÃÍøÕ¾µÄ·ÃÎÊ¡£ËùÒÔ£¬µ±ÌṩµÄºÏ·¨IPµØÖ·ÊýÁ¿ÉÔ¶àʱ£¬¿Éͬʱ²ÉÓö˿ڸ´ÓúͶ¯Ì¬µØַת»»·½Ê½£¬´Ó¶ø¼È¿É±£Ö¤ËùÓÐÓû§¶¼Äܹ»»ñµÃ·ÃÎÊInternetµÄȨÁ¦£¬Í¬Ê±£¬ÓÖ²»Ö¡¢Ä³Ð©¼ÆËã»úÒòʹÓÃͬһIPµØÖ·¶ø±»ÏÞÖÆȨÏÞ¡£ÐèҪעÒâµÄÊÇ£¬ÓÉÓÚËùÓмÆËã»ú¶¼²ÉÓö¯Ì¬µØַת»»·½Ê½£¬Òò´ËInternetÖеÄËùÓмÆËã»ú½«ÎÞ·¨ÊµÏÖ¶ÔÍøÂçÄÚ²¿·þÎñÆ÷µÄ·ÃÎÊ¡£ ÍøÂç»·¾³£º ¾ÖÓòÍøÒÔ2Mb/s DNAרÏß½ÓÈëInternet£¬Â·ÓÉÆ÷Ñ¡Óð²×°Á˹ãÓòÍøÄ£¿éµÄCisco 2611,Èçͼ4-2-2Ëùʾ¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ172.16.100.1~172.16.102.254,¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ172.16.100.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.99.160.128~202.99.160.129,×ÓÍøÑÚÂëΪ255.255.255.192,¿ÉÓÃÓÚת»»µÄIPµØÖ··¶Î§Îª202.99.160.130~202.99.160.190¡£ÒªÇóÍøÂ粿·ÖµÄ²¿·Ö¼ÆËã»ú¿ÉÒÔ²»ÊÜÈκÎÏÞÖƵطÃÎÊInternet£¬·þÎñÆ÷ÎÞÐèÌṩInternet·ÃÎÊ·þÎñ¡£ °¸Àý·ÖÎö£º ¼ÈȻҪÇóÍøÂçÖеIJ¿·Ö¼ÆËã»ú¿ÉÒÔ²»ÊÜÈκÎÏÞÖƵطÃÎÊInternet,ͬʱ£¬·þÎñÆ÷ÎÞÐèÌṩInternet·ÃÎÊ·þÎñ£¬ÄÇô£¬Ö»Ðè²ÉÓö¯Ì¬µØַת»»+¶Ë¿Ú¸´ÓõØַת»»·½Ê½¼´¿ÉʵÏÖ¡£²¿·ÖÓÐÌØÊâÐèÇóµÄ¼ÆËã»ú²ÉÓö¯Ì¬µØַת»»µÄNAT·½Ê½£¬ÆäËû¼ÆËã»úÔò²ÉÓö˿ڸ´ÓõØַת»»µÄNAT·½Ê½¡£Òò´Ë£¬²¿·ÖÓÐÌØÊâÐèÇóµÄ¼ÆËã»ú¿É²ÉÓÃÄÚ²¿ÍøÖ·172.16.100.1~172.16.100.254£¬²¢¶¯Ì¬×ª»»ÎªºÏ·¨µØÖ·202.99.160.130~202.99.160.189£¬ÆäËû¼ÆËã»ú²ÉÓÃÄÚ²¿ÍøÖ·172.16.101.1~172.16.102.254,È«²¿×ª»»Îª202.99.160.190¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/1 ip address 10.100.100.1 255.255.255.0 //¶¨Òå¾ÖÓòÍø¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat inside //¶¨ÒåΪ¾ÖÓò¶Ë¿Ú ! interface serial 0/0 ip address 202.99.160.129 255.255.255.192 //¶¨Òå¹ãÓòÍø¶Ë¿ÚIPµØÖ· ! duplex auto speed auto ip nat outside //¶¨ÒåΪ¹ãÓò¶Ë¿Ú ! ip nat pool public 202.99.160.130 202.130.160.190 netmask 255.255.255.192 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪpublic ip nat pool super 202.99.160.130 202.130.160.189 netmask 255.255.255.192 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪsuper ip nat inside source list1 pool super //¶¨ÒåÁбí´ï1²ÉÓö¯Ì¬µØַת»» ip nat inside source list2 pool public overload? //¶¨ÒåÁбí2²ÉÓö˿ڸ´ÓõØַת»» access-list1 permit 172.16.100.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí1 access-list2 permit 172.16.102.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí2 access-list2 permit 172.16.102.0 0.0.0.255 ʾÀýÈý£º¾²Ì¬µØַת»»+¶Ë¿Ú¸´ÓõØַת»» ÆäʵÔںܶàʱºò£¬ÍøÂçÖеķþÎñÆ÷¼ÈΪÍøÂçÄÚ²¿µÄ¿Í»§ÌṩÍøÂç·þÎñ£¬ÓÖͬʱΪInternetÖеÄÓû§Ìṩ·ÃÎÊ·þÎñ¡£Òò´Ë£¬Èç¹û²ÉÓö˿ڸ´ÓõØַת»»»ò¶¯Ì¬µØַת»»£¬½«ÓÉÓÚÎÞ·¨È·¶¨·þÎñÆ÷µÄIPµØÖ·£¬¶øµ¼ÖÂInternetÓû§ÎÞ·¨ÊµÏÖ¶ÔÍøÂçÄÚ²¿·þÎñÆ÷µÄ·ÃÎÊ¡£´Ëʱ£¬¾ÍÓ¦µ±²ÉÓþ²Ì¬µØַת»»+¶Ë¿Ú¸´ÓõØַת»»µÄNAT·½Ê½¡£Ò²¾ÍÊÇ˵£¬¶Ô·þÎñÆ÷²ÉÓþ²Ì¬µØַת»»£¬ÒÔÈ·±£·þÎñÆ÷ÓµÓй̶¨µÄºÏ·¨IPµØÖ·¡£¶ø¶ÔÆÕͨµÄ¿Í»§¼ÆËã»úÔò²ÉÓö˿ڸ´ÓõØַת»»£¬Ê¹ËùÓÐÓû§¶¼ÏíÓзÃÎÊInternetµÄȨÁ¦¡£ ÍøÂç»·¾³Îª£º ¾ÖÓòÍø²ÉÓÃ10Mb/s¹âÏË£¬ÒÔ³ÇÓòÍø·½Ê½½ÓÈëInternet£¬Èçͼ4-2-2Ëùʾ¡£Â·ÓÉÆ÷Ñ¡ÓÃÓµÓÐ2¸ö10/100 Mb/s×ÔÊÊÓ¦¶Ë¿ÚµÄCisco 2611¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ10.18.100.1~10.18.104.254,¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ10.18.100.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª211.82.220.80~211.82.220.87£¬Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ211.82.220.81,×ÓÍøÑÚÂëΪ255.255.255.248¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet£¬²¢ÇÒÔÚInternetÖÐÌṩWeb¡¢E-mail¡¢FTPºÍMediaµÈ4ÖÖ·þÎñ¡£ °¸Àý·ÖÎö£º ¼ÈÈ»ÍøÂçÄڵķþÎñÆ÷ÒªÇóÄܹ»±»Internet·ÃÎʵ½£¬ÄÇô£¬Õⲿ·ÖÖ÷»ú±ØÐëÓµÓкϷ¨µÄIPµØÖ·£¬Ò²¾ÍÊÇ˵£¬·þÎñÆ÷±ØÐë²ÉÓþ²Ì¬µØַת»»¡£ÆäËû¼ÆËã»úÓÉÓÚûÓÐÈκÎÏÞÖÆ£¬ËùÒÔ£¬¿É²ÉÓö˿ڸ´ÓõØַת»»µÄNAT·½Ê½¡£Òò´Ë£¬·þÎñÆ÷¿É²ÉÓÃÄÚÍøÖ·10.18.100.1~10.18.100.254£¬²¢·Ö±ðÓ³ÉäΪһ¸öºÏ·¨µÄIPµØÖ·¡£ÆäËû¼ÆËã»úÔò²ÉÓÃÄÚ²¿ÍøÖ·10.18.101.1~172.16.104.254,²¢È«²¿×ª»»ÎªÒ»¸öºÏ·¨µÄIPµØÖ·¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/0 ip address 10.18.100.1 255.255.0.0 //¶¨Òå¾ÖÓòÍø¿ÚIPµØÖ· duplex auto speed auto ip nat inside //¶¨Òå¾ÖÓòÍø¿Ú ! interface fastethernet0/1 ip address 211.82.220.81 255.255.255.248 //¶¨Òå¹ãÓòÍø¿ÚIPµØÖ· duplex auto speed auto ip nat outside //¶¨Òå¹ãÓòÍø¿Ú ! ip nat pool every 211.82.220.86 211.82.220.86 netmask 255.255.255.248 //¶¨ÒåºÏ·¨IPµØÖ·³Ø access-list 1 permit 10.18.101.