PC0
int s 2/0
ip access-group 5ijsj out end
PC1
ping 172.16.4.2 (success)
ping 172.16.4.2 (Replay from 172.16.2.1: Destination host
unreachable)
µÚÊ®ÆßÕ À©Õ¹IP·ÃÎÊ¿ØÖÆÁбíÅäÖÃ
ʵÑéÄ¿±ê
Àí½â±ê×¼IP·ÃÎÊ¿ØÖÆÁбíµÄÔÀí¼°¹¦ÄÜ£» ÕÆÎÕ±àºÅµÄ±ê×¼IP·ÃÎÊ¿ØÖÆÁбíµÄÅäÖ÷½·¨£» ÄãÊǹ«Ë¾µÄÍøÂç¹ÜÀíÔ±£¬¹«Ë¾µÄ¾Àí²¿¡¢²ÆÎñ²¿ÃǺÍÏú
ʵÑé±³¾°
ÊÛ²¿ÃÅ·ÖÊôÓÚ²»Í¬µÄ3¸öÍø¶Î£¬Èý²¿ÃÅÖ®¼äÓ÷ÓÉÆ÷½øÐÐÐÅÏ¢´«µÝ£¬ÎªÁË°²È«Æð¼û£¬¹«Ë¾Áìµ¼ÒªÇóÏúÊÛ²¿ÃŲ»ÄܶԲÆÎñ²¿½øÐзÃÎÊ£¬µ«¾Àí²¿¿ÉÒÔ¶Ô²ÆÎñ²¿½øÐзÃÎÊ¡£
PC1´ú±í¾Àí²¿µÄÖ÷»ú¡¢PC2´ú±íÏúÊÛ²¿µÄÖ÷»ú¡¢PC3
PC0
À©Õ¹IP·ÃÎÊÁбíµÄÅäÖðüÀ¨ÒÔÏÂÁ½²¿£º
¶¨ÒåÀ©Õ¹IP·ÃÎÊÁбí
½«À©Õ¹IP·ÃÎÊÁбíÓ¦ÓÃÓÚÌض¨½Ó¿ÚÉÏ
21
IP:
172.16.1.2 255.255.255.0 172.16.1.1 172.16.4.2 255.255.255.0 172.16.4.1
Submask: Gateway: IP:
´ú±í²ÆÎñ²¿µÄÖ÷»ú¡£ ¼¼ÊõÔÀí
·ÃÎÊÁбíÖж¨ÒåµÄµäÐ͹æÔòÖ÷ÒªÓÐÒÔÏ£ºÔ´µØÖ·¡¢Ä¿±ê
µØÖ·¡¢ÉϲãÐÒ顢ʱ¼äÇøÓò£»
À©Õ¹IP·ÃÎÊÁÐ±í£¨±àºÅ100-199¡¢2000¡¢2699£©Ê¹ÓÃÒÔÉÏ
Server0
Submask: Gateway: en conf t host R0 int fa 0/0
ip address 172.16.1.1 255.255.255.0 no shutdown int fa 1/0
ip address 172.16.2.1 255.255.255.0 no shutdown exit en conf t host R1 int fa 1/0
ip address 172.16.2.2 255.255.255.0 no shutdown int s 2/0
ip address 172.16.3.1 255.255.255.0 no shutdown
ËÄÖÖ×éºÏÀ´½øÐÐת·¢»ò×è¶Ï·Ö×飻¿ÉÒÔ¸ù¾ÝÊý¾Ý°üµÄÔ´IP¡¢Ä¿µÄIP¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú¡¢ÐÒéÀ´¶¨Òå¹æÔò£¬½øÐÐÊý¾Ý°üµÄ¹ýÂË¡£
Router0
ʵÑé²½Öè
н¨Packet TracerÍØÆËͼ
£¨1£©·Ö¹«Ë¾³ö¿Ú·ÓÉÆ÷ÓëÍâ·ÓÉÆ÷Ö®¼äͨ¹ýV.35µçÀ´®
¿ÚÁ¬½Ó£¬DCE¶ËÁ¬½ÓÔÚR2ÉÏ£¬ÅäÖÃÆäʱÖÓƵÂÊ64000£»Ö÷»úÓë·ÓÉÆ÷ͨ¹ý½»²æÏßÁ¬½Ó¡£
