1.静态NAT
2.动态NAT3.复用内部全局地址的NAT(PAT)enableconf tno ip do loenable pass ciscoline con 0logg syncexec-t 0 0line vty 0 4pass ciscologg syncexithost 1.静态NATR2为一个ISP接入路由器,客户端为(R1,R3),ISP分配给客户端一个公网IP地址为12.1.1.1.客户端服务器内网地址为33.1.1.1.(R1,R3)运行OSPF协议,通过默认路由访问外网。R1:int s1/1ip add 13.1.1.1 255.255.255.0no shutexitint s1/0ip add 12.1.1.1 255.255.255.0no shutexitrouter ospf 1router-id 11.1.1.1network 13.1.1.0 0.0.0.255 area 0default-info originateexitip route 0.0.0.0 0.0.0.0 12.1.1.2R3:int s1/1ip add 13.1.1.3 255.255.255.0no shutexitint l0ip add 33.1.1.1 255.255.255.0no shutexitrouter ospf 1router-id 33.1.1.1network 13.1.1.0 0.0.0.255 area 0network 33.1.1.0 0.0.0.255 area 0exitR2:int s1/0ip add 12.1.1.2 255.255.255.0no shutexitint l0ip add 22.1.1.1 255.255.255.0no shutexitip route 0.0.0.0 0.0.0.0 12.1.1.1R1:ip nat inside source static 33.1.1.1 12.1.1.1int s1/1ip nat insideexitint s1/0ip nat outsidedebug ip natR3:ping 22.1.1.1 source 33.1.1.12.动态NAT不能用一个本地全局地址访问内部特定地址,因为每次分配的本地全局地址可能不同。仿真客户从ISP处申请了10个公网IP(12.1.1.1-10/24)R1:ip nat pool WBSN 12.1.1.1 12.1.1.10 netmask 255.255.255.0access-list 1 permit 33.1.1.1 0.0.0.255ip nat inside source list 1 pool WBSNint s1/1ip nat insideexitint s1/0ip nat outsideR3:int l0ip add 33.1.1.2 255.255.255.0 secondaryip add 33.1.1.3 255.255.255.0 secondaryip add 33.1.1.4 255.255.255.0 secondaryip add 33.1.1.5 255.255.255.0 secondaryexitping 22.1.1.1 source 33.1.1.1ping 22.1.1.1 source 33.1.1.2ping 22.1.1.1 source 33.1.1.3ping 22.1.1.1 source 33.1.1.4ping 22.1.1.1 source 33.1.1.5R1:show ip nat translationsshow ip nat translations verbose3.复用内部全局地址的NAT(PAT)当多个本地地址映射到同一个全局地址的时候,用端口号来区别不同的本地地址。R1:ip nat pool WBSN 12.1.1.1 12.1.1.1 netmask 255.255.255.0access-list 1 permit 33.1.1.1 0.0.0.255ip nat inside source list 1 pool WBSN overloadint s1/1ip nat insideexitint s1/0ip nat outsideR3:int l0ip add 33.1.1.2 255.255.255.0 secondaryip add 33.1.1.3 255.255.255.0 secondaryip add 33.1.1.4 255.255.255.0 secondaryip add 33.1.1.5 255.255.255.0 secondaryexitping 22.1.1.1 source 33.1.1.1ping 22.1.1.1 source 33.1.1.2ping 22.1.1.1 source 33.1.1.3ping 22.1.1.1 source 33.1.1.4ping 22.1.1.1 source 33.1.1.5R1:show ip nat translationsshow ip nat translations verbose