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí1 access-list 1 premit 10.18.102.0 0.0.0.255 access-list 1 premit 10.18.103.0 0.0.0.255 access-list 1 premit 10.18.104.0 0.0.0.255 ip nat inside source list1 pool every overload //¶¨ÒåÁбí´ï1²ÉÓö˿ڸ´ÓõØַת»» ip nat inside source static 10.18.100.10 211.82.220.82 //¶¨Ò徲̬µØַת»» ip nat inside source static 10.18.100.11 211.82.220.83 ip nat inside source static 10.18.100.12 211.82.220.84 ip nat inside source static 10.18.100.13 211.82.220.85 ʾÀýËÄ£ºTCP/UDP¶Ë¿ÚNATÓ³Éä Èç¹ûISPÌṩµÄºÏ·¨IPµØÖ·µÄÊýÁ¿½Ï¶à£¬ÎÒÃÇ×ÔÈ»¿ÉÒÔ²ÉÓþ²Ì¬µØַת»»+¶Ë¿Ú¸´Óö¯Ì¬µØַת»»µÄ·½Ê½µÃÒÔÍêÃÀʵÏÖ¡£µ«Èç¹ûISPÖ»Ìṩ4¸öIPµØÖ·£¬ÆäÖÐ2¸ö×÷ΪÍøÂçºÅºÍ¹ã²¥µØÖ·¶ø²»¿ÉʹÓã¬1¸öIPµØÖ·ÒªÓÃÓÚ·ÓÉÆ÷¶¨ÒåΪĬÈÏÍø¹Ø£¬ ÄÇô½«Ö»Ê£ÏÂ1¸öIPµØÖ·¿ÉÓᣵ±È»ÎÒÃÇÒ²¿ÉÒÔÀûÓÃÕâ¸ö½ö´æµÄÒ»¸öIPµØÖ·²ÉÓö˿ڸ´ÓõØַת»»¼¼Êõ£¬´Ó¶øʵÏÖÕû¸ö¾ÖÓòÍøµÄInternet½ÓÈë¡£µ«ÊÇÓÉÓÚ·þÎñÆ÷Ò²²ÉÓö¯Ì¬¶Ë¿Ú£¬Òò´Ë£¬InternetÖеļÆËã»ú½«ÎÞ·¨·ÃÎʵ½ÍøÂçÄÚ²¿µÄ·þÎñÆ÷¡£ÓÐûÓкõĽâ¾öÎÊÌâµÄ·½°¸ÄØ£¿Õâ¾ÍÊÇTCP/UDP¶Ë¿ÚNATÓ³Éä¡£ ÎÒÃÇÖªµÀ£¬²»Í¬Ó¦ÓóÌÐòʹÓõÄTCP/UDPµÄ¶Ë¿ÚÊDz»Í¬µÄ£¬±ÈÈ磬Web·þÎñʹÓÃ50£¬FTP·þÎñʹÓÃ21£¬SMTP·þÎñʹÓÃ25£¬POP3·þÎñʹÓÃ110£¬µÈµÈ¡£Òò´Ë£¬¿ÉÒÔ½«²»Í¬µÄTCP¶Ë¿Ú°ó¶¨ÖÁ²»Í¬µÄÄÚ²¿IPµØÖ·£¬´Ó¶øֻʹÓÃÒ»¸öºÏ·¨µÄIPµØÖ·£¬¼´¿ÉÔÚÔÊÐíÄÚ²¿ËùÓзþÎñÆ÷±»Internet·ÃÎʵÄͬʱ£¬ÊµÏÖÄÚ²¿ËùÓÐÖ÷»ú¶ÔInternet·ÃÎÊ¡£ ÍøÂç»·¾³£º ¾ÖÓòÍø²ÉÓÃ10Mb/s¹âÏË£¬ÒÔ³ÇÓòÍø·½Ê½½ÓÈëInternet£¬Èçͼ4-2-5Ëùʾ¡£Â·ÓÉÆ÷Ñ¡ÓÃÓµÓÐ2¸ö10/100 Mb/s×ÔÊÊÓ¦¶Ë¿ÚµÄCisco 2611¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ192.168.1.1~192.168.1.254£¬¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ192.168.1.1,×ÓÍøÑÚÂëΪ255.255.255.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª£¬211.82.220.128~211.82.220.131,Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ211.82.220.129,×ÓÍøÑÚÂëΪ255.225.255.252£¬¿ÉÓÃÓÚת»»µÄIPµØַΪ211.82.220.130¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet¡£ °¸Àý·ÖÎö£º ¼ÈȻֻÓÐÒ»¸ö¿ÉÓõĺϷ¨IPµØÖ·£¬µ±È»Ö»ÄܲÉÓö˿ڸ´Ó÷½Ê½ÊµÏÖNAT£¬²»¹ý£¬ÓÉÓÚͬʱÓÖÒªÇóÍøÂçÄÚ²¿µÄ·þÎñÆ÷¿ÉÒÔ±»Internet·ÃÎʵ½£¬Òò´Ë£¬±ØÐëʹÓÃPAT´´½¨TCP/UDP¶Ë¿ÚµÄNATÓ³Éä¡£ÐèҪעÒâµÄÊÇ£¬Ò²¿ÉÒÔÖ±½ÓʹÓùãÓò¶Ë¿Ú´´½¨TCP/UDP¶Ë¿ÚµÄNATÓ³É䣬Ҳ¾ÍÊÇ˵£¬¼´Ê¹Ö»ÓÐÒ»¸öIPµØÖ·£¬Ò²¿ÉÒÔÍêÃÀʵÏֶ˿ڸ´Óá£ÓÉÓںϷ¨IPµØַλÓÚ·ÓÉÆ÷¶Ë¿ÚÉÏ£¬ËùÒÔ£¬²»ÔÙÐèÒª¶¨ÒåNAT³Ø£¬Ö»¼òµ¥µØʹÓÃinside source listÓï¾ä¼´¿É¡£ ÐèҪעÒâµÄÊÇ£¬ÓÉÓÚÿÖÖÓ¦Ó÷þÎñ¶¼ÓÐ×Ô¼ºÄ¬ÈϵĶ˿ڣ¬ËùÒÔ£¬ÕâÖÖNAT·½Ê½Ï£¬ÍøÂçÄÚ²¿Ã¿ÖÖÓ¦Ó÷þÎñÖÐÖ»Äܸ÷×ÔÓÐһ̨·þÎñÆ÷³ÉΪInternetÖеÄÖ÷»ú£¬ÀýÈ磬ֻÄÜÓÐһ̨Web·þÎñÆ÷£¬Ò»Ì¨E-mail·þÎñ£¬Ò»Ì¨FTP·þÎñÆ÷¡£¾¡¹Ü¿ÉÒÔ²ÉÓøıäĬÈ϶˿ڵķ½Ê½´´½¨¶ą̀ӦÓ÷þÎñÆ÷£¬µ«ÕâÖÖ·þÎñÆ÷ÔÚ·ÃÎÊʱ±È½ÏÀ§ÄÑ£¬ÒªÇóÓû§±ØÐëÏÈÁ˽âijÖÖ·þÎñ²ÉÓõÄÐÂTCP¶Ë¿Ú¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/0 ip address 192.168.1.1 255.255.255.0//Ö¸¶¨¾ÖÓòÍø¿ÚµÄIPµØÖ· duplex auto speed auto ip nat inside //Ö¸¶¨¾ÖÓòÍø½Ó¿Ú ! interface fastethernet0/1 ip address 211.82.220.129 255.255.255.248 //Ö¸¶¨¹ãÓòÍø¿ÚµÄIPµØÖ· access-list 1 permit 192.168.1.0 0.0.0.255 ! ip nat inside source list1 interface fastethernet0/1 overload //ÆôÓö˿ڸ´ÓõØַת»»£¬²¢Ö±½Ó²ÉÓÃfastethernet0/1µÄIPµØÖ·¡£ ip nat inside source static tcp 192.168.1.11 80 202.99.160.129.80 ip nat inside source static tcp 192.168.1.12 21 202.99.160.129.21 ip nat inside source static tcp 192.168.1.13 25 202.99.160.129.25 ip nat inside source static tcp 192.168.1.13 110 202.99.160.129 110 ʾÀýÎ壺ÀûÓõØַת»»ÊµÏÖ¸ºÔؾùºâ Ëæ×Å·ÃÎÊÁ¿µÄÉÏÉý£¬µ±Ò»Ì¨·þÎñÆ÷ÄÑÒÔʤÈÎʱ£¬¾Í±ØÐë²ÉÓøºÔؾùºâ¼¼Êõ£¬½«´óÁ¿µÄ·ÃÎʺÏÀíµØ·ÖÅäÖÁ¶ą̀·þÎñÆ÷ÉÏ¡£µ±È»£¬ÊµÏÖ¸ºÔؾùºâµÄÊÖ¶ÎÓÐÐí¶àÖÖ£¬±ÈÈç¿ÉÒÔ²ÉÓ÷þÎñÆ÷Ⱥ¼¯¸ºÔؾùºâ¡¢½»»»»ú¸ºÔؾùºâ¡¢DNS½âÎö¸ºÔؾùºâµÈµÈ¡£ Æäʵ³ý´ËÒÔÍ⣬Ҳ¿ÉÒÔͨ¹ýµØַת»»·½Ê½ÊµÏÖ·þÎñÆ÷µÄ¸ºÔؾùºâ¡£ÊÂʵÉÏ£¬ÕâЩ¸ºÔؾùºâµÄʵÏÖ´ó¶àÊDzÉÓÃÂÖѯ·½Ê½ÊµÏֵģ¬Ê¹Ã¿Ì¨·þÎñÆ÷¶¼ÓµÓÐƽµÈµÄ±»·ÃÎÊ»ú»á¡£ ÍøÂç»·¾³£º ¾ÖÓòÍøÒÔ2Mb/s DDNרÏßÀÈëInternet,·ÓÉÆ÷Ñ¡Óð²×°Á˹ãÓòÍøÄ£¿éµÄCisco 2611,Èçͼ4-2-6Ëùʾ¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ10.1.1.1~10.1.3.254£¬¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ10.1.1.