设为首页收藏本站language 语言切换
查看: 2568|回复: 3
收起左侧

[考试战报] NA -NAT地址转换问题

[复制链接]
发表于 2009-9-26 17:21:18 | 显示全部楼层 |阅读模式
想问下前辈们关于TK16中
2 t9 [# @5 c, h! |/ ~& u5 Y  ^# ~3 C
bomar路由器s0/0配置的是192.0.2.113  ISP是192.0.2.114。
0 @: L- ~7 D9 A  Q6 wNAT地址转换是把192.168.16.32-46网段转换成198.18.237.225-230网段。: y& b, g8 p; R
那么私有地址在传送到bomar路由器时,将被转换成198.18.237.225-30; l5 R* p3 u9 L! A6 b  {# y2 P4 @
问题是198.18.237.225这个网段怎么能ping通ISP的192.0.2.114?7 q6 V( Y! g7 [- P4 e( W" e

" g0 L- y$ b1 l: p; W% g* T! {+ p
困惑已久,请指点。在线等
发表于 2009-9-26 18:07:56 | 显示全部楼层
我给你配置清单你看吧RouterA#show running-config % s: i7 T' s3 n/ n5 N9 c  I" n
!( }: A' ^2 e$ ?" w: \2 J
hostname RouterA
# K2 U  p" h' A$ j) X8 `8 l!
/ I. S% k7 D* h. Z' K9 E" P+ ano ip domain-lookup4 E" M4 U+ J$ H0 v" }2 E0 U" B  T8 E
!) t9 e8 M+ @+ ]2 K* q6 c
interface Serial0/0$ b1 ~6 O- [. b
ip address 192.168.1.1 255.255.255.08 T. |/ g$ o  y- S* l3 z" {6 c
ip nat outside3 h! y6 {; f0 t# A5 G3 h
serial restart-delay 0
1 }4 q5 ^2 k: u. W! X clock rate 64000
" ?. S4 g! b. f+ O8 j0 {+ i!$ U! h$ E% e$ A) q& S
interface FastEthernet1/0
  Z  A% b* B) r) v( Q ip address 10.1.1.1 255.255.255.0
% D0 m, D0 @+ U$ P4 N ip nat inside, r; ]! x0 j3 _# o
speed 100
% v5 c' q) d( R$ X! O& N: L4 G full-duplex
  l  t% r, `: n!
7 _* N5 |6 i6 ^' z6 a0 j; |, Uip nat inside source static 10.1.1.2 192.168.1.10
2 x: {  ^. {- R9 Cip nat inside source static 10.1.1.3 192.168.1.11
+ G, h% Q" r$ \$ B/ {ip classless8 q  D! i  @8 h- o7 j7 _
ip route 0.0.0.0 0.0.0.0 192.168.1.2' t( o7 C* K( ?) @+ l" a
ip http server; P: E# w- Y- ]: ~
!
5 X5 A$ `* P9 \/ V/ z* g!
. J" n- u: D1 _  L5 G' w1 Yline con 02 P- n% E" j7 I$ L3 |8 J7 W
line aux 0
7 i* C4 `; M& Nline vty 0 4
, c3 }2 F" }' |!
  T1 \* s, M8 k7 U+ y8 B) bend
0 N+ E! U9 f7 o3 p) }% B$ V( {9 V4 G  O. W; ^' J! U* P9 A
; U5 o/ f; l1 M9 a
4 E/ ^/ s# C) f/ _' K3 o

! l' G7 A) B  _6 J7 X0 j- g! X) N
! [* ^6 p. l( f1 P# N+ b) n; y( G! o7 bRouterB#show running-config ' i+ ?& J( p' ^
!
5 O0 Y$ f# V$ u, T9 K1 e4 hhostname RouterB
: k: m" X5 e6 M!/ f: [& I( A  N* x
no ip domain-lookup- M3 Y: J4 D4 s# z! _) F
!4 D! e3 c* m( ]$ j# k% `0 z
interface Serial0/0$ {* V& m- i$ g
ip address 192.168.1.2 255.255.255.02 t* Q$ t; i  t: b# C3 x
ip nat outside& `, l) _+ \1 t) ?  e4 c
serial restart-delay 0; [' `3 b  @$ Z; L# x3 N
!
7 U/ N) d% x( i8 ]interface FastEthernet1/0! V- _/ S( j3 Z0 J5 H9 s! u
ip address 172.16.1.1 255.255.255.0# M" l5 n7 i" j% E% U
ip nat inside
7 W+ _: X) X6 W, Y% d speed 100! a6 H+ P6 {- c6 x" M
full-duplex
% p" O2 p5 Z- m2 \( g' g!0 {; c0 x9 r1 H! ~$ B2 ~5 Z
ip nat inside source static 172.16.1.2 192.168.1.20' j+ ?6 i1 }" ?3 i2 J1 C
ip nat inside source static 172.16.1.3 192.168.1.21, z0 Z9 T8 z) s! M; x9 r
ip classless
# i) k0 h6 n% x- }: W8 Sip route 0.0.0.0 0.0.0.0 192.168.1.12 g6 p1 Y2 s, K5 I0 z7 j4 ~* C
ip http server
# v1 e  A( C( f. ^+ R, j+ t% i2 {!) d0 C2 Z3 @" P  c& p. Z
!
9 i7 u% o- f+ T: N6 i  z- g$ B' g% Mline con 0/ T# m4 R: q6 U( M+ y& T8 H- U* P
line aux 0$ W2 \7 M' C; y0 C( W& O% s9 C2 [2 ~
line vty 0 4
+ r9 I" {$ Z$ f8 ?" K7 F!' [- q5 j$ h' `, U7 V8 z. r
end1 |: O. c% U3 ~+ @  `& @  I' q
( N# V- }' f6 H5 B

