设为首页收藏本站language 语言切换
查看: 2572|回复: 3
收起左侧

[考试战报] NA -NAT地址转换问题

[复制链接]
发表于 2009-9-26 17:21:18 | 显示全部楼层 |阅读模式
想问下前辈们关于TK16中8 p6 r6 |% F" }( G6 H
% C: W  q8 O- o# S% t  A+ ~
bomar路由器s0/0配置的是192.0.2.113  ISP是192.0.2.114。
( L& f7 Q" E7 X- f& Y9 ZNAT地址转换是把192.168.16.32-46网段转换成198.18.237.225-230网段。' D% I' k7 g( b5 A* v
那么私有地址在传送到bomar路由器时,将被转换成198.18.237.225-30) w' X, O( o/ u* [
问题是198.18.237.225这个网段怎么能ping通ISP的192.0.2.114?
2 S' O4 }) J6 r
, s6 O, Q3 a/ V& p  }/ r# s. \% ]" `& Z$ B) m# B; ]
困惑已久,请指点。在线等
发表于 2009-9-26 18:07:56 | 显示全部楼层
我给你配置清单你看吧RouterA#show running-config
9 r, @8 T8 |! e( y6 z- P  f& y% H+ A!+ l  ^) K( X; i5 O7 _/ D8 R% }3 X
hostname RouterA
# u8 f6 k1 p5 ]' Y5 \$ s8 m!
: I! Y/ K- k9 i  X2 e  Mno ip domain-lookup
6 C3 g8 Q: ]- J7 V# e* b" C!$ r! n& F  w3 P7 g& X
interface Serial0/09 Y2 E7 O' H! `/ i4 W
ip address 192.168.1.1 255.255.255.07 g0 R6 \  j1 Y& M
ip nat outside, Y5 V5 w+ l( ~
serial restart-delay 0
* \* X! n$ s* W! f& O clock rate 64000* C% t  g2 \% q4 C) e
!
6 k: |" e8 {) P0 {interface FastEthernet1/0
) ]; U+ ^; |- Q8 D) X. T* j/ N ip address 10.1.1.1 255.255.255.0
* o! b# m3 k  R* v* D/ T ip nat inside" u9 `6 ]* J* |0 y$ ~
speed 100
% X: j, q9 w+ \8 \! W full-duplex; d7 S' e1 T- [, P
!6 o+ n+ z5 P6 \7 d
ip nat inside source static 10.1.1.2 192.168.1.10/ v1 q! Z! U7 G0 _8 u( g' t, ~
ip nat inside source static 10.1.1.3 192.168.1.11" t; B; K* |8 d
ip classless7 l1 Z; [, F3 j0 s
ip route 0.0.0.0 0.0.0.0 192.168.1.2
# w5 o$ _$ l8 a1 ?. V, A7 Fip http server( A6 Y" l3 h% o$ R) R1 p! r
!2 _& |  D: q+ m& V2 z7 O
!
7 p; k+ C: i9 g2 {1 |line con 0
( z" Y. m6 e/ {% E# a  B0 ]/ jline aux 0& ^9 R( M4 @) S6 o* Z
line vty 0 4! X: ^+ q3 t3 j& d4 h* w
!6 {. X$ c( w% Q; f/ J5 ?$ n
end
1 v7 Y6 @/ n/ n/ E
& c4 ]4 c. p4 u5 y; w
3 z+ f0 y3 [/ [4 v( {4 T9 b$ x, X2 |# ^% q' b3 g- b
2 V9 o" ~! m% w( |

: a; r' z9 ]6 h2 U, e! WRouterB#show running-config 4 s3 x. N) V6 }; C( A# _  ]
!, K# b% z: {# V) k, Y0 j$ k; ^
hostname RouterB
4 d; L( f- K# m% m- g5 E" F+ y7 f!# z" \. o1 P& n% _1 I: U
no ip domain-lookup: N, f) d5 Y) B/ ?, Y
!
# R6 ~& r- S$ z% O' Finterface Serial0/0
% j: x0 `7 i# y* n ip address 192.168.1.2 255.255.255.06 d" T1 H% M. G  b% f
ip nat outside3 R. |8 i8 ^* Z  H
serial restart-delay 0
( K0 Y4 V9 ?% ~6 i. W!
0 |$ B' |4 S+ S; q. u* k9 qinterface FastEthernet1/0
  U1 _: k' B- Z8 y* O2 M  _+ g2 \# G ip address 172.16.1.1 255.255.255.0
& O& B1 _$ B( z0 [2 M* J ip nat inside
4 r) A! t3 u( ^) k; k, e& O speed 100
/ Q* K1 ?" q& M7 l: z" { full-duplex( O  Z5 f- Y& e4 w* S# ^
!. Z" S7 J/ L* \" r" u$ H
ip nat inside source static 172.16.1.2 192.168.1.20. e% |! D4 ~/ `
ip nat inside source static 172.16.1.3 192.168.1.21% b7 f5 F" R2 S8 Z3 V! p! l
ip classless
$ M, p& E4 d& g( Pip route 0.0.0.0 0.0.0.0 192.168.1.1
0 |1 Z" r# J4 u8 E  Zip http server
/ Z9 R  o+ `! N' a$ R& x8 z!1 ~! U; z4 H2 P8 J1 F* z8 {
!
2 ^$ I8 t! ?5 B8 F# A! Bline con 0( M; ?- Z+ _/ |% z/ R# A
line aux 0
* L& O. I9 o- Z" P" Yline vty 0 4
5 @* ?# c7 C6 [# M) c% R& q6 p!' j" `% h' c4 p" U6 E% Y
end
% s4 _6 [: u) M% F% t
$ p: E- w! C* H9 W5 O' W& x1 Z; T! p+ v4 P; C- }. q6 Z
6 {3 r3 \1 ]: j. M! W: V, d