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.110.198.80~202.110.198.87,Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ202.110.198.81,×ÓÍøÑÚÂëΪ255.255.255.248¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet£¬²¢ÇÒÔÚ3̨Web·þÎñÆ÷ºÍ2̨FTP·þÎñÆ÷ʵÏÖ¸ºÔؾùºâ¡£ °¸Àý·ÖÎö£º ¼ÈȻҪÇóÍøÂçÄÚËùÓмÆËã»ú¶¼¿ÉÒÔ½ÓÈëInternet,¶øºÏ·¨IPµØÖ·ÓÖÖ»ÓÐ5¸ö¿ÉÓ㬵±È»¿É²ÉÓö˿ڸ´ÓõØַת»»·½Ê½¡£±¾À´¶Ô·þÎñÆ÷ͨ¹ý²ÉÓþ²Ì¬µØַת»»£¬¸³ÓèÆäºÏ·¨IPµØÖ·¼´¿É¡£µ«ÊÇ£¬ÓÉÓÚ·þÎñÆ÷µÄ·ÃÎÊÁ¿Ì«´ó£¨»òÕßÊÇ·þÎñÆ÷µÄÐÔÄÜÌ«²î£©£¬²»µÃ²»Ê¹Óöą̀·þÎñÆ÷×÷¸ºÔؾùºâ£¬Òò´Ë£¬±ØÐ뽫һ¸öºÏ·¨IPµØַת»»³É¶àÏàÄÚ²¿IPµØÖ·£¬ÒÔÂÖѯ·½Ê½¼õÇáÿ̨·þÎñÆ÷µÄ·ÃÎÊѹÁ¦¡£ ÅäÖÃÎļþ£º interface fastethernet0/1 ip adderss 10.1.1.1 255.255.0.0 //¶¨Òå¾ÖÓòÍø¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat inside //¶¨ÒåΪ¾ÖÓò¶Ë¿Ú ! interface serial 0/0 ip address 202.110.198.81 255.255.255.248 //¶¨Òå¹ãÓòÍø¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat outside //¶¨ÒåΪ¹ãÓò¶Ë¿Ú ! access-list 1 permit 202.110.198.82 //¶¨ÒåÂÖѯµØÖ·Áбí1 access-list 2 permit 202.110.198.83 access-list 3 permit 10.1.1.0 0.0.255.255 //¶¨Òå±¾µØ·ÃÎÊÁбí3 ! ip nat pool websev 10.1.1.2 10.1.1.1 255.255.255.248 type rotary //¶¨ÒåWeb·þÎñÆ÷µÄIPµØÖ·³Ø£¬Rotary¹Ø¼ü×Ö±íʾ׼±¸Ê¹ÓÃÂÖѯ²ßÂÔ´ÓNAT³ØÖÐÈ¡³öÏàÓ¦µÄIPµØÖ·ÓÃÓÚת»»½øÀ´µÄIP±¨ÎÄ£¬·ÃÎÊ202.110.198.82µÄÇëÇó½«ÒÀ´Î·¢Ë͸ø10.1.1.2¡¢10.1.1.3ºÍ10.1.1.4 ip nat pool ftpsev 10.1.1.8 10.1.1.9 255.255.255.248 type rotary ip nat pool normal 202.110.198.84 202.110.198.84 netmask 255.255.255.248 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪnormal ip nat inside destination list 1 pool websev //inside destination list Óï¾ä¶¨ÒåÓëÁбí1ÏàÆ¥ÅäµÄIPµØÖ·µÄ±¨ÎĽ«Ê¹ÓÃÂÖѯ²ßÂÔ ip nat inside destination list 2 pool ftpsev
ÍøÂçµØַת»»(NAT)¸ÅÊö ÍøÂçµØַת»»(NAT,Network Address Traslation)±»¹ã·ºÓ¦ÓÃÓÚ¸÷ÖÖÀàÐÍInternet½ÓÈ뷽ʽºÍ±¸ÖÖÀàÐ͵ÄÍøÂçÖС£ÔÒòºÜ¼òµ¥£¬NAT²»½öÍêÃÀµØ½â¾öÁËlPµØÖ·²»×ãµÄÎÊÌ⣬¶øÇÒ»¹Äܹ»ÓÐЧµØ±ÜÃâÀ´×ÔÍøÂçÍⲿµÄ¹¥»÷£¬Òþ²Ø²¢±£»¤ÍøÂçÄÚ²¿µÄ¼ÆËã»ú¡£ ËäÈ»NAT¿ÉÒÔ½èÖúÓÚijЩ´úÀí·þÎñÆ÷δʵÏÖ£¬µ«¿¼Âǵ½ÔËËã³É±¾ºÍÍøÂçÐÔÄÜ£¬ºÜ¶àʱºò¶¼ÊÇÔÚ·ÓÉÆ÷ÉÏÀ´ÊµÏֵġ£ Ëæ׎ÓÈëInternetµÄ¼ÆËã»úÊýÁ¿µÄ²»¶ÏÃÍÔö£¬IPµØÖ·×ÊÔ´Ò²¾ÍÓú¼ÓÏÔµÃ×½½ó¼ûÖâ¡£ÊÂʵÉÏ£¬³ýÁËÖйú½ÌÓýºÍ¿ÆÑмÆËã»úÍø(CERNET)Í⣬һ°ãÓû§¼¸ºõÉêÇë²»µ½Õû¶ÎµÄCÀàIPµØÖ·¡£ÔÚÆäËûISPÄÇÀ¼´Ê¹ÊÇÓµÓм¸°Ų̀¼ÆËã»úµÄ´óÐ;ÖÓòÍøÓû§£¬µ±ËûÃÇÉêÇëIPµØַʱ£¬Ëù·ÖÅäµÄµØÖ·Ò²²»¹ýÖ»Óм¸¸ö»òÊ®¼¸¸öIPµØÖ·¡£ÏÔÈ»£¬ÕâÑùÉÙµÄIPµØÖ·¸ù±¾ÎÞ·¨Âú×ãÍøÂçÓû§µÄÐèÇó£¬ÓÚÊÇÒ²¾Í²úÉúÁËNAT¼¼Êõ¡£ l.NAT¼ò½é ½èÖúÓÚNAT£¬Ë½ÓÐ(±£Áô)µØÖ·µÄ"ÄÚ²¿"ÍøÂçͨ¹ý·ÓÉÆ÷·¢ËÍÊý¾Ý°üʱ£¬Ë½ÓеØÖ·±»×ª»»³ÉºÏ·¨µÄIPµØÖ·£¬Ò»¸ö¾ÖÓòÍøÖ»ÐèʹÓÃÉÙÁ¿IPµØÖ·(ÉõÖÁÊÇ1¸ö)¼´¿ÉʵÏÖ˽ÓеØÖ·ÍøÂçÄÚËùÓмÆËã»úÓëInternetµÄͨÐÅÐèÇó¡£ NAT½«×Ô¶¯ÐÞ¸ÄIP±¨ÎÄÍ·ÉêµÄÔ´IPµØÖ·ºÍÄ¿µÄIPµØÖ·£¬IpµØַУÑéÔòÔÚNAT´¦Àí¹ý³ÌÖÐ×Ô¶¯Íê³É¡£ÓÐЩӦÓóÌÐò½«Ô´IPµØַǶÈëµ½IP±¨ÎĵÄÊý¾Ý²¿·ÖÖУ¬ËùÒÔ»¹ÐèҪͬʱ¶Ô±¨ÎĽøÐÐÐ޸ģ¬ÒÔÆ¥ÅäIPÍ·ÖÐÒѾÐ޸ĹýµÄÔ´IPµØÖ·¡£·ñÔò£¬ÔÚ±¨ÎÄÊý¾Ý¶¼·Ö±ÀǶÈëIPµØÖ·µÄÓ¦ÓóÌÐò¾Í²»ÄÜÕý³£¹¤×÷¡£ 2.NATʵÏÖ·½Ê½ NATµÄʵÏÖ·½Ê½ÓÐÈýÖÖ£¬¼´¾²Ì¬×ª»»¡¢¶¯Ì¬×ª»»ºÍ¶Ë¿Ú¶à·¸´Óᣠ¾²Ì¬×ª»»ÊÇÖ¸½«ÄÚ²¿ÍøÂçµÄ˽ÓÐIPµØַת»»Îª¹«ÓÐIPµØÖ·£¬IPµØÖ·¶ÔÊÇÒ»¶ÔÒ»µÄ£¬ÊÇÒ»³É²»±äµÄ£¬Ä³¸ö˽ÓÐIPµØַֻת»»ÎªÄ³¸ö¹«ÓÐIPµØÖ·¡£½èÖúÓÚ¾²Ì¬×ª»»£¬¿ÉÒÔʵÏÖÍⲿÍøÂç¶ÔÄÚ²¿ÍøÂçÖÐijЩÌض¨É豸(Èç·þÎñÆ÷)µÄ·ÃÎÊ¡£ ¶¯Ì¬×ª»»ÊÇÖ¸½«ÄÚ²¿ÍøÂçµÄ˽ÓÐIPµØַת»»Îª¹«ÓÃIPµØַʱ£¬IPµØÖ·¶ÔÊDz»È·¶¨µÄ£¬¶øÊÇËæ»úµÄ£¬ËùÓб»ÊÚȨ·ÃÎÊÉÏInternetµÄ˽ÓÐIPµØÖ·¿ÉËæ»úת»»ÎªÈκÎÖ¸¶¨µÄºÏ·¨IPµØÖ·¡£Ò²¾ÍÊÇ˵£¬Ö»ÒªÖ¸¶¨ÄÄЩÄÚ²¿µØÖ·¿ÉÒÔ½øÐÐת»»£¬ÒÔ¼°ÓÃÄÄЩºÏ·¨µØÖ·×÷ΪÍⲿµØַʱ£¬¾Í¿ÉÒÔ½øÐж¯Ì¬×ª»»¡£¶¯Ì¬×ª»»¿ÉÒÔʹÓöà¸öºÏ·¨ÍⲿµØÖ·¼¯¡£µ±ISPÌṩµÄºÏ·¨IPµØÖ·ÂÔÉÙÓÚÍøÂçÄÚ²¿µÄ¼ÆËã»úÊýÁ¿Ê±¡£¿ÉÒÔ²ÉÓö¯Ì¬×ª»»µÄ·½Ê½¡£ ¶Ë¿Ú¶à·¸´ÓÃÊÇÖ¸¸Ä±äÍâ³öÊý¾Ý°üµÄÔ´¶Ë¿Ú²¢½øÐж˿Úת»»£¬¼´¶Ë¿ÚµØַת»»(PAT£¬Port Address Translation).