任务一:利用静态NAT技术实现外网主机访问内网服务
一、基础配置
LAN:
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center ena
Info: Information center is disabled.
[Huawei]sysn LAN
[LAN]int g0/0/0
[LAN-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[LAN-GigabitEthernet0/0/0]int s1/0/0
[LAN-Serial1/0/0]ip add 200.1.1.1 24
[LAN-Serial1/0/0]qu
[LAN]ip route-static 0.0.0.0 0 s1/0/0
ISP:
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center ena
Info: Information center is disabled.
[Huawei]sysn ISP
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip add 63.19.6.254 24
[ISP-GigabitEthernet0/0/0]int s1/0/0
[ISP-Serial1/0/0]ip add 200.1.1.2 24
[ISP-Serial1/0/0]qu
二、在LAN上配置静态NAT技术映射
第一种方法:全局模式
LAN:
[LAN]nat static global 200.1.1.5 inside 192.168.1.1
[LAN]int s1/0/0
[LAN-Serial1/0/0]nat static ena
[LAN-Serial1/0/0]qu
第二种方法:接口模式
[LAN]int s1/0/0
[LAN-Serial1/0/0]nat static global 200.1.1.5 inside 192.168.1.1
[LAN-Serial1/0/0]qu
三、在server1服务器上配置HTTPServer服务器
四、在Client1上测试访问“http://200.1.1.5",可以正常访问WEB服务器。
五、在LAN上查看NAT技术的映射关系
任务二:利用动态NAPT技术实现局域网访问internet
一、基础配置
LAN:
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center ena
Info: Information center is disabled.
[Huawei]sysn LAN
[LAN]int g0/0/0
[LAN-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[LAN-GigabitEthernet0/0/0]int s1/0/0
[LAN-Serial1/0/0]ip add 200.1.1.1 24
[LAN-Serial1/0/0]qu
[LAN]ip route-static 0.0.0.0 0 s1/0/0
ISP:
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center ena
Info: Information center is disabled.
[Huawei]sysn ISP
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip add 63.19.6.254 24
[ISP-GigabitEthernet0/0/0]int s1/0/0
[ISP-Serial1/0/0]ip add 200.1.1.2 24
[ISP-Serial1/0/0]qu
二、在LAN上配置动态NAPT
LAN:
[LAN]nat address-group 1 200.1.1.3 200.1.1.4
[LAN]acl 2000
[LAN-acl-basic-2000]rule 5 permit sou
[LAN-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
[LAN-acl-basic-2000]int s1/0/0
[LAN-Serial1/0/0]nat outbound 2000 address-group 1
[LAN-Serial1/0/0]qu
三、在server1服务器上配置HTTPServer服务器
四、在Client1上测试访问“http://63.19.6.1",可以正常访问WEB服务器。
五、在LAN上查看NAPT会话信息