! S+ X  s. t& S1 \PC1#show running-config
; V6 [. F/ C/ c$ \) e5 Z: C!
3 L2 u; @4 f, a. s8 U0 |% uhostname PC1
. s- U& u" F' W1 f9 p) |!5 W4 n2 W/ t# j* c
no ip routing
8 v' v( h" M9 q1 u7 S! y8 H!
  ?2 `0 V$ U$ m, Dno ip domain-lookup
, u0 X& P! M- r: L3 J, E3 c6 {( U. r!( E0 `4 R* e( l0 _/ n6 q# K
interface FastEthernet0/01 n3 C+ `. L0 t# p3 _6 L- M; U  P5 n
ip address 10.1.1.2 255.255.255.0
6 ~/ v4 ]! D; U; U1 y" ~6 `( J8 o no ip route-cache
& J8 W- u3 Z" ?& @4 p speed 100
5 x3 V0 y4 t5 O5 s( t& e full-duplex
1 N/ t7 d! p5 L4 E+ S+ s. ~. m!3 S: Z. O( X8 @( t# t1 P- Z
ip default-gateway 10.1.1.1+ k9 g- G- d$ ]+ D( }7 f
ip classless$ N( M8 o4 P! I0 S3 x
ip http server  F4 w& T$ c" p! h! |1 S: y
!* d) K$ z" T" j, N9 b2 R) {
!
8 D. q5 K! e( vline con 0
9 n2 F; U) d" D- f! X( c( fline aux 0
' a# d* B6 [: o& iline vty 0 4' @3 O0 ^, T# k* D, d
!7 x2 p0 v8 P9 h% z) e1 N; H! L) F
end( q4 U! N! \3 d; F* N' K
5 `# V+ ~, p% Z: M