²ÉÓö˿ڶà·¸´Ó÷½Ê½¡£ÄÚ²¿ÍøÂçµÄËùÓÐÖ÷»ú¾ù¿É¹²ÏíÒ»¸öºÏ·¨ÍⲿIPµØַʵÏÖ¶ÔInternetµÄ·ÃÎÊ£¬´Ó¶ø¿ÉÒÔ×î´óÏ޶ȵؽÚÔ¼IPµØÖ·×ÊÔ´¡£Í¬Ê±£¬ÓÖ¿ÉÒþ²ØÍøÂçÄÚ²¿µÄËùÓÐÖ÷»ú£¬ÓÐЧ±ÜÃâÀ´×ÔinternetµÄ¹¥»÷¡£Òò´Ë£¬Ä¿Ç°ÍøÂçÖÐÓ¦ÓÃ×î¶àµÄ¾ÍÊǶ˿ڶà·¸´Ó÷½Ê½¡£ 3.ÍøÂçµØַת»»(NAT)µÄʵÏÖ ÔÚÅäÖÃÍøÂçµØַת»»µÄ¹ý³Ì֮ǰ£¬Ê×ÏȱØÐë¸ãÇå³þÄÚ²¿½Ó¿ÚºÍÍⲿ½Ó¡õ£¬ÒÔ¼°ÔÚÄĸöÍⲿ½Ó¿ÚÉÏÆôÓÃNAT¡£Í¨³£Çé¿öÏ£¬Á¬½Óµ½Óû§ÄÚ²¿ÍøÂçµÄ½Ó¿ÚÊÇNATÄÚ²¿½Ó¿Ú£¬¶øÁ¬½Óµ½ÍⲿÍøÂç(ÈçInternet)µÄ½Ó¿ÚÊÇNATÍⲿ½Ó¡õ¡£ 1).¾²Ì¬µØַת»»µÄʵÏÖ ¼ÙÉèÄÚ²¿¾ÖÓòÍøʹÓõÄlPµØÖ·¶ÎΪ192.168.0.1~192.168.0.254£¬Â·ÓÉÆ÷¾ÖÓòÍø¶Ë¡õ(¼´Ä¬ÈÏÍø¹Ø)µÄIPµØַΪ192.168.0.1£¬×ÓÍøÑÚÂëΪ255.255.255.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª61.159.62.128~61.159.62.135£¬Â·ÓÉÆ÷ÔÚ¹ãÓòÍøÖеÄIPµØַΪ61.159.62.129£¬×ÓÍøÑÚÂëΪ255.255.255.248¿ÉÓÃÓÚת»»µÄIPµØÖ··¶Î§Îª61.159.63.130~61.159.62.134¡£ÒªÇó½«ÄÚ²¿ÍøÖ¹192.168.0.2~192.168.0.6·Ö±ðת»»ÎªºÏ·¨IPµØÖ·61.159.62.130~61.159.62.134¡£ µÚÒ»²½£¬ÉèÖÃÍⲿ¶Ë¿Ú¡£ interface serial 0 ip address 61.159.62.129.255.255.255.248 ip nat outside µÚ¶þ²½£¬ÉèÖÃÄÚ²¿¶Ë¿Ú¡£ interface ethernet 0 ip address 192.168.0.1.255.255.255.0 ip nat inside µÚÈý²½£¬ÔÚÄÚ²¿±¾µØÓëÄÚ²¿ºÏ·¨µØÖ·Ö®¼ä½¨Á¢¾²Ì¬µØַת»»¡£ ip nat inside source static ÄÚ²¿±¾µØµØÖ·ÄÚ²¿ºÏ·¨µØÖ· ʾÀý£º ip nat inside source static 192.168.0.2 61.159.62.130//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.2ת»»ÎªºÏ·¨IPµØÖ·61.159.62.130 ip nat inside source static 192.168.0.3 61.159.62.131//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.3ת»»ÎªºÏ·¨IPµØÖ·61.159.62.131 ip nat inside source static 192.168.0.4 61.159.62.132//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.4ת»»ÎªºÏ·¨IPµØÖ·61.159.62.132 ip nat inside source static 192.168.0.5 61.159.62.133//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.5ת»»ÎªºÏ·¨IPµØÖ·61.159.62.133 ip nat inside source static 192.168.0.6 61.159.62.134//½«ÄÚ²¿ÍøÂçµØÖ·192.168.0.6ת»»ÎªºÏ·¨IPµØÖ·61.159.62.134 ÖÁ´Ë£¬¾²Ì¬µØַת»»ÅäÖÃÍê±Ï¡£ 2).¶¯Ì¬µØַת»»µÄʵÏÖ ¼ÙÉèÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ172.16.0.1~172.16.0.254,·ÓÉÆ÷¾ÖÓòÍø¶Ë¿Ú£¨¼´Ä¬ÈÏÍø¹Ø£©µÄIPµØַΪ172.16.100.1,×ÓÍøÑÚÂëΪ255.255.2585.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª61.159.62.128~61.159.62.191£¬Â·ÓÉÆ÷ÔÚ¹ãÓòÍøÖеÄIPµØַΪ61.159.62.129,×ÓÍøÑÚÂëΪ255.255.255.192,¿ÉÓÃÓÚת»»µÄIPµØÖ··¶Î§Îª61.159.62.130~61.159.62.190¡£ÒªÇó½«ÄÚ²¿ÍøÖ·172.16.100.1~172.16.100.254¶¯Ì¬×ª»»ÎªºÏ·¨IPµØÖ·61.159.62.130~61.159.62.190¡£ µÚÒ»²½£¬ÉèÖÃÍⲿ¶Ë¿Ú¡£ ÉèÖÃÍⲿ¶Ë¿ÚÃüÁîµÄÓï·¨ÈçÏ£º ip nat outside ʾÀý£º interface serial 0//½øÈë´®Ðж˿Úserial 0 ip address 61.159.62.129 255.255.248//½«ÆäIPµØÖ·Ö¸¶¨Îª61.159.62.129,×ÓÍøÑÚÂëΪ255.255.255.248 ip nat outside //½«´®ÐпÚserial 0ÉèÖÃΪÍâÍø¶Ë¿Ú ×¢Ò⣬¿ÉÒÔ¶¨Òå¶à¸öÍⲿ¶Ë¿Ú¡£ µÚ¶þ²½£¬ÉèÖÃÄÚ²¿¶Ë¿Ú¡£ ÉèÖÃÄÚ²¿½Ó¿ÚÃüÁîµÄÓï·¨ÈçÏ£º ip nat inside ʾÀý£º interface ethernet 0 //½øÈëÒÔÌ«Íø¶Ë¿ÚEthernet 0 ip address 172.16.100.1 255.255.255.0 // ½«ÆäIPµØÖ·Ö¸¶¨Îª172.16.100.1,×ÓÍøÑÚÂëΪ255.255.255.0 ip nat inside //½«Ethernet 0 ÉèÖÃΪÄÚÍø¶Ë¿Ú¡£ ×¢Ò⣬¿ÉÒÔ¶¨Òå¶à¸öÄÚ²¿¶Ë¿Ú¡£ µÚÈý²½£¬¶¨ÒåºÏ·¨IPµØÖ·³Ø¡£ ¶¨ÒåºÏ·¨IPµØÖ·³ØÃüÁîµÄÓï·¨ÈçÏ£º ip nat pool µØÖ·³ØÃû³Æ ÆðʼIPµØÖ· ÖÕÖ¹IPµØÖ· ×ÓÍøÑÚÂë ÆäÖУ¬µØÖ·³ØÃû×Ö¿ÉÒÔÈÎÒâÉ趨¡£ ʾÀý£º ip nat pool net 61.159.62.130 61.159.62.190 netmask 255.255.255.192//Ö¸Ã÷µØÖ·»º³å³ØµÄÃû³ÆΪnet,IPµØÖ··¶Î§Îª61.159.62.130~61.159.62.190,×ÓÍøÑÚÂëΪ255.255.255.192¡£ÐèҪעÒâµÄÊÇ£¬¼´Ê¹ÑÚÂëΪ255.255.255.0£¬Ò²»áÓÉÆðʼIPµØÖ·ºÍÖÕÖ¹IPµØÖ·¶ÔIPµØÖ·³Ø½øÐÐÏÞÖÆ¡£ »òip nat