当前位置:   article > 正文

华为NAT基本配置_华为nat配置

华为nat配置

6e80945dda784422a5fdac01758b8378.png

client1:192.168.1.1 gw:192.168.1.254

client2:192.168.1.2  gw:192.168.1.254 

私有地址:

(1)a: 10.0.0.0 ~ 10.255.255.255/8

(2)b: 172.16.0.0 ~ 172.32.255.255/12

(3)c: 192.168.0.0 ~ 192.168.255.255/16

NAT的类型:

(1)静态NAT:一对一,内部本地地址—>内部全局地址

(2)动态NAT:在地址池选一个空闲的地址进行转换,先到先得

(3)端口复用NAPT:192.168.1.1-->100.1.1.0:2048

                                     192.168.1.2-->100.0.0.0:2059

                                      192.168.1.3-->100.0.0.0:2050

(4)easy ip:类似于NAPT,但没有地址池,都可以通过

 AR1

  1. <Huawei>sys
  2. Enter system view, return user view with Ctrl+Z.
  3. [Huawei]sys AR1
  4. [AR1]int g0/0/1
  5. [AR1-GigabitEthernet0/0/1]ip add 192.168.1.254 24
  6. [AR1-GigabitEthernet0/0/1]int g0/0/0
  7. [AR1-GigabitEthernet0/0/0]ip add 10.1.11.1 24
  8. [AR1-GigabitEthernet0/0/0]q
  9. [AR1]ospf router-id 2.2.2.2
  10. [AR1-ospf-1]area 0
  11. [AR1-ospf-1-area-0.0.0.0]net 192.168.1.0 0.0.0.255
  12. [AR1-ospf-1-area-0.0.0.0]net 10.1.11.0 0.0.0.255
  13. [AR1-ospf-1-area-0.0.0.0]net 2.2.2.2 0.0.0.0
  14. [AR1-ospf-1-area-0.0.0.0]q

0b6d40d7d1894d9a8bd9f5640edf72db.png

FW1

  1. 配置ip
  2. [FW1]int g1/0/1
  3. [FW1-GigabitEthernet1/0/1]di th
  4. ip address 10.1.11.2 255.255.255.0
  5. [FW1-GigabitEthernet1/0/1]int g1/0/0
  6. [FW1-GigabitEthernet1/0/0]dis th
  7. ip address 102.1.1.1 255.255.255.0
  8. 将两个端口分别加入trust和untrust
  9. [FW1]firewall zone trust
  10. [FW1-zone-trust]dis th
  11. firewall zone trust
  12. set priority 85
  13. add interface GigabitEthernet0/0/0
  14. add interface GigabitEthernet1/0/1
  15. [FW1-zone-trust]firewall zone untrust
  16. [FW1-zone-untrust]dis th
  17. firewall zone untrust
  18. set priority 5
  19. add interface GigabitEthernet1/0/0
  20. 配置安全策略
  21. [FW1]security-policy
  22. [FW1-policy-security]rule name trust_untrust
  23. [FW1-policy-security-rule-trust_untrust]dis th
  24. #
  25. rule name trust_untrust
  26. source-zone trust
  27. destination-zone untrust
  28. destination-address 8.8.8.1 0.0.0.0
  29. action permit
  30. #
  31. 配置动态路由
  32. [FW1]ospf router-id 1.1.1.1
  33. [FW1-ospf-1]dis th
  34. #
  35. ospf 1 router-id 1.1.1.1
  36. area 0.0.0.0
  37. network 1.1.1.1 0.0.0.0
  38. network 10.1.11.0 0.0.0.255
  39. network 102.1.1.0 0.0.0.255
  40. #
  41. [FW1-ospf-1]default-route-advertise always
  42. [FW1]nat address-group trust_untrust
  43. [FW1-address-group-trust_untrust]dis th
  44. #
  45. nat address-group trust_untrust 0
  46. mode pat
  47. [FW1-address-group-trust_untrust]section 100.1.1.1 100.1.1.6
  48. [FW1-address-group-trust_untrust]q
  49. [FW1]nat-policy
  50. [FW1-policy-nat]rule name trust_untrust
  51. [FW1-policy-nat-rule-trust_untrust]source-zone trust
  52. [FW1-policy-nat-rule-trust_untrust]destination-zone untrust
  53. [FW1-policy-nat-rule-trust_untrust]source-address 192.168.1.0 24
  54. [FW1-policy-nat-rule-trust_untrust]action source-nat easy-ip
  55. [FW1-policy-nat-rule-trust_untrust]dis th
  56. #
  57. rule name trust_untrust
  58. source-zone trust
  59. destination-zone untrust
  60. source-address 192.168.1.0 mask 255.255.255.0
  61. action source-nat easy-ip
  62. #
  63. return

4c77f41cfd1d4d53976fe21ad34691e0.png

AR2 

  1. <Huawei>sys
  2. [Huawei]sys AR2
  3. [AR2]undo info-center enable
  4. [AR2]int g0/0/0
  5. [AR2-GigabitEthernet0/0/0]ip add 102.1.1.2 24
  6. [AR2-GigabitEthernet0/0/0]int g0/0/1
  7. [AR2-GigabitEthernet0/0/1]ip add 8.8.8.254 24
  8. [AR2-GigabitEthernet0/0/1]q
  9. 配置动态路由
  10. [AR2]ospf router-id 3.3.3.3
  11. [AR2-ospf-1]area 0
  12. [AR2-ospf-1-area-0.0.0.0]net 102.1.1.0 0.0.0.255
  13. [AR2-ospf-1-area-0.0.0.0]net 8.8.8.0 0.0.0.255
  14. [AR2-ospf-1-area-0.0.0.0]net 3.3.3.3 0.0.0.0
  15. [AR2-ospf-1-area-0.0.0.0]q
  16. 配置静态路由
  17. [AR2]ip route-static 100.1.1.1 32 102.1.1.1

bf190f8ba19c4739bd0854291f0ff067.png

最后加入测试阶段:

client1 ping server1

c561a830a26c430a95d6bf55d3f69c28.png

client2 ping server1

c4fc32c342ad4b0d93f4476010cc55f4.png

声明:本文内容由网友自发贡献,不代表【wpsshop博客】立场,版权归原作者所有,本站不承担相应法律责任。如您发现有侵权的内容,请联系我们。转载请注明出处:https://www.wpsshop.cn/w/weixin_40725706/article/detail/662674
推荐阅读
相关标签
  

闽ICP备14008679号