£¨2£©ÅäÖÃPC»ú¡¢·þÎñÆ÷¼°Â·ÓÉÆ÷½Ó¿ÚIPµØÖ·¡£ £¨3£©ÔÚ¸÷·ÓÉÆ÷ÉÏÅäÖþ²Ì¬Â·ÓÉÐÒ飬ÈÃPC¼äÄÜÏ໥£¨4£©ÔÚR2ÉÏÅäÖñàºÅµÄIPÀ©Õ¹·ÃÎÊ¿ØÖÆÁÐ±í¡£ £¨5£©½«À©Õ¹IP·ÃÎÊÁбíÓ¦Óõ½½Ó¿ÚÉÏ¡¢¡£ £¨6£©ÑéÖ¤Ö÷»úÖ®¼äµÄ»¥Í¨ÐÔ¡£
PC 1̨£»Server-PT 1̨£» Router-PT 3̨£»½»²æÏߣ»DCE´®¿ÚÏß
pingͨ£¬ÒòΪֻÓÐÔÚ»¥Í¨µÄÇ°ÌáϲÅÉæ¼°µ½·ÃÎÊ¿ØÖÆÁÐ±í¡£
Router1
ʵÑéÉ豸
clock rate 64000 en conf t host R2 int s 2/0
ip address 172.16.3.2 255.255.255.0 no shutdown int fa 0/0
ip address 172.16.4.1 255.255.255.0 no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.2.2 exit
ip route 0.0.0.0 0.0.0.0 172.16.3.1 eixt
ip route 172.16.1.0 255.255.255.0 172.16.2.1
PC0 echo PC0
ip route 172.16.4.0 255.255.255.0 172.16.3.2 end
show ip route
ping 172.16.4.2(success)
Webä¯ÀÀÆ÷£ºhttp://172.16.4.2(success) conf t
access-list 100 permit tcp host 172.16.1.2 host 172.16.4.2 eq access-lint 100 deny icmp host 172.16.1.2 host 172.16.4.2 int s 2/0
ip access-group 100 out end
Webä¯ÀÀÆ÷£ºhttp://172.16.4.2(success)
ping 172.16.4.2(Reply from 172.16.2.2: Destination host
Router2
Router1
www
Router0 Router2
Router1
unreachable)
µÚÊ®°ËÕ ÍøÂçµØַת»»NATÅäÖÃ
ʵÑéÄ¿±ê
Àí½âNATÍøÂçµØַת»»µÄÔÀí¼°¹¦ÄÜ£»
ÕÆÎÕ¾²Ì¬NATµÄÅäÖã¬ÊµÏÖ¾ÖÓòÍø·ÃÎÊ»¥ÁªÍø£» ÄãÊÇij¹«Ë¾µÄÍøÂç¹ÜÀíÔ±£¬Óû·¢²¼¹«Ë¾µÄWWW·þÎñ¡£
NAT·ÖΪÁ½ÖÖÀàÐÍ£ºNAT£¨ÍøÂçµØַת»»£©ºÍNAPT£¨Íø
¾²Ì¬NAT£ºÊµÏÖÄÚ²¿µØÖ·ÓëÍⲿµØÖ·Ò»¶ÔÒ»µÄÓ³Éä¡£¶¯Ì¬NAT£º¶¨ÒåÒ»¸öµØÖ·³Ø£¬×Ô¶¯Ó³É䣬ҲÊÇÒ»¶ÔNAPT£ºÊ¹Óò»Í¬µÄ¶Ë¿ÚÀ´Ó³Éä¶à¸öÄÚÍøIPµØÖ·µ½