pool test 61.159.62.130 61.159.62.190 prefix-length 26 ×¢Ò⣬Èç¹ûÓжà¸öºÏ·¨IPµØÖ··¶Î§£¬¿ÉÒÔ·Ö±ðÌí¼Ó¡£ÀýÈ磬Èç¹û»¹ÓÐÒ»¶ÎºÏ·¨IPµØÖ··¶Î§Îª"211.82.216.1~211.82.216.254"£¬ÄÇô£¬¿ÉÒÔÔÙͨ¹ýÏÂÊöÃüÁÆäÌí¼ÓÖÁ»º³å³ØÖС£ ip nat pool cernet 211.82.216.1 211.82.216.254 netmask 255.255.255.0 »ò ip nat pool test 211.82.216.1 211.82.216.254 prefix-length 24 µÚËIJ½£¬¶¨ÒåÄÚ²¿ÍøÂçÖÐÔÊÐí·ÃÎÊInternetµÄ·ÃÎÊÁÐ±í¡£ ¶¨ÒåÄÚ²¿·ÃÎÊÁбíÃüÁîµÄÓï·¨ÈçÏ£º access-listl ±êºÅ permit Ô´µØÖ· ͨÅä·û£¨ÆäÖУ¬±êºÅΪ1~99Ö®¼äµÄÕûÊý£© access-listl permit 172.16.100.0 0.0.0.255 //ÔÊÐí·ÃÎÊInternetµÄÍø¶ÎΪ172.16.100.0~172.16.100.255£¬Ö÷»úÑÚÂëΪ0.0.0.255¡£ÐèҪעÒâµÄÊÇ£¬ÔÚÕâÀï²ÉÓõÄÊÇÖ÷»úÑÚÂ룬¶ø·Ç×ÓÍøÑÚÂë¡£×ÓÍøÑÚÂëÓëÖ÷»úÑÚÂëµÄ¹ØϵΪ£ºÖ÷»úÑÚÂë+×ÓÍøÑÚÂë=255.255.255.255¡£ÀýÈ磬×ÓÍøÑÚÂëΪ255.255.0.0£¬ÔòÖ÷»úÑÚÂëΪ0.0.255.255£»×ÓÍøÑÚÂëΪ255.0.0.0,ÔòÖ÷»úÑÚÂëΪ0.255.255.255;×ÓÍøÑÚÂëΪ255.252.0.0,ÔòÖ÷»úÑÚÂëΪ0.3.255.255;×ÓÍøÑÚÂëΪ255.255.255.192£¬¸ÕÖ÷»úÑÚÂëΪ 0.0.0.63¡£ ÁíÍ⣬Èç¹ûÏ뽫¶à¸öIPµØÖ·¶Îת»»ÎªºÏ·¨IPµØÖ·£¬¿ÉÒÔÌí¼Ó¶à¸ö·ÃÎÊÁÐ±í¡£ÀýÈ磬µ±Óû½«172.16.98.0~172.16.98.255ºÍ172.16.99.0~172.16.99.255ת»»ÎªºÏ·¨IPµØַʱ£¬Ó¦µ±Ìí¼ÓÏÂÊöÃüÁ access-list2 permit 172.16.98.0~0.0.0.255 access-list2 permit 172.16.99.0~0.0.0.255 µÚÎå²½£¬ÊµÏÖÍøÂçµØַת»»¡£ ÔÚÈ«¾ÖÉèÖÃģʽÏ£¬½«ÓÉaccess-listÖ¸¶¨µÄÄÚ²¿±¾µØµØÖ·ÓëÖ¸¶¨µÄÄÚ²¿ºÏ·¨µØÖ·³Ø½øÐеØַת»»¡£ÃüÁîÓï·¨ÈçÏ£º ip nat inside source list ·ÃÎÊÁбí±êºÅ pool ÄÚ²¿ºÏ·¨µØÖ·³ØÃû×Ö Ê¾Àý£º ip nat inside source list 1 pool chinanet Èç¹ûÓжà¸öÄÚ²¿·ÃÎÊÁÐ±í£¬¿ÉÒÔÒ»Ò»Ìí¼Ó£¬ÒÔʵÏÖÍøÂçµØַת»»£¬Èç ip nat insde source list 2 pool chinanet ip nat insde source list 2 pool chinanet Èç¹ûÓжà¸öµØÖ·³Ø£¬Ò²¿ÉÒÔÒ»Ò»Ìí¼Ó£¬ÒÔÔö¼ÓºÏ·¨µØÖ·³Ø·¶Î§£¬Èç ip nat insde source list 2 pool cernet ip nat insde source list 2 pool cernet ip nat insde source list 2 pool cernet ÖÁ´Ë£¬¶¯Ì¬µØַת»»ÉèÖÃÍê±Ï¡£ 3).¶Ë¿Ú¸´Óö¯Ì¬µØַת»» ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ10.100.100.1~10.100.100.254,·ÓÉÆ÷¾ÖÓòÍø¶Ë¿Ú£¨¼´Ä¬ÈÏÍø¹Ø£©µÄIPµØַΪ10.100.100.1£¬×ÓÍøÑÚÂëΪ255.255.255.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.99.160.0~202.99.160.3,·ÓÉÆ÷¹ãÓòÍøÖеÄIPµØַΪ202.99.160.1,×ÓÍøÑÚÂëΪ255.255.255.252£¬¿ÉÓÃÓÚת»»µÄIPµØַΪ202.99.160.2¡£ÒªÇó½«ÄÚ²¿ÍøÖ·10.100.100.1~10.100.100.254 ת»»ÎªºÏ·¨IPµØÖ·202.99.160.2¡£ µÚÒ»²½£¬ÉèÖÃÍⲿ¶Ë¿Ú¡£ interface serial 0 ip address 202.99.160.1 255.255.255.252 in nat outside µÚ¶þ²½£¬ÉèÖÃÄÚ²¿¶Ë¿Ú¡£ interface ethernet 0 ?ip address 10.100.100.1 255.255.255.0 ?ip nat inside µÚÈý²½£¬¶¨ÒåºÏ·¨IPµØÖ·³Ø¡£ in nat pool onlyone 202.99.160.2 202.99.160.2 netmask 255.255.255.252 // Ö¸Ã÷µØÖ·»º³å³ØµÄÃû³ÆΪonlyone,IPµØÖ··¶Î§Îª202.99.160.2,×ÓÍøÑÚÂëΪ255.255.255.252¡£ÓÉÓÚ±¾ÀýÖ»ÓÐÒ»¸öIPµØÖ·¿ÉÓã¬ËùÒÔ£¬ÆðʼIPµØÖ·ÓëÖÕÖ¹IPµØÖ·¾ùΪ202.99.160.2¡£Èç¹ûÓжà¸öIPµØÖ·£¬ÔòÓ¦µ±·Ö±ð¼üÈëÆðÖ¹µÄIPÖ±Ö·¡£ µÚËIJ½£¬¶¨ÒåÄÚ²¿·ÃÎÊÁС£ access-list 1 permit 10.100.100.0 0.0.0.255 ÔÊÐí·ÃÎÊInternetrµÄÍø¶ÎΪ10.100.100.0~10.100.100.255£¬×ÓÍøÑÚÂëΪ255.255.255.0¡£ÐèҪעÒâµÄÊÇ£¬ÔÚÕâÀï×ÓÍøÑÚÂëµÄ˳Ðò¸úƽ³£ËùдµÄ˳ÐòÏà·´£¬¼´0.255.255.255¡£ µÚÎå²½£¬ÉèÖø´Óö¯Ì¬µØַת»»¡£ ÔÚÈ«¾ÖÉèÖÃģʽÏ£¬ÉèÖÃÔÚÄÚ²¿µÄ±¾µØµØÖ·ÓëÄÚ²¿ºÏ·¨IPµØÖ·¼ä½¨Á¢¸´Óö¯Ì¬µØַת»»¡£ÃüÁîÓï·¨ÈçÏ£º ip nat inside source list·ÃÎÊÁбíºÅpoolÄÚ²¿ºÏ·¨µØÖ·³ØÃû×Öoverload ʾÀý£º ip nat inside source list1 pool onlyone overload //ÒԶ˿ڸ´Ó÷½Ê½£¬½«·ÃÎÊÁбí1ÖеÄ˽ÓÐIPµØַת»»Îªonlyone IPµØÖ·³ØÖж¨ÒåµÄºÏ·¨IPµØÖ·¡£ ÖÁ´Ë£¬¶Ë¿Ú¸´Óö¯Ì¬µØַת»»Íê³É¡£ ÍøÂçµØַת»»(NAT)-ʵÀý ʾÀýÒ»£ºÈ«²¿²ÉÓö˿ڸ´ÓõØַת»» µ±ISP·ÖÅäµÄIPµØÖ·ÊýÁ¿ºÜÉÙ£¬ÍøÂçÓÖûÓÐÆäËûÌØÊâÐèÇ󣬼´ÎÞÐèΪInternetÌṩÍøÂç·þÎñʱ£¬¿É²ÉÓö˿ÚÀûÓõØַת»»·½Ê½£¬Ê¹ÍøÂçÄڵļÆËã»ú²ÉÓÃͬһIPµØÖ··ÃÎÊInternet£¬ÔÚ½ÚÔ¼IPµØÖ·×ÊÔ´µÄͬʱ£¬ÓÖ¿ÉÓÐЧ±£»¤ÍøÂçÄÚ²¿µÄ¼ÆËã»ú¡£ ÍøÂç»·¾³Îª£º ¾ÖÓòÍø²ÉÓÃ10Mb/s¹âÏË£¬ÒÔ³ÇÓòÍø·½Ê½½ÓÈëInternet£¬Èçͼ4-2-2Ëùʾ¡£Â·ÓÉÆ÷Ñ¡ÓÃÓµÓÐ2¸ö10/100 Mb/s×ÔÊÊÓ¦¶Ë¿ÚµÄCisco 2611¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ192.168.100.1~192.101.254£¬¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ192.168.100.