diff --git a/B. 第二阶段/拓扑练习/0902_NAPT.md b/B. 第二阶段/拓扑练习/0902_NAPT.md index 6f90b58..cc15ac5 100644 --- a/B. 第二阶段/拓扑练习/0902_NAPT.md +++ b/B. 第二阶段/拓扑练习/0902_NAPT.md @@ -13,6 +13,7 @@ [AR1-GigabitEthernet0/0/0]ip add 192.168.1.254 24 [AR1-GigabitEthernet0/0/0]int g0/0/1 [AR1-GigabitEthernet0/0/1]ip add 100.1.1.1 29 + [AR1-GigabitEthernet0/0/1]quit [AR1]ip route-static 0.0.0.0 0 100.1.1.2 ``` @@ -27,6 +28,8 @@ ### 二、ACL + NAPT(单一公网地址) +#### 1、配置 + - **AR1** ``` @@ -42,7 +45,7 @@ > 见 `0902_动态NAT.md` -### 三、测试【NAPT(单一公网地址)】 +#### 2、测试 - **PC PING Server** @@ -121,7 +124,9 @@ > > -### 四、ACL + NAPT(复数公网地址) +### 三、ACL + NAPT(复数公网地址) + +#### 1、配置 - **AR1** @@ -150,7 +155,7 @@ - `[AR1]nat address-group 1 100.1.1.3 100.1.1.5`:创建或修改编号为1的NAT地址组将包含从100.1.1.3到100.1.1.5的IP地址范围 -### 五、测试【NAPT(复数公网地址)】 +#### 2、测试 - **AR1** @@ -186,4 +191,68 @@ New DestPort : ---- ``` - \ No newline at end of file + + + +### 四、ACL + NAPT(网段内无冗余IP) + +![image-20240902141522705](https://picgo-noriu.oss-cn-beijing.aliyuncs.com/Images/image-20240902141522705.png) + +| 网段 | 网络地址 | 可用主机地址 | 广播地址 | 子网掩码 | +| ------------- | --------- | --------------------- | --------- | --------------- | +| 100.1.1.0 /29 | 100.1.1.0 | 100.1.1.1 & 100.1.1.2 | 100.1.1.3 | 255.255.255.252 | + +#### 1、IP & Routing + +- **AR1** + + ``` + [AR1]int g0/0/0 + [AR1-GigabitEthernet0/0/0]ip add 192.168.1.254 24 + [AR1-GigabitEthernet0/0/0]int g0/0/1 + [AR1-GigabitEthernet0/0/1]ip add 100.1.1.1 30 + [AR1-GigabitEthernet0/0/1]quit + [AR1]ip route-static 0.0.0.0 0 100.1.1.2 + ``` + +- **IPX-dx** + + ``` + [ISP-dx]int g0/0/0 + [ISP-dx-GigabitEthernet0/0/0]ip add 100.1.1.2 30 + [ISP-dx-GigabitEthernet0/0/0]int g0/0/1 + [ISP-dx-GigabitEthernet0/0/1]ip add 200.1.1.254 24 + ``` + +#### 2、ACL + +- **AR1** + + ``` + [AR1]acl 2000 + [AR1-acl-basic-2000]rule 10 permit source 192.168.1.0 0.0.0.255 + [AR1-acl-basic-2000]quit + [AR1]int g0/0/1 + [AR1-GigabitEthernet0/0/1]nat outbound 2000 + ``` + +#### 3、NAPT + +- **AR1** + + ``` + + ``` + + + +### 五、NAT-Server(添加内网服务器) + +![image-20240902151642145](https://picgo-noriu.oss-cn-beijing.aliyuncs.com/Images/image-20240902151642145.png) + +![image-20240902151333560](https://picgo-noriu.oss-cn-beijing.aliyuncs.com/Images/image-20240902151333560.png) + +#### 1、配置 + +- **IP & Routing** + - \ No newline at end of file diff --git a/B. 第二阶段/拓扑练习/0902_动态NAT.md b/B. 第二阶段/拓扑练习/0902_动态NAT.md index 4a9ee78..cfbbb0c 100644 --- a/B. 第二阶段/拓扑练习/0902_动态NAT.md +++ b/B. 第二阶段/拓扑练习/0902_动态NAT.md @@ -13,6 +13,7 @@ [AR1-GigabitEthernet0/0/0]ip add 192.168.1.254 24 [AR1-GigabitEthernet0/0/0]int g0/0/1 [AR1-GigabitEthernet0/0/1]ip add 100.1.1.1 29 + [AR1-GigabitEthernet0/0/1]quit [AR1]ip route-static 0.0.0.0 0 100.1.1.2 ```