赞
踩
网络地址转换NAT(Network Address Translation)是将IP数据报文头中的IP地址转换为另一个IP地址的过程。
随着Internet的发展和网络应用的增多,IPv4地址枯竭已成为制约网络发展的瓶颈。尽管IPv6可以从根本上解决IPv4地址空间不足问题,但目前众多网络设备和网络应用大多是基于IPv4的,因此在IPv6广泛应用之前,一些过渡技术(如CIDR、私网地址等)的使用是解决这个问题最主要的技术手段。NAT主要用于实现内部网络(简称内网,使用私有IP地址)访问外部网络(简称外网,使用公有IP地址)的功能。当内网的主机要访问外网时,通过NAT技术可以将其私网地址转换为公网地址,可以实现多个私网用户共用一个公网地址来访问外部网络,这样既可保证网络互通,又节省了公网地址。
作为减缓IP地址枯竭的一种过渡方案,NAT通过地址重用的方法来满足IP地址的需要,可以在一定程度上缓解IP地址空间枯竭的压力。NAT除了解决IP地址短缺的问题,还带来了两个好处:
静态NAT是指在进行NAT转换时,内部网络主机的IP同公网IP是一对一静态绑定的,静态NAT中的公网IP只会给唯一且固定的内网主机转换使用。
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]
- [Huawei]un in en
- Info: Information center is disabled.
- [Huawei]
- [Huawei]sys AR1
- [AR1]
- [AR1]int g0/0/0
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]ip add 192.168.1.2 24
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]q
- [AR1]
- [AR1]int g0/0/1
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]ip add 192.168.2.2 24
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]q
- [AR1]
- [AR1]int g0/0/2
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]ip add 192.168.3.2 24
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]ip add 100.100.100.1 24
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat static global 100.100.100.3 inside 192.168.1.1 net
- mask 255.255.255.255
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat static global 100.100.100.4 inside 192.168.2.1 net
- mask 255.255.255.255
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat static global 100.100.100.5 inside 192.168.3.1 net
- mask 255.255.255.255
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]ip route-s
- [AR1]ip route-static 0.0.0.0 0 100.100.100.2
- [AR1]
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]
- [Huawei]un in en
- Info: Information center is disabled.
- [Huawei]
- [Huawei]sys AR2
- [AR2]
- [AR2]int g0/0/0
- [AR2-GigabitEthernet0/0/0]
- [AR2-GigabitEthernet0/0/0]ip add 100.100.100.2 24
- [AR2-GigabitEthernet0/0/0]
- [AR2-GigabitEthernet0/0/0]q
- [AR2]
- [AR2]int g0/0/1
- [AR2-GigabitEthernet0/0/1]
- [AR2-GigabitEthernet0/0/1]ip add 200.200.200.2 30
- [AR2-GigabitEthernet0/0/1]
- [AR2-GigabitEthernet0/0/1]q
- [AR2]
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]
- [Huawei]un in en
- Info: Information center is disabled.