$ X' G$ {( J* i. L. g. ^  A! P
- [7 F& p/ X1 ?4 B2 @! B) a6 rPC2#show running-config
6 k+ A" w: K$ h: z8 |4 r4 M# b!8 |; U# M& |2 n# a  }% D
hostname PC2" l3 @& G5 A; Z; e, Q4 J
!
, Q8 ]# b. q6 f/ W, Z8 Y; ino ip routing
4 u( x$ h& E% S) ?!
( y# n4 X8 C+ a" b5 y; X" Uno ip domain-lookup" y6 ^8 I1 T; c" ~# Q' l/ M6 \# Z
!
1 X% r# }" S8 [: @interface FastEthernet0/0
( `8 V) Q3 p  l9 M4 G ip address 10.1.1.3 255.255.255.0/ u* w" l$ p# ]9 H
no ip route-cache
6 w- b% K, ~0 Y% G" ^' m( X( V+ z speed 100
; P% B8 Z) n( J) W0 n5 r- D& \ full-duplex
5 M) x( ^: E1 |) {. D1 Y9 y!
5 i+ t# Y" j. p9 _2 q2 o$ v) W3 sip default-gateway 10.1.1.11 T3 I  S: U8 B1 ~. \  N
ip classless& j4 ?6 ~# c& `! T
ip http server
' S6 i' K. N% K- ?( N!! W- y7 y+ K, Y* h- i: n
!& O- P) k! x# C) Y
line con 0/ r6 Q8 x7 j) B2 q- n) u
line aux 0
/ j/ D- c5 ~! U7 B2 J. c+ lline vty 0 4: o  d0 J* |1 {3 G! P3 p
!
& I& @9 w. m) V: V7 K: N6 T0 Pend% T7 j  ?) c- q5 k0 [0 N
; G8 o1 u- P& i5 t" @
0 }! {% }" J( |& ^& B' q( }
PC3#show ru
4 I+ E8 K4 j) y, `' c!3 H+ \& U( [. N& Q# u7 F
hostname Router1 h$ H! V6 [2 C
!
, i, t' U! r8 eno ip routing  o$ ~8 v% P0 u3 P
!5 U8 s* c2 }' y5 R5 s
no ip domain-lookup
) a: E0 M& z' S, j9 s  W$ X0 Q!
: R0 `. C2 t9 i6 H2 U9 c8 minterface FastEthernet0/0
) c+ O; T' ?- D3 ?/ W- A5 I, }; @ ip address 172.16.1.2 255.255.255.05 n4 s6 z7 a, i( t1 v: p
no ip route-cache
: f2 i( G" o) f1 R speed 100
2 n5 {5 ]( E+ h7 E7 D* k( J6 `. ? full-duplex
% m# ^* s2 L4 V, Z' v!! x) }/ B; l1 K, m
ip default-gateway 172.16.1.1
4 C  w6 }. |9 D# d( kip classless
& \0 y" g% y% f# B- jip http server
3 T$ y4 q% Z" U( }- G& J$ Q. s7 b0 Y!6 q" G2 I5 I6 C0 w4 k
!/ u8 t) W/ B9 d/ f
line con 0
6 n& e6 u! b* w! Sline aux 03 j; N8 E& [$ J& h6 e' d9 O
line vty 0 4
9 u( v1 g% Z2 N% z4 q!
5 \! `/ V2 r2 s# nend
+ i% `; K4 L2 Q9 y8 O" w( x; M# i
/ O& G, I2 i+ W7 J8 K
$ V# b  {+ A6 }2 b5 S, A# I& k! w
) B( z6 Z3 B* a. J4 g
  x' }( M% [2 x$ P, \4 MPC4#show running-config
; n9 n* s1 [) s/ m* K# T5 a; m+ p+ v/ d!
; v1 u7 C( S- }$ m, L- ~& k2 Zhostname PC40 ~3 y/ I& H- N. a6 T# e
!
1 m) @& I0 F% D4 B, Q( S, i+ xno ip routing
3 ^' ?/ I1 y. d# A- z3 f!& m+ m% i% m6 D% k  O
no ip domain-lookup
9 Z8 {# ~" L! P& D!
8 Z5 [3 W" s7 ointerface FastEthernet0/01 V7 W8 R4 q2 a5 i5 e5 e6 B: A! {
ip address 172.16.1.3 255.255.255.0* z; e; T) y4 |* D
no ip route-cache
& g- g( D$ V- F0 C/ F speed 100& h; h0 u8 e* {  B0 C
full-duplex3 e+ O9 V3 D! J1 A- ^5 g9 P% Q
!
! _/ ~: |  z9 U8 w! g% Tip classless4 \, H( P* {! g( S$ C
ip http server* J2 W$ h- Q( x% i
!! e$ A7 x7 Q+ j5 U+ d" \
!1 l- a! y* A7 u  N! q
line con 07 L: x; G5 d6 U! ~3 G: ~( @( J7 i
line aux 0
! A0 p* Q7 i$ |line vty 0 4
$ F6 C- ]8 L2 n, n& z- I. G# o' Y6 |!$ V. b2 H: l' u' d0 X& e! x
end
: z' }( |1 m- m/ t/ x8 `6 c8 [% K
: u( o. N8 W  X  s" j' ^
6 }, i+ d, M) X2 ^: F. S; m
  D9 o% m( B5 k; R0 E$ e+ @, x4 gSwitchA#show running-config " o* e# C$ w! l( h8 ]% ~. c1 _
!% F8 B3 p+ G/ _8 I* ]0 u# c: w/ W/ [
hostname SwitchA  T/ K0 ~( U' D5 V4 u6 U/ Z
!
4 c2 J8 `8 t. Fno ip routing" V8 q) A/ L2 m4 a+ Y
!$ N4 o, b! F3 C3 V+ j) U
interface FastEthernet0/0: Z9 ?) y3 i& M1 H1 w1 K/ Y- S7 t
duplex full
% C, S) L/ U' a% I' M; A9 z speed 1000 i: d  }+ m  C5 _; z5 }
!" P4 P5 B: @, |$ w' q
interface FastEthernet0/1. j3 C( s+ c8 {" a, g* v1 H. r
duplex full4 f2 z% c( l  @6 R' N
speed 100
, O% D; k& G" [: P( U- e!9 ^) m+ b' s" O% |8 i
interface FastEthernet0/2
' l/ i& A# d5 c/ z duplex full
* O& B; \# W# N" h speed 100
3 a; r- {3 b' g! @2 J7 D) C, u, f" U* |0 S4 p6 C: J' K* V: b
end
- e8 g* a: E+ ^. o/ h5 p8 [7 Y9 Y5 k; S% v5 ?/ B
6 c+ p) q  C  m' K