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.99.160.128~202.99.160.131,Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ202.99.160.129,×ÓÍøÑÚÂëΪ255.255.255.252¡£¿ÉÓÃÓÚת»»µÄIPµØַΪ202.99.160.130¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet¡£ °¸Àý·ÖÎö£º ¼ÈȻֻÓÐÒ»¸ö¿ÉÓõĺϷ¨IPµØÖ·£¬Í¬Ê±´¦ÓÚ¾ÖÓòÍøµÄ·þÎñÆ÷ÓÖֻΪ¾ÖÓòÍøÌṩ·þÎñ£¬¶ø²»ÔÊÐíInternetÖеÄÖ÷»ú¶ÔÆä·ÃÎÊ£¬Òò´ËÍêÈ«¿ÉÒÔ²ÉÓö˿ڸ´ÓõØַת»»·½Ê½ÊµÏÖNAT£¬Ê¹µÃÍøÂçÄÚµÄËùÓмÆËã»ú¾ù¿É¶ÀÁ¢·ÃÎÊInternet¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/0 ip address 192.168.100.1 255.255.0.0 //¶¨Òå±¾µØ¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat inside // ¶¨ÒåΪ±¾µØ¶Ë¿Ú ! interface fastethernet0/1 ip address 202.99.160.129 255.255.255.252 duplx auto speed auto ip nat outside ! ip nat pool onlyone 202.99.160.130 202.99.160.130 netmadk 255.255.255.252 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪonlyone access-list 1 permit 192.168.100.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí access-list 1 permit 192.168.100.0 0.0.0.255 ip nat inside source list1 pool onlyone overload //²ÉÓö˿ڸ´Óö¯Ì¬µØַת»» ʾÀý¶þ£º¶¯Ì¬µØÖ·+¶Ë¿Ú¸´ÓõØַת»» Ðí¶àFTPÍøÕ¾¿¼Âǵ½·þÎñÆ÷ÐÔÄܺÍInternetÁ¬½Ó´ø¿íµÄÕ¼ÓÃÎÊÌ⣬¶¼ÏÞÖÆͬһIPµØÖ·µÄ¶à¸ö½ø³Ì·ÃÎÊ¡£Èç¹û²ÉÓö˿ڸ´µØַת»»·½Ê½£¬ÔòÍøÂçÄÚµÄËùÒÔ¼ÆËã»ú¶¼²ÉÓÃͬһIPµØÖ··ÃÎÊInternet,ÄÇô£¬½«Òò´Ë¶ø±»½ûÖ¹¶Ô¸ÃÍøÕ¾µÄ·ÃÎÊ¡£ËùÒÔ£¬µ±ÌṩµÄºÏ·¨IPµØÖ·ÊýÁ¿ÉÔ¶àʱ£¬¿Éͬʱ²ÉÓö˿ڸ´ÓúͶ¯Ì¬µØַת»»·½Ê½£¬´Ó¶ø¼È¿É±£Ö¤ËùÓÐÓû§¶¼Äܹ»»ñµÃ·ÃÎÊInternetµÄȨÁ¦£¬Í¬Ê±£¬ÓÖ²»Ö¡¢Ä³Ð©¼ÆËã»úÒòʹÓÃͬһIPµØÖ·¶ø±»ÏÞÖÆȨÏÞ¡£ÐèҪעÒâµÄÊÇ£¬ÓÉÓÚËùÓмÆËã»ú¶¼²ÉÓö¯Ì¬µØַת»»·½Ê½£¬Òò´ËInternetÖеÄËùÓмÆËã»ú½«ÎÞ·¨ÊµÏÖ¶ÔÍøÂçÄÚ²¿·þÎñÆ÷µÄ·ÃÎÊ¡£ ÍøÂç»·¾³£º ¾ÖÓòÍøÒÔ2Mb/s DNAרÏß½ÓÈëInternet£¬Â·ÓÉÆ÷Ñ¡Óð²×°Á˹ãÓòÍøÄ£¿éµÄCisco 2611,Èçͼ4-2-2Ëùʾ¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ172.16.100.1~172.16.102.254,¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ172.16.100.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.99.160.128~202.99.160.129,×ÓÍøÑÚÂëΪ255.255.255.192,¿ÉÓÃÓÚת»»µÄIPµØÖ··¶Î§Îª202.99.160.130~202.99.160.190¡£ÒªÇóÍøÂ粿·ÖµÄ²¿·Ö¼ÆËã»ú¿ÉÒÔ²»ÊÜÈκÎÏÞÖƵطÃÎÊInternet£¬·þÎñÆ÷ÎÞÐèÌṩInternet·ÃÎÊ·þÎñ¡£ °¸Àý·ÖÎö£º ¼ÈȻҪÇóÍøÂçÖеIJ¿·Ö¼ÆËã»ú¿ÉÒÔ²»ÊÜÈκÎÏÞÖƵطÃÎÊInternet,ͬʱ£¬·þÎñÆ÷ÎÞÐèÌṩInternet·ÃÎÊ·þÎñ£¬ÄÇô£¬Ö»Ðè²ÉÓö¯Ì¬µØַת»»+¶Ë¿Ú¸´ÓõØַת»»·½Ê½¼´¿ÉʵÏÖ¡£²¿·ÖÓÐÌØÊâÐèÇóµÄ¼ÆËã»ú²ÉÓö¯Ì¬µØַת»»µÄNAT·½Ê½£¬ÆäËû¼ÆËã»úÔò²ÉÓö˿ڸ´ÓõØַת»»µÄNAT·½Ê½¡£Òò´Ë£¬²¿·ÖÓÐÌØÊâÐèÇóµÄ¼ÆËã»ú¿É²ÉÓÃÄÚ²¿ÍøÖ·172.16.100.1~172.16.100.254£¬²¢¶¯Ì¬×ª»»ÎªºÏ·¨µØÖ·202.99.160.130~202.99.160.189£¬ÆäËû¼ÆËã»ú²ÉÓÃÄÚ²¿ÍøÖ·172.16.101.1~172.16.102.254,È«²¿×ª»»Îª202.99.160.190¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/1 ip address 10.100.100.1 255.255.255.0 //¶¨Òå¾ÖÓòÍø¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat inside //¶¨ÒåΪ¾ÖÓò¶Ë¿Ú ! interface serial 0/0 ip address 202.99.160.129 255.255.255.192 //¶¨Òå¹ãÓòÍø¶Ë¿ÚIPµØÖ· ! duplex auto speed auto ip nat outside //¶¨ÒåΪ¹ãÓò¶Ë¿Ú ! ip nat pool public 202.99.160.130 202.130.160.190 netmask 255.255.255.192 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪpublic ip nat pool super 202.99.160.130 202.130.160.189 netmask 255.255.255.192 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪsuper ip nat inside source list1 pool super //¶¨ÒåÁбí´ï1²ÉÓö¯Ì¬µØַת»» ip nat inside source list2 pool public overload? //¶¨ÒåÁбí2²ÉÓö˿ڸ´ÓõØַת»» access-list1 permit 172.16.100.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí1 access-list2 permit 172.16.102.