实战:配置动态NAT

实战:配置动态NAT

实战1:动态NAT

image-20250611155610092

[Huawei]nat address-group 1 ?
[Huawei]nat address-group 1 12.2.2.2 12.2.2.3

[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.0.255
[Huawei-acl-basic-2000]rule 10 deny
[Huawei-acl-basic-2000]quit

[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 address-group 1
image-20250611160402195

PC抓包

image-20250611160502216

PC4抓包

image-20250611160559859

实战2:动态NAT+路由

image-20250611163901689

AR3

<Huawei>sys
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.0.254 24
[Huawei-GigabitEthernet0/0/0]quit

[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.1 24
[Huawei-GigabitEthernet0/0/1]quit

[Huawei]ip route-static 0.0.0.0 0 192.168.0.1

AR1

<Huawei>sys
[Huawei]ip route-static 192.168.1.0 24 192.168.0.254
[Huawei-acl-basic-2000]rule 6 permit source 192.168.1.0 0.0.0.255

测试

image-20250611164019057

PC1

image-20250611164110350

PC5

image-20250611164151730

实战3:EASY NAT

EASY NAT属于简化版动态NAT

image-20250611165729864

<Huawei>sys
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]display this

[V200R003C00]
#
interface GigabitEthernet0/0/1
 ip address 12.2.2.1 255.255.255.0 
 nat outbound 2000 address-group 1 
#
return

[Huawei-GigabitEthernet0/0/1]undo nat outbound 2000 address-group 1
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]undo nat address-group 1

[Huawei-GigabitEthernet0/0/1]nat outbound 2000

测试

image-20250611165538777

PC5抓包

image-20250611165518409

实战4:端口映射

client1

image-20250611171739433

server2

image-20250611171620850

image-20250611172029945

配置端口映射

AR1

<Huawei>sys

[Huawei]interface GigabitEthernet 0/0/1    
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global 12.2.2.8 80 inside 1
92.168.0.2 80 #-- 12.2.2.8是公网地址里面一个地址段

测试

image-20250611172355510

实战5:端口映射+远程桌面

image-20250611174413844

cloud1

image-20250611173940099

clould2

image-20250611174116996

WIN7

image-20250611174242932

image-20250611174325077

WINDOWS 2016

image-20250611173819122

image-20250611173846088

image-20250611174027852

image-20250611174354482

AR1

[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global 12.2.2.8 4500 inside
 192.168.0.110 3389

测试

WIN7 登录WIN2016

image-20250611174706414

image-20250611175252410

image-20250611175335149ch

查看端口映射的情况

[Huawei]display nat server interface GigabitEthernet 0/0/1
image-20250611175529562

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注