& [: r$ x( V3 H3 `9 M; DSwitchB#show running-config - Y6 [, h; `$ l
Building configuration...
# Y8 M; q) f# D' ^* a/ _+ R!- V/ ^; E: w7 l( v# F( D
hostname SwitchB  g; a$ o; k3 b4 [- U
!
. m& H+ j4 w0 fno ip routing
+ P# c8 z5 [7 `' D) d0 G# U4 e9 x!" G; Z6 q& k+ X/ S8 C
interface FastEthernet0/0  }  ?% ?, {8 Q& L4 ]) P/ {
duplex full
/ _' Z) ^- M# u) @$ F' ~; e speed 100
5 e7 d. u4 X* p, R' S!) U$ B2 I6 G  p6 i  V6 O/ u
interface FastEthernet0/1* e# E4 B* d6 g  A2 g+ R
duplex full+ ]& L1 j& E% J, X  N, v( l
speed 100/ a" w7 x! S# E) I$ F
!
( P) j7 a* k/ b" S1 \1 einterface FastEthernet0/2% Z: {& t; L, h6 s  w$ }
duplex full$ \/ D! L! z4 }
speed 100! j: p' ?/ B2 b! y  }6 o5 c7 z
!
" {/ ?. N: ?! N1 @( b# Qend
1 o$ }) D, g! C1 g) ^; M& D' `- @) ^- t6 z
DEBUG调试结果* y8 A# v3 s$ S! i3 s6 K
RouterA#debug ip nat detailed
; u* N5 ~8 u: B5 PIP NAT detailed debugging is on
+ a. `( A) y( c0 pRouterA#
# u& j3 `6 T& z9 l; l00:20:48: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [40]8 S7 `: r; q: b& q4 t3 [3 i
00:20:48: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [40]
, B+ Z7 u+ a: I- A+ ?' _6 @7 b00:20:49: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [40]9 g" A' w* P5 n9 O
00:20:49: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [40]) E( w0 |' L. E
00:20:49: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [41]
# h( `8 g% @  X' }8 T00:20:49: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [41]
! ~* ~6 p( n. r# h5 k& d# X00:20:49: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [41]
# y  `& ~% ^/ O  I! I# X6 {% t00:20:49: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [41]
/ u+ F; p$ o& M+ k4 }  `( c00:20:49: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [42]' B) I% \0 {. H( W# ~
00:20:49: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [42]9 i3 ^5 P; J4 N1 p. l
00:20:50: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [42]% k* E7 M6 Q1 h. F( X# m
00:20:50: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [42]. ~1 A* m, Z: K; u9 y$ `
00:20:50: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [43]8 Q( \/ \- u# ^. Y4 I$ S# A5 P7 |2 |
00:20:50: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [43]1 [  z0 }" P0 x" c) m5 b
00:20:50: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [43]
1 T2 I3 |5 @3 v00:20:50: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [43]
( h  {5 U7 O6 v; ?8 D$ R00:20:51: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [44]! f& g9 b' ~- f9 |0 ~
00:20:51: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [44]9 {( m3 j' |* y- r
00:20:51: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [44]
! O6 J7 K% J3 o00:20:51: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [44]
" u4 g3 y$ S& h8 a$ U
! |7 I4 n+ k  x( {' }7 ?! f$ R$ |9 t# n$ q7 z
( `) C8 a0 Z* W3 P3 e: C; S
RouterB#
) x7 M1 h/ v8 c00:20:54: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [40]
( i+ T# }3 U! ~! o5 H. T00:20:54: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [40]
) ?% z* \& ~) b/ U00:20:54: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [41]4 L" V, ?( @  Z# b7 @, C  a
00:20:54: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [41]
. D: O* v& }0 s& C9 V: D' O3 O- s9 Z7 v00:20:55: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [42]
" `9 |4 ~, I6 {- v4 ]5 X( T! |00:20:55: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [42]3 x- o, ]& }/ {$ S; ^8 h" G3 t" d
00:20:56: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [43]
: ]/ B2 g% f* R% i, G00:20:56: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [43]
% D& ~* `8 `5 e1 z# J00:20:56: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [44]) h# d2 M, l) q3 A; O. h4 ^1 }
00:20:56: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [44]3 J* e8 D" i+ N

& c+ d* U2 Z6 L# s你看了就明白了
沙发 2009-9-26 18:07:56 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2009-11-30 11:13:16 | 显示全部楼层
  
板凳 2009-11-30 11:13:16 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2012-2-25 14:26:31 | 显示全部楼层
我爱鸿鹄论坛。
地板 2012-2-25 14:26:31 回复 收起回复
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-2-3 11:12 , Processed in 0.053043 second(s), 13 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表