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí2 access-list2 permit 172.16.102.0 0.0.0.255 ʾÀýÈý£º¾²Ì¬µØַת»»+¶Ë¿Ú¸´ÓõØַת»» ÆäʵÔںܶàʱºò£¬ÍøÂçÖеķþÎñÆ÷¼ÈΪÍøÂçÄÚ²¿µÄ¿Í»§ÌṩÍøÂç·þÎñ£¬ÓÖͬʱΪInternetÖеÄÓû§Ìṩ·ÃÎÊ·þÎñ¡£Òò´Ë£¬Èç¹û²ÉÓö˿ڸ´ÓõØַת»»»ò¶¯Ì¬µØַת»»£¬½«ÓÉÓÚÎÞ·¨È·¶¨·þÎñÆ÷µÄIPµØÖ·£¬¶øµ¼ÖÂInternetÓû§ÎÞ·¨ÊµÏÖ¶ÔÍøÂçÄÚ²¿·þÎñÆ÷µÄ·ÃÎÊ¡£´Ëʱ£¬¾ÍÓ¦µ±²ÉÓþ²Ì¬µØַת»»+¶Ë¿Ú¸´ÓõØַת»»µÄNAT·½Ê½¡£Ò²¾ÍÊÇ˵£¬¶Ô·þÎñÆ÷²ÉÓþ²Ì¬µØַת»»£¬ÒÔÈ·±£·þÎñÆ÷ÓµÓй̶¨µÄºÏ·¨IPµØÖ·¡£¶ø¶ÔÆÕͨµÄ¿Í»§¼ÆËã»úÔò²ÉÓö˿ڸ´ÓõØַת»»£¬Ê¹ËùÓÐÓû§¶¼ÏíÓзÃÎÊInternetµÄȨÁ¦¡£ ÍøÂç»·¾³Îª£º ¾ÖÓòÍø²ÉÓÃ10Mb/s¹âÏË£¬ÒÔ³ÇÓòÍø·½Ê½½ÓÈëInternet£¬Èçͼ4-2-2Ëùʾ¡£Â·ÓÉÆ÷Ñ¡ÓÃÓµÓÐ2¸ö10/100 Mb/s×ÔÊÊÓ¦¶Ë¿ÚµÄCisco 2611¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ10.18.100.1~10.18.104.254,¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ10.18.100.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª211.82.220.80~211.82.220.87£¬Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ211.82.220.81,×ÓÍøÑÚÂëΪ255.255.255.248¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet£¬²¢ÇÒÔÚInternetÖÐÌṩWeb¡¢E-mail¡¢FTPºÍMediaµÈ4ÖÖ·þÎñ¡£ °¸Àý·ÖÎö£º ¼ÈÈ»ÍøÂçÄڵķþÎñÆ÷ÒªÇóÄܹ»±»Internet·ÃÎʵ½£¬ÄÇô£¬Õⲿ·ÖÖ÷»ú±ØÐëÓµÓкϷ¨µÄIPµØÖ·£¬Ò²¾ÍÊÇ˵£¬·þÎñÆ÷±ØÐë²ÉÓþ²Ì¬µØַת»»¡£ÆäËû¼ÆËã»úÓÉÓÚûÓÐÈκÎÏÞÖÆ£¬ËùÒÔ£¬¿É²ÉÓö˿ڸ´ÓõØַת»»µÄNAT·½Ê½¡£Òò´Ë£¬·þÎñÆ÷¿É²ÉÓÃÄÚÍøÖ·10.18.100.1~10.18.100.254£¬²¢·Ö±ðÓ³ÉäΪһ¸öºÏ·¨µÄIPµØÖ·¡£ÆäËû¼ÆËã»úÔò²ÉÓÃÄÚ²¿ÍøÖ·10.18.101.1~172.16.104.254,²¢È«²¿×ª»»ÎªÒ»¸öºÏ·¨µÄIPµØÖ·¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/0 ip address 10.18.100.1 255.255.0.0 //¶¨Òå¾ÖÓòÍø¿ÚIPµØÖ· duplex auto speed auto ip nat inside //¶¨Òå¾ÖÓòÍø¿Ú ! interface fastethernet0/1 ip address 211.82.220.81 255.255.255.248 //¶¨Òå¹ãÓòÍø¿ÚIPµØÖ· duplex auto speed auto ip nat outside //¶¨Òå¹ãÓòÍø¿Ú ! ip nat pool every 211.82.220.86 211.82.220.86 netmask 255.255.255.248 //¶¨ÒåºÏ·¨IPµØÖ·³Ø access-list 1 permit 10.18.101.0 0.0.0.255 //¶¨Òå±¾µØ·ÃÎÊÁбí1 access-list 1 premit 10.18.102.0 0.0.0.255 access-list 1 premit 10.18.103.0 0.0.0.255 access-list 1 premit 10.18.104.0 0.0.0.255 ip nat inside source list1 pool every overload //¶¨ÒåÁбí´ï1²ÉÓö˿ڸ´ÓõØַת»» ip nat inside source static 10.18.100.10 211.82.220.82 //¶¨Ò徲̬µØַת»» ip nat inside source static 10.18.100.11 211.82.220.83 ip nat inside source static 10.18.100.12 211.82.220.84 ip nat inside source static 10.18.100.13 211.82.220.85 ʾÀýËÄ£ºTCP/UDP¶Ë¿ÚNATÓ³Éä Èç¹ûISPÌṩµÄºÏ·¨IPµØÖ·µÄÊýÁ¿½Ï¶à£¬ÎÒÃÇ×ÔÈ»¿ÉÒÔ²ÉÓþ²Ì¬µØַת»»+¶Ë¿Ú¸´Óö¯Ì¬µØַת»»µÄ·½Ê½µÃÒÔÍêÃÀʵÏÖ¡£µ«Èç¹ûISPÖ»Ìṩ4¸öIPµØÖ·£¬ÆäÖÐ2¸ö×÷ΪÍøÂçºÅºÍ¹ã²¥µØÖ·¶ø²»¿ÉʹÓã¬1¸öIPµØÖ·ÒªÓÃÓÚ·ÓÉÆ÷¶¨ÒåΪĬÈÏÍø¹Ø£¬ ÄÇô½«Ö»Ê£ÏÂ1¸öIPµØÖ·¿ÉÓᣵ±È»ÎÒÃÇÒ²¿ÉÒÔÀûÓÃÕâ¸ö½ö´æµÄÒ»¸öIPµØÖ·²ÉÓö˿ڸ´ÓõØַת»»¼¼Êõ£¬´Ó¶øʵÏÖÕû¸ö¾ÖÓòÍøµÄInternet½ÓÈë¡£µ«ÊÇÓÉÓÚ·þÎñÆ÷Ò²²ÉÓö¯Ì¬¶Ë¿Ú£¬Òò´Ë£¬InternetÖеļÆËã»ú½«ÎÞ·¨·ÃÎʵ½ÍøÂçÄÚ²¿µÄ·þÎñÆ÷¡£ÓÐûÓкõĽâ¾öÎÊÌâµÄ·½°¸ÄØ£¿Õâ¾ÍÊÇTCP/UDP¶Ë¿ÚNATÓ³Éä¡£ ÎÒÃÇÖªµÀ£¬²»Í¬Ó¦ÓóÌÐòʹÓõÄTCP/UDPµÄ¶Ë¿ÚÊDz»Í¬µÄ£¬±ÈÈ磬Web·þÎñʹÓÃ50£¬FTP·þÎñʹÓÃ21£¬SMTP·þÎñʹÓÃ25£¬POP3·þÎñʹÓÃ110£¬µÈµÈ¡£Òò´Ë£¬¿ÉÒÔ½«²»Í¬µÄTCP¶Ë¿Ú°ó¶¨ÖÁ²»Í¬µÄÄÚ²¿IPµØÖ·£¬´Ó¶øֻʹÓÃÒ»¸öºÏ·¨µÄIPµØÖ·£¬¼´¿ÉÔÚÔÊÐíÄÚ²¿ËùÓзþÎñÆ÷±»Internet·ÃÎʵÄͬʱ£¬ÊµÏÖÄÚ²¿ËùÓÐÖ÷»ú¶ÔInternet·ÃÎÊ¡£ ÍøÂç»·¾³£º ¾ÖÓòÍø²ÉÓÃ10Mb/s¹âÏË£¬ÒÔ³ÇÓòÍø·½Ê½½ÓÈëInternet£¬Èçͼ4-2-5Ëùʾ¡£Â·ÓÉÆ÷Ñ¡ÓÃÓµÓÐ2¸ö10/100 Mb/s×ÔÊÊÓ¦¶Ë¿ÚµÄCisco 2611¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ192.168.1.1~192.168.1.254£¬¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ192.168.1.1,×ÓÍøÑÚÂëΪ255.255.255.