Âç¶Ë¿ÚµØַת»»IPµØÖ·¶ÔÓ¦Ò»¸öÈ«¾ÖµØÖ·£©¡£ ÏÖʵÖУ¬Ò»°ã¶¼ÓÃÓÚ·þÎñÆ÷£»
ʵÑé±³¾°
ÏÖÒªÇó½«ÄÚÍøWeb·þÎñÆ÷IPµØÖ·Ó³ÉäΪȫ¾ÖIPµØÖ·£¬ÊµÏÖÍⲿÍøÂç¿ÉÒÔ·ÃÎʹ«Ë¾ÄÚ²¿Web·þÎñÆ÷¡£ ¼¼ÊõÔÀí
ÍøÂçµØַת»»NAT£¨Network Address Translation£©£¬±»¹ã
Ò»µÄ¡£ÏÖʵÖУ¬ÓõñȽÏÉÙ£»
Ò»¸öÖ¸¶¨µÄÍâÍøIPµØÖ·£¬¶à¶ÔÒ»¡£ ʵÑé²½Öè
н¨Packet TracerÍØÆËͼ
£¨1£©R1Ϊ¹«Ë¾³ö¿Ú·ÓÉÆ÷£¬ÆäÓëÍⲿ·ÓÉÆ÷Ö®¼äͨ¹ý
·ºÓ¦ÓÃÓÚ¸÷ÖÖÀàÐÍInternet½ÓÈ뷽ʽºÍ¸÷ÖÖÀàÐ͵ÄÍøÂçÖС£ÔÒòºÜ¼òµ¥£¬NAT²»½öÍêÃÀµØ½â¾öÁËIPµØÖ·²»×ãµÄÎÊÌ⣬¶øÇÒ»¹Äܹ»ÓÐЧµØ±ÜÃâÀ´×ÔÍøÂçÍⲿµÄ¹¥»÷£¬Òþ²Ø²¢±£»¤ÍøÂçÄÚ²¿µÄ¼ÆËã»ú¡£
ĬÈÏÇé¿öÏ£¬ÄÚ²¿IPµØÖ·ÊÇÎÞ·¨±»Â·Óɵ½ÍâÍøµÄ£¬ÄÚ²¿
V.35µçÀ´®¿ÚÁ¬½Ó£¬DCE¶ËÁ¬½ÓÔÚR1ÉÏ£¬ÅäÖÃÆäʱÖÓƵÂÊ64000£»
£¨2£©ÅäÖÃPC»ú¡¢·þÎñÆ÷¼°Â·ÓÉÆ÷½Ó¿ÚIPµØÖ·£» £¨3£©ÔÚ¸÷·ÓÉÆ÷ÉÏÅäÖþ²Ì¬Â·ÓÉÐÒ飬ÈÃPC¼äÄÜÏ໥£¨4£©ÔÚR1ÉÏÅäÖþ²Ì¬NAT¡£ £¨5£©ÔÚR1É϶¨ÒåÄÚÍâÍøÂç½Ó¿Ú¡£ £¨6£©ÑéÖ¤Ö÷»úÖ®¼äµÄ»¥Í¨ÐÔ¡£
PC 1̨£»Server-PT 1̨£»Switch_2950-24 1̨£»Router-PT
Ö÷»ú10.1.1.1ÒªÓëÍⲿInternetͨÐÅ£¬IP°üµ½´ïNAT·ÓÉÆ÷ʱ£¬ IP°üÍ·µÄÔ´µØÖ·10.1.1.1±»Ìæ»»³ÉÒ»¸öºÏ·¨µÄÍâÍøIP£¬²¢ÔÚNATת·¢±íÖб£´æÕâÌõ¼Ç¼¡£µ±ÍⲿÖ÷»ú·¢ËÍÒ»¸öÓ¦´ðµ½ÄÚÍøʱ£¬NAT·ÓÉÆ÷Êܵ½ºó£¬²é¿´µ±Ç°NATת»»±í£¬ÓÃ10.1.1.1Ìæ»»µôÕâ¸öÍâÍøµØÖ·¡£
NAT½«ÍøÂç»®·ÖΪÄÚ²¿ÍøÂçºÍÍⲿÍøÂçÁ½²¿·Ö£¬¾ÖÓòÍø
Pingͨ£»
ʵÑéÉ豸
Ö÷»úÀûÓÃNAT·ÃÎÊÍøÂçʱ£¬Êǽ«¾ÖÓòÍøÄÚ²¿µÄ±¾µØµØַת»»ÎªÈ«¾ÖµØÖ·£¨»¥ÁªÍøºÏ·¨µÄIPµØÖ·£©ºóת·¢Êý¾Ý°ü£»
2̨£»Ö±Á¬Ïߣ»½»²æÏߣ»DCE´®¿ÚÏß 22
Server-PT PC0
222.0.2.2 255.255.255.0 222.0.2.1 en conf t host R0 int fa 0/0
ip address 192.168.1.1 255.255.255.0 no shutdown int s 2/0
