版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報或認(rèn)領(lǐng)
文檔簡介
20442de 乾頤堂ADHCPserverallocatesnetworkaddressesanddeliversADHCPclientisahostthatrequestsanIPaddressandconfigurationfromaDHCPserver.DynamicHostConfigurationProtocolDHCPIPaddressallocationAutomaticallocation:ApermanentIPaddressisassignedtoaDynamicallocationAclientisassignedanIPaddressforalimitedManualallocation:AclientisassignedanIPaddressbythenetworkAssignedIPAddress-SP給企業(yè)級用戶分配的OptionsforconfiguringIPConfiguringaStaticProvider-AssignedIPConfiguresapublicIPRouter(config)#iRouter(config)#iproute0.0.0.00.0.0.0Createsadefaultroutethatpointstowardthenext-hopIPConfiguringaDHCPRouterautomaticallyinjectsdefaultroutebasedonoptionaldefaultgatewayparameterreceivedwithassignedIPaddress.CPE自動的通過默認(rèn)網(wǎng)關(guān)的參數(shù)注入一條默認(rèn)路由Publicvs.PrivateIPv4PrivateAddressA10.0.0.0toB172.16.0.0toC192.168.0.0toPublicAddressA1.0.0.0to11.0.0.0toB128.0.0.0to172.32.0.0toC192.0.0.0to192.169.0.0toNATallowsprivateuserstoaccesstheInternetbysharingoneormorepublicIPaddresses.TypesofAddressesinThesearethemostimportanttypesofaddressesinInsidelocal:HostontheinsideInsideglobal:UsuallyassignedbyanISPandallowsthecustomeroutsideaccessOutsideglobal:HostontheoutsideTypesofAddressesinNATTypesofThesearethetypesofStaticNAT:One-to-oneaddressDynamicNAT:Many-to-manyaddressNATOrderof IfIPSecthencheckinputaccessdecryption-forCET(CiscoEncryptionTechnology)orIPSeccheckinputaccesscheckinputrateinputredirecttowebpolicyNATinsidetooutside(localtoglobalcrypto(checkmapandmarkforcheckoutputaccessinspect(Context-basedAccessControlTCP
IfIPSecthencheckinputaccessdecryption-forCETorcheckinputaccesscheckinputrateinputredirecttowebNAToutsidetoinside(globaltolocalpolicycrypto(checkmapandmarkforcheckoutputaccessinspectTCPEnder 乾頤堂Example:ConfiguringstaticRouter(config)#Router(config)#interfaceGigabitEthernet0/1Router(config-if)#ipaddress209.165.201.1255.255.255.240Router(config-if)#ipnatoutsideRouter(config)#interfaceGigabitEthernet0/0Router(config-if)#ipaddress10.1.1.1255.255.255.0Router(config-if)#ipnatinsideRouter(config)#ipnatinsidesourcestatic10.1.1.2Trying202.100.1.1...OpenUserAccessPassword:Branch#showBranch#showipnatProInsidetcpInsideOutsideOutside202.100.1.2:29430tcp202.100.1.1:2873710.1.20.100:28737 --- -- --Ender 乾頤堂ipnatinsidesourcestatictcp10.1.20.10023202.100.1.14444HQ#telnet202.100.1.1Trying202.100.1.1,4444...UserAccessVerificationBranch#showipnatProInside Inside tcp tcp -nr -- --乾頤堂VerifyingStaticNATRouter#showipnatProInside InsideOutsideOutsidetcp---Router(config)#access-list1permit10.1.1.00.0.0.255—ACL攜帶掩碼,否則可能無效Router(config)#ipnatpoolNAT-POOL209.165.201.5209.165.201.10netmaskRouter(config)#interfaceGigabitEthernet0/1Router(config-if)#ipaddress209.165.201.1255.255.255.240Router(config-if)#ipnatoutsideRouter(config)#interfaceGigabitEthernet0/0Router(config-if)#ipaddress10.1.1.1255.255.255.0Router(config-if)#ipnatinsideRouter(config)#ipnatinsidesourcelist1poolNAT-Router#showipnatProInside InsideOutsideOutsideicmp---icmptcp---Router(config)#Router(config)#access-list1permit10.1.1.00.0.0.255Router(config)#interfaceGigabitEthernet0/0Router(config-if)#ipaddress10.1.1.1255.255.255.0Router(config-if)#ipnatinsideRouter(config-if)#interfaceGigabitEthernet0/1Router(config-if)#ipaddress209.165.201.1255.255.255.240Router(config#ipnatoutsideRouter(config)#ipnatinsidesourcelist1interfaceGi0/1VerifyingPATRouter#showipnatProInside