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª£¬211.82.220.128~211.82.220.131,Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ211.82.220.129,×ÓÍøÑÚÂëΪ255.225.255.252£¬¿ÉÓÃÓÚת»»µÄIPµØַΪ211.82.220.130¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet¡£ °¸Àý·ÖÎö£º ¼ÈȻֻÓÐÒ»¸ö¿ÉÓõĺϷ¨IPµØÖ·£¬µ±È»Ö»ÄܲÉÓö˿ڸ´Ó÷½Ê½ÊµÏÖNAT£¬²»¹ý£¬ÓÉÓÚͬʱÓÖÒªÇóÍøÂçÄÚ²¿µÄ·þÎñÆ÷¿ÉÒÔ±»Internet·ÃÎʵ½£¬Òò´Ë£¬±ØÐëʹÓÃPAT´´½¨TCP/UDP¶Ë¿ÚµÄNATÓ³Éä¡£ÐèҪעÒâµÄÊÇ£¬Ò²¿ÉÒÔÖ±½ÓʹÓùãÓò¶Ë¿Ú´´½¨TCP/UDP¶Ë¿ÚµÄNATÓ³É䣬Ҳ¾ÍÊÇ˵£¬¼´Ê¹Ö»ÓÐÒ»¸öIPµØÖ·£¬Ò²¿ÉÒÔÍêÃÀʵÏֶ˿ڸ´Óá£ÓÉÓںϷ¨IPµØַλÓÚ·ÓÉÆ÷¶Ë¿ÚÉÏ£¬ËùÒÔ£¬²»ÔÙÐèÒª¶¨ÒåNAT³Ø£¬Ö»¼òµ¥µØʹÓÃinside source listÓï¾ä¼´¿É¡£ ÐèҪעÒâµÄÊÇ£¬ÓÉÓÚÿÖÖÓ¦Ó÷þÎñ¶¼ÓÐ×Ô¼ºÄ¬ÈϵĶ˿ڣ¬ËùÒÔ£¬ÕâÖÖNAT·½Ê½Ï£¬ÍøÂçÄÚ²¿Ã¿ÖÖÓ¦Ó÷þÎñÖÐÖ»Äܸ÷×ÔÓÐһ̨·þÎñÆ÷³ÉΪInternetÖеÄÖ÷»ú£¬ÀýÈ磬ֻÄÜÓÐһ̨Web·þÎñÆ÷£¬Ò»Ì¨E-mail·þÎñ£¬Ò»Ì¨FTP·þÎñÆ÷¡£¾¡¹Ü¿ÉÒÔ²ÉÓøıäĬÈ϶˿ڵķ½Ê½´´½¨¶ą̀ӦÓ÷þÎñÆ÷£¬µ«ÕâÖÖ·þÎñÆ÷ÔÚ·ÃÎÊʱ±È½ÏÀ§ÄÑ£¬ÒªÇóÓû§±ØÐëÏÈÁ˽âijÖÖ·þÎñ²ÉÓõÄÐÂTCP¶Ë¿Ú¡£ ÅäÖÃÇåµ¥£º interface fastethernet0/0 ip address 192.168.1.1 255.255.255.0//Ö¸¶¨¾ÖÓòÍø¿ÚµÄIPµØÖ· duplex auto speed auto ip nat inside //Ö¸¶¨¾ÖÓòÍø½Ó¿Ú ! interface fastethernet0/1 ip address 211.82.220.129 255.255.255.248 //Ö¸¶¨¹ãÓòÍø¿ÚµÄIPµØÖ· access-list 1 permit 192.168.1.0 0.0.0.255 ! ip nat inside source list1 interface fastethernet0/1 overload //ÆôÓö˿ڸ´ÓõØַת»»£¬²¢Ö±½Ó²ÉÓÃfastethernet0/1µÄIPµØÖ·¡£ ip nat inside source static tcp 192.168.1.11 80 202.99.160.129.80 ip nat inside source static tcp 192.168.1.12 21 202.99.160.129.21 ip nat inside source static tcp 192.168.1.13 25 202.99.160.129.25 ip nat inside source static tcp 192.168.1.13 110 202.99.160.129 110 ʾÀýÎ壺ÀûÓõØַת»»ÊµÏÖ¸ºÔؾùºâ Ëæ×Å·ÃÎÊÁ¿µÄÉÏÉý£¬µ±Ò»Ì¨·þÎñÆ÷ÄÑÒÔʤÈÎʱ£¬¾Í±ØÐë²ÉÓøºÔؾùºâ¼¼Êõ£¬½«´óÁ¿µÄ·ÃÎʺÏÀíµØ·ÖÅäÖÁ¶ą̀·þÎñÆ÷ÉÏ¡£µ±È»£¬ÊµÏÖ¸ºÔؾùºâµÄÊÖ¶ÎÓÐÐí¶àÖÖ£¬±ÈÈç¿ÉÒÔ²ÉÓ÷þÎñÆ÷Ⱥ¼¯¸ºÔؾùºâ¡¢½»»»»ú¸ºÔؾùºâ¡¢DNS½âÎö¸ºÔؾùºâµÈµÈ¡£ Æäʵ³ý´ËÒÔÍ⣬Ҳ¿ÉÒÔͨ¹ýµØַת»»·½Ê½ÊµÏÖ·þÎñÆ÷µÄ¸ºÔؾùºâ¡£ÊÂʵÉÏ£¬ÕâЩ¸ºÔؾùºâµÄʵÏÖ´ó¶àÊDzÉÓÃÂÖѯ·½Ê½ÊµÏֵģ¬Ê¹Ã¿Ì¨·þÎñÆ÷¶¼ÓµÓÐƽµÈµÄ±»·ÃÎÊ»ú»á¡£ ÍøÂç»·¾³£º ¾ÖÓòÍøÒÔ2Mb/s DDNרÏßÀÈëInternet,·ÓÉÆ÷Ñ¡Óð²×°Á˹ãÓòÍøÄ£¿éµÄCisco 2611,Èçͼ4-2-6Ëùʾ¡£ÄÚ²¿ÍøÂçʹÓõÄIPµØÖ·¶ÎΪ10.1.1.1~10.1.3.254£¬¾ÖÓòÍø¶Ë¿ÚEthernet 0µÄIPµØַΪ10.1.1.1,×ÓÍøÑÚÂëΪ255.255.0.0¡£ÍøÂç·ÖÅäµÄºÏ·¨IPµØÖ··¶Î§Îª202.110.198.80~202.110.198.87,Á¬½ÓISPµÄ¶Ë¿ÚEthernet 1µÄIPµØַΪ202.110.198.81,×ÓÍøÑÚÂëΪ255.255.255.248¡£ÒªÇóÍøÂçÄÚ²¿µÄËùÓмÆËã»ú¾ù¿É·ÃÎÊInternet£¬²¢ÇÒÔÚ3̨Web·þÎñÆ÷ºÍ2̨FTP·þÎñÆ÷ʵÏÖ¸ºÔؾùºâ¡£ °¸Àý·ÖÎö£º ¼ÈȻҪÇóÍøÂçÄÚËùÓмÆËã»ú¶¼¿ÉÒÔ½ÓÈëInternet,¶øºÏ·¨IPµØÖ·ÓÖÖ»ÓÐ5¸ö¿ÉÓ㬵±È»¿É²ÉÓö˿ڸ´ÓõØַת»»·½Ê½¡£±¾À´¶Ô·þÎñÆ÷ͨ¹ý²ÉÓþ²Ì¬µØַת»»£¬¸³ÓèÆäºÏ·¨IPµØÖ·¼´¿É¡£µ«ÊÇ£¬ÓÉÓÚ·þÎñÆ÷µÄ·ÃÎÊÁ¿Ì«´ó£¨»òÕßÊÇ·þÎñÆ÷µÄÐÔÄÜÌ«²î£©£¬²»µÃ²»Ê¹Óöą̀·þÎñÆ÷×÷¸ºÔؾùºâ£¬Òò´Ë£¬±ØÐ뽫һ¸öºÏ·¨IPµØַת»»³É¶àÏàÄÚ²¿IPµØÖ·£¬ÒÔÂÖѯ·½Ê½¼õÇáÿ̨·þÎñÆ÷µÄ·ÃÎÊѹÁ¦¡£ ÅäÖÃÎļþ£º interface fastethernet0/1 ip adderss 10.1.1.1 255.255.0.0 //¶¨Òå¾ÖÓòÍø¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat inside //¶¨ÒåΪ¾ÖÓò¶Ë¿Ú ! interface serial 0/0 ip address 202.110.198.81 255.255.255.248 //¶¨Òå¹ãÓòÍø¶Ë¿ÚIPµØÖ· duplex auto speed auto ip nat outside //¶¨ÒåΪ¹ãÓò¶Ë¿Ú ! access-list 1 permit 202.110.198.82 //¶¨ÒåÂÖѯµØÖ·Áбí1 access-list 2 permit 202.110.198.83 access-list 3 permit 10.1.1.0 0.0.255.255 //¶¨Òå±¾µØ·ÃÎÊÁбí3 ! ip nat pool websev 10.1.1.2 10.1.1.1 255.255.255.248 type rotary //¶¨ÒåWeb·þÎñÆ÷µÄIPµØÖ·³Ø£¬Rotary¹Ø¼ü×Ö±íʾ׼±¸Ê¹ÓÃÂÖѯ²ßÂÔ´ÓNAT³ØÖÐÈ¡³öÏàÓ¦µÄIPµØÖ·ÓÃÓÚת»»½øÀ´µÄIP±¨ÎÄ£¬·ÃÎÊ202.110.198.82µÄÇëÇó½«ÒÀ´Î·¢Ë͸ø10.1.1.2¡¢10.1.1.3ºÍ10.1.1.4 ip nat pool ftpsev 10.1.1.8 10.1.1.9 255.255.255.248 type rotary ip nat pool normal 202.110.198.84 202.110.198.84 netmask 255.255.255.248 //¶¨ÒåºÏ·¨IPµØÖ·³Ø£¬Ãû³ÆΪnormal ip nat inside destination list 1 pool websev //inside destination list Óï¾ä¶¨ÒåÓëÁбí1ÏàÆ¥ÅäµÄIPµØÖ·µÄ±¨ÎĽ«Ê¹ÓÃÂÖѯ²ßÂÔ ip nat inside destination list 2 pool ftpsev
±§Ç¸£¬´ËÒ³ÃæµÄÄÚÈÝÊÜ°æȨ±£»¤£¬¸´ÖÆÐè¿Û³ý´ÎÊý£¬´ÎÊý²»×ãʱÐ踶·Ñ¹ºÂò¡£
ÈçÐèÏÂÔØÇëµã»÷£ºµã»÷´Ë´¦ÏÂÔØ
ɨÂ븶·Ñ¼´¿É¸´ÖÆ
ÏßËÙ | H.235 | ATMÊÊÅä²ã2 | RBOC | ÑÇÒôƵ | ÏîÁ¢¸Õ | ¹âÀÂÉ豸 | Ä¿±êÊý¾Ý¿â | lteý | IPֱͨ³µ | ͨÐÅÊý¾Ý×ֶΠ| M£Í |