ip address 222.0.1.1 255.255.255.0 no shutdown clock rate 64000 en conf t host R1 int s 2/0 192.168.1.2 255.255.255.0 192.168.1.1
PC0 PC0
Webä¯ÀÀÆ÷
http://222.0.1.3 (success) CMD
ping 192.168.1.2 (success) http://192.168.1.2 (success) Webä¯ÀÀÆ÷
ip address 222.0.1.2 255.255.255.0 no shut int fa 0/0
ip address 222.0.2.1 255.255.255.0 no shutdown exit;
ip route 222.0.2.0 255.255.255.0 222.0.1.2 exit
ip route 192.168.1.0 255.255.255.0 222.0.1.1 end
show ip route
Router0
Router1
Router0
Router0
int fa 0/0 ip nat inside int s 2/0 ip nat outside exit
ip nat inside source static 192.168.1.2 222.0.1.3 end
show ip nat translations
Router1
Router0
show ip nat translations
µÚÊ®¾ÅÕ ÍøÂç¶Ë¿ÚµØַת»»NAPTÅäÖÃ
ʵÑéÄ¿µÄ
Àí½âNATÍøÂçµØַת»»µÄÔÀí¼°¹¦ÄÜ£» ÕÆÎÕNAPTµÄÅäÖã¬ÊµÏÖ¾ÖÓòÍø·ÃÎÊ»¥ÁªÍø£»
Ö÷»úÀûÓÃNAT·ÃÎÊÍøÂçʱ£¬Êǽ«¾ÖÓòÍøÄÚ²¿µÄ±¾µØµØַת»»ÎªÈ«¾ÖµØÖ·£¨»¥ÁªÍøºÏ·¨µÄIPµØÖ·£©ºóת·¢Êý¾Ý°ü£»
NAT·ÖΪÁ½ÖÖÀàÐÍ£ºNAT£¨ÍøÂçµØַת»»£©ºÍNAPT£¨Íø
NAPT£ºÊ¹Óò»Í¬µÄ¶Ë¿ÚÀ´Ó³Éä¶à¸öÄÚÍøIPµØÖ·µ½
ʵÑé±³¾° Âç¶Ë¿ÚµØַת»»IPµØÖ·¶ÔÓ¦Ò»¸öÈ«¾ÖµØÖ·£©¡£ Ò»¸öÖ¸¶¨µÄÍâÍøIPµØÖ·£¬¶à¶ÔÒ»¡£
NAPT²ÉÓö˿ڶà·¸´Ó÷½Ê½¡£ÄÚ²¿ÍøÂçµÄËùÓÐÖ÷»ú¾ù¿É
ÄãÊÇij¹«Ë¾µÄÍøÂç¹ÜÀíÔ±£¬¹«Ë¾°ì¹«ÍøÐèÒª½ÓÈ뻥ÁªÍø£¬
¹«Ë¾Ö»ÏòISPÉêÇëÁËÒ»ÌõרÏߣ¬¸ÃרÏß·ÖÅäÁËÒ»¸ö¹«Ë¾IPµØÖ·£¬ÅäÖÃʵÏÖÈ«¹«Ë¾µÄÖ÷»ú¶¼ÄÜ·ÃÎÊÍâÍø¡£ ¼¼ÊõÔÀí
NAT½«ÍøÂç»®·ÖΪÄÚ²¿ÍøÂçºÍÍⲿÍøÂçÁ½²¿·Ö£¬¾ÖÓòÍø
¹²ÏíÒ»¸öºÏ·¨ÍⲿIPµØַʵÏÖ¶ÔInternetµÄ·ÃÎÊ£¬´Ó¶ø¿ÉÒÔ×î´óÏ޶ȵؽÚÔ¼IPµØÖ·×ÊÔ´¡£Í¬Ê±£¬ÓÖ¿ÉÒþ²ØÍøÂçÄÚ²¿µÄËùÓÐ23
Ö÷»ú£¬ÓÐЧ±ÜÃâÀ´×ÔInternetµÄ¹¥»÷¡£Òò´Ë£¬Ä¿Ç°ÍøÂçÖÐÓ¦ÓÃ×î¶àµÄ¾ÍÊǶ˿ڶà·¸´Ó÷½Ê½¡£ ʵÑé²½Öè