- [Huawei]
- [Huawei]sys AR1
- [AR1]
- [AR1]int g0/0/0
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]ip add 192.168.1.2 24
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]q
- [AR1]
- [AR1]int g0/0/1
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]ip add 192.168.2.2 24
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]q
- [AR1]
- [AR1]int g0/0/2
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]ip add 192.168.3.2 24
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]ip add 100.100.100.1 24
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]nat address-group 1 100.100.100.3 100.100.100.254
- [AR1]
- [AR1]acl 2000
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat outbound 2000 address-group 1 no-pat
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]ip route-static 0.0.0.0 0 100.100.100.2
- [AR1]
除了一对一的NAT转换方式外,网络地址端口转换NAPT(Network Address Port Translation)可以实现并发的地址转换。它允许多个内部地址映射到同一个公有地址上,因此也可以称为“多对一地址转换”或地址复用。
NAPT方式属于多对一的地址转换,它通过使用“IP地址+端口号”的形式进行转换,使多个私网用户可共用一个公网IP地址访问外网。
- [Huawei]sys AR1
- [AR1]
- [AR1]int g0/0/0
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]ip add 192.168.1.2 24
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]q
- [AR1]
- [AR1]int g0/0/1
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]ip add 192.168.2.2 24
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]q
- [AR1]
- [AR1]int g0/0/2
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]ip add 192.168.3.2 24
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]ip add 100.100.100.1 24
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]nat address-group 1 100.100.100.3 100.100.100.3
- [AR1]
- [AR1]acl 2000
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat outbound 2000 address-group 1
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]ip route-static 0.0.0.0 0 100.100.100.2
- [AR1]
- [AR1]q
Easy IP方式可以利用访问控制列表来控制哪些内部地址可以进行地址转换。
Easy IP方式特别适合小型局域网访问Internet的情况。这里的小型局域网主要指中小型网吧、小型办公室等环境,一般具有以下特点:内部主机较少、出接口通过拨号方式获得临时公网IP地址以供内部主机访问Internet。对于这种情况,可以使用Easy IP方式使局域网用户都通过这个IP地址接入Internet。
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]
- [Huawei]un in en
- Info: Information center is disabled.
- [Huawei]
- [Huawei]sys AR1
- [AR1]
- [AR1]int g0/0/0
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]ip add 192.168.1.2 24
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]q
- [AR1]
- [AR1]int g0/0/1
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]ip add 192.168.2.2 24
- [AR1-GigabitEthernet0/0/1]
- [AR1-GigabitEthernet0/0/1]q
- [AR1]
- [AR1]int g0/0/2
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]ip add 192.168.3.2 24
- [AR1-GigabitEthernet0/0/2]
- [AR1-GigabitEthernet0/0/2]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]ip add 100.100.100.1 24
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]ip route-static 0.0.0.0 0 100.100.100.2
- [AR1]
- [AR1]acl 2000
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat outbound 2000
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
NAT具有“屏蔽”内部主机的作用,但有时内网需要向外网提供服务,比如提供WWW服务或者FTP服务。这种情况下需要内网的服务器不被“屏蔽”,外网用户可以随时访问内网服务器。
NAT Server可以很好地解决这个问题,当外网用户访问内网服务器时,它通过事先配置好的“公网IP地址+端口号”与“私网IP地址+端口号”间的映射关系,将服务器的“公网IP地址+端口号”根据映射关系替换成对应的“私网IP地址+端口号”。
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]
- [Huawei]un in en
- Info: Information center is disabled.
- [Huawei]
- [Huawei]sys AR1
- [AR1]
- [AR1]int g0/0/0
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]ip add 192.168.1.2 24
- [AR1-GigabitEthernet0/0/0]
- [AR1-GigabitEthernet0/0/0]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]ip add 100.100.100.1 24
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]ip route-static 0.0.0.0 0 100.100.100.2
- [AR1]
- [AR1]acl 2000
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
- [AR1-acl-basic-2000]
- [AR1-acl-basic-2000]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat outbound 2000
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]q
- [AR1]
- [AR1]int g4/0/0
- [AR1-GigabitEthernet4/0/0]
- [AR1-GigabitEthernet4/0/0]nat server protocol tcp global 100.100.100.3 80 inside
- 192.168.1.1 80
- [AR1-GigabitEthernet4/0/0]
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]
- [Huawei]un in en
- Info: Information center is disabled.
- [Huawei]
- [Huawei]sys AR2
- [AR2]
- [AR2]int g0/0/0
- [AR2-GigabitEthernet0/0/0]
- [AR2-GigabitEthernet0/0/0]ip add 100.100.100.2 24
- [AR2-GigabitEthernet0/0/0]
- [AR2-GigabitEthernet0/0/0]q
- [AR2]
- [AR2]int g0/0/1
- [AR2-GigabitEthernet0/0/1]
- [AR2-GigabitEthernet0/0/1]ip add 200.200.200.2 24
- [AR2-GigabitEthernet0/0/1]
- [AR2-GigabitEthernet0/0/1]q
- [AR2]
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。