InsideOutside OutsidetcptcpAreAddressesBeingRouter#Router#showipnatTotaltranslations:5(0static,5dynamic,5extended)OutsideInterfaces:Serial0InsideInterfaces:Ethernet0,Ethernet1Hits:42Misses:44<outputMonitorsNATaccess-list1permit10.1.1.100VerifiesthattheNATACLispermittingallnecessaryTodisplaydetaileddynamicdataandevents,youcanuseAdebugcommandcanintensivelyusedeviceresources.Usecarefullyonproductionequipment.AlwaysturnoffdebugaftertroubleshootingwiththenodebugallRouter#Router#debugipNAT*:s=10.1.1.100->209.165.201.1,d=172.16.1.100[103]NAT*:s=172.16.1.100,d=209.165.201.1->10.1.1.100[103]NAT*:s=10.1.1.100->209.165.201.1,d=172.16.1.100[104]NAT*:s=172.16.1.100,d=209.165.201.1->10.1.1.100[104]<outputDisplaysinformationabouteverypacketthatistranslatedbytheIftranslationsareoccurring,butthereisnoconnectivity,verifythattheremoterouterhasaroutetothetranslatedaddress.Branch#showBranch#showipCodes:L-local,C-connected,S-static,R-RIP,M-mobile,B-BGPD-EIGRP,EX-EIGRPexternal,O-OSPF,IA-OSPFinterareaN1-OSPFNSSAexternaltype1,N2-OSPFNSSAexternaltype2E1-OSPFexternaltype1,E2-OSPFexternaltype2i-IS-IS,su-IS-ISsummary,L1-IS-ISlevel-1,L2-IS-ISlevel-2ia-IS-ISinterarea,*-candidatedefault,U-per-userstaticrouteo-ODR,P-periodicdownloadedstaticroute,+-replicatedrouteGatewayoflastresortis209.165.201.1tonetwork0.0.0.0C10.1.1.0/24isdirectlyconnected,GigabitEthernet0/0L10.1.1.2/32isdirectlyconnected,C209.165.201.0/27isdirectlyconnected,GigabitEthernet0/1S*0.0.0.0/0[1/0]via209.165.201.1HostAandhostBareunabletopingafteranewNATconfigurationisputinplace.<outputiproute0.0.0.00.0.0.0!access-list20permit0.0.0.0!interfaceipaddress10.1.1.1255.255.255.0ipnatoutside!interfaceipaddress209.165.200.1ipnat!ipnatinsidesourcelist20interfaceGigabitEthernet0/1Router#showipnatProRouter#showipnatProInside InsideOutsideOutsideTranslationsarenotTherouterinterfacesareincorrectlydefinedasNATinsideandNAToutside.Router#Router#showipnatTotalactivetranslations:0(0static,0dynamic;0extended)Outsideinterfaces:Insideinterfaces:<outputHowtofixRouter#Router#configureterminalRouter(config)#interfaceGigabitEthernet0/0Router(config-if)#ipnatinsideRouter(config-if)#ipnatVerifythattheaccesslistisStandardIPaccesslist10permit0.0.0.0,wildcardbitsHowtofixaccessVerifythattranslationsareoccurringandyouhaveconnectivitytotheremotenetwork.209.165.202.131:1Outside209.165.202.131:1OutsideOutsideInsidelocalProInsideglobalicmp209.165.201.1:1Router#showipnatPinging209.165.202.131with32bytesofReplyfrom209.165.202.131:bytes=32Replyfrom209.165.202.131:<output
time=70msTTL=127Provider-assignedIPaddressescanbeconfiguredonarouterstaticallyorcanbedynamically
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 妊娠期PKU的腸內(nèi)營養(yǎng)輸注管路維護培訓(xùn)方案優(yōu)化策略總結(jié)-1
- 廠區(qū)招聘考試題目及答案
- 女性職場人群代謝綜合征的激素干預(yù)考量
- 頭頸部鱗癌分子分型與放療優(yōu)化
- 大數(shù)據(jù)視角下的體檢資源優(yōu)化配置策略-1
- 漢語考試初級試題及答案
- 職稱考試邏輯題及答案
- 多組學(xué)數(shù)據(jù)質(zhì)控:整合分析與結(jié)果可靠性
- 2025年大學(xué)烹飪類(烹飪技術(shù)創(chuàng)新)試題及答案
- 2025年高職(文創(chuàng)產(chǎn)品設(shè)計)產(chǎn)品研發(fā)專項測試試題及答案
- SF-36健康調(diào)查量表(含excel版)
- 安全評估培訓(xùn)體會課件
- 課題班級自主管理申報書
- 2024-2025學(xué)年山東省濰坊市高一下學(xué)期5月期中考試政治試題(解析版)
- 環(huán)境污染治理設(shè)施運營考試試題
- 國際貨運代理公司合伙協(xié)議書
- 質(zhì)量安全環(huán)保保證協(xié)議書
- 2025年證監(jiān)會招聘面試高頻考題及解析
- 飛行營地建設(shè)項目可行性研究報告
- 2025-2030中國溶劑染料行業(yè)消費狀況及競爭策略分析報告
- 電大專科水利水電工程水法規(guī)與行政執(zhí)法試題及答案
評論
0/150
提交評論