н¨Packet TracerÍØÆËͼ
£¨1£©R1Ϊ¹«Ë¾³ö¿Ú·ÓÉÆ÷£¬ÆäÓëISP·ÓÉÆ÷Ö®¼äͨ¹ý
PC1
int s 2/0
ip address 200.1.1.1 255.255.255.0 no shutdown clock rate 64000 en conf t host R1 int s 2/0
ip address 200.1.1.2 255.255.255.0 no shutdown int fa 0/0
ip address 200.1.2.1 255.255.255.0 no shutdown exit
ip route 200.1.2.0 255.255.255.0 200.1.1.2 exit
ip route 192.168.1.0 255.255.255.0 200.1.1.1 end
show ip route CMD
ping 200.1.2.2 (success) http://200.1.2.2 (success) Webä¯ÀÀÆ÷
Router1
V.35µçÀ´®¿ÚÁ¬½Ó£¬DCE¶ËÁ¬½ÓÔÚR1ÉÏ£¬ÅäÖÃÆäʱÖÓƵÂÊ64000£»
£¨2£©ÅäÖÃPC»ú¡¢·þÎñÆ÷¼°Â·ÓÉÆ÷½Ó¿ÚIPµØÖ·£» £¨3£©ÔÚ¸÷·ÓÉÆ÷ÉÏÅäÖþ²Ì¬Â·ÓÉÐÒ飬ÈÃPC¼äÄÜÏ໥£¨4£©ÔÚR1ÉÏÅäÖÃNAPT¡£ £¨5£©ÔÚR1É϶¨ÒåÄÚÍâÍøÂç½Ó¿Ú¡£ £¨6£©ÑéÖ¤Ö÷»úÖ®¼äµÄ»¥Í¨ÐÔ¡£
PC 2̨£»Server-PT 1̨£»Switch_2950-24 1̨Router-PT 2̨£»Ö±Í¨Ïߣ»½»²æÏߣ»DCE´®¿ÚÏß
Pingͨ£»
ʵÑéÉ豸
Router0
Router1
PC1 PC2
192.168.1.3 255.255.255.0 192.168.1.1 200.1.2.2 255.255.255.0 200.1.2.1 en conf t host R0 int fa 0/0
ip address 192.168.1.1 255.255.255.0 no shutdown 192.168.1.2 255.255.255.0 192.168.1.1
Router0 PC1 PC2 24
Webä¯ÀÀÆ÷ Webä¯ÀÀÆ÷
http://200.1.2.2 (success) int fa 0/0 ip nat inside int s 2/0 ip nat outside exit
access-list 1 permit 192.168.1.0 0.0.0.255
ip nat pool 5ijsj 200.1.1.3 200.1.1.3 netmask 255.255.255.0 ip nat inside source list 1 pool 5ijsj overload (ÎÞoverload±íend
show ip nat translations(ÎÞ½á¹û)
Server
ʾ¶à¶Ô¶à£¬ÓÐoverload±íʾ¶à¶ÔÒ»)
Router0
Router0
show ip nat translations(ÓÐ1¸ö½á¹û)