, h3 [+ ^; c9 ^& C: i  c+ _2 v% V5 e; W$ z1 o) C, z
! t$ O& ]1 O) ?' k& `+ p
PC1#show running-config   L8 o, Q; d; X' j5 M
!' f, v' g9 D- c& c
hostname PC1
6 K/ t- ~2 k- U( r5 _4 d9 ]2 F& r- u!
. d9 {' z$ X. Eno ip routing
# v1 B5 o# P$ a+ o# }!
& Z7 I+ F! q4 L! y+ vno ip domain-lookup
9 q7 R( Y" _* j3 a  x: [!1 f3 K6 B4 x8 }) s' p
interface FastEthernet0/09 @/ t5 R6 B5 x! }4 ^& c! H& A9 \9 \
ip address 10.1.1.2 255.255.255.0
" t: k- F( Z! L no ip route-cache5 s5 ~; W: |0 j2 R$ k
speed 100! h" N4 ?' W7 q, f2 r
full-duplex$ g% q/ G) W6 g4 t4 ~* d# q
!6 r' T5 h! S$ q5 b
ip default-gateway 10.1.1.1
+ X" O. p% ~. t0 Pip classless9 @+ _  o2 ]3 C$ g# D
ip http server
( k3 A% L6 B  b!
% B, Z0 j5 ?" L. D( o6 `!9 o# ~0 }, Y, N* G. N
line con 03 L  ]+ b' V( v4 m; n! j
line aux 03 C6 P% Q. K% Z. ?: D
line vty 0 4
$ X) l" j+ a2 C1 u2 j: z) k!
2 @% F" L2 b) I1 ]end
/ h5 N9 n* A/ z+ @7 q5 k$ I& v* h

: |% V6 k. N- Z! D) Q+ `% C& E; f  B* h' Y: ]
PC2#show running-config ; B/ q+ U. {. S- _$ [
!1 k1 H6 T8 ^$ [  P( d
hostname PC2& u# R+ f4 O' X$ H' |- {0 \
!0 O- |7 C# i3 o+ j
no ip routing
7 _) H$ U; O: m6 D!3 [) m7 S/ O4 b( j
no ip domain-lookup4 |1 j- N2 F' q; C: b3 _8 h% Y
!
) `7 t2 Q" Y8 P$ q& W& x; einterface FastEthernet0/0
; h' o+ p/ ?# R4 o! J# I$ C ip address 10.1.1.3 255.255.255.0
1 ?3 t4 k% S, e: P% c( g no ip route-cache
7 {! d' K5 z. u. l& H: U6 b speed 100; b9 I- Q7 L% X* J$ j5 F
full-duplex+ Z( h! B9 M4 |2 _5 t0 \. n* Q+ T
!7 ]: Y' e: K! w5 m7 Z  F. @9 z
ip default-gateway 10.1.1.15 \3 i# O0 e, H
ip classless
/ R; i4 h. n( S% w. jip http server3 U! j1 \$ u+ L
!
2 R7 j" g$ N7 ~!
3 `2 y6 E; z( `2 U. Jline con 0  N( y1 O  X( m% {. X* F
line aux 0# y! D$ N0 k! ]3 F4 }7 S7 ^( b
line vty 0 4
8 G" e0 M) d  d- Z2 u% g!- d4 ?. [7 R/ Z- n: r
end
; ~3 |3 d4 Q0 w3 Q0 }2 D; K
6 ]+ W2 i) [3 A2 \" Z' b* e2 E+ M4 [4 M( w4 ~4 c
PC3#show ru/ [: K  A6 C! d
!
$ ~8 j2 F. B& z5 F# Dhostname Router, b, Z7 p  a1 Y& i7 @
!1 A/ J  ~( G6 Q( T5 e2 ^
no ip routing
6 O+ i5 |% M0 f( L) g) S+ S!
3 N, R+ M% N5 O! Q- {& r# {no ip domain-lookup
+ H- b! z" _0 {! R6 X# B3 d!
9 t. M1 u* E/ [" R5 i& `interface FastEthernet0/0  w& t& X3 r8 n4 w2 I6 a  C% e
ip address 172.16.1.2 255.255.255.0
0 o  S/ T) }( v1 i, ~ no ip route-cache* X- u2 f" U$ g; s
speed 1001 u1 }& i; w( f
full-duplex' `. j3 Y  c& N( K7 h/ @7 @0 s# \
!8 i. e# R/ Z1 I* n: w& ?
ip default-gateway 172.16.1.1
# n: j: L% S* z( e! uip classless2 r7 T  U; e; y1 N6 j( B0 \
ip http server0 p1 F9 [+ {+ j$ b( w, ^
!
  Z# F' |5 I/ L: B* K6 y; W0 a- d!
; Y3 N. r# t* r3 U: }% a+ Sline con 03 a9 {$ W  S8 P+ g- }
line aux 0( P2 M- z& v7 P+ \4 P
line vty 0 48 g+ u/ E9 O) J- Z* Y
!
- P. r# y" j7 r- E0 t" ?end
3 t& b# E' b$ j% G2 `) M
7 A( ?& H  O: {' u5 o* T3 N. x
; z# G: _# d3 N* b8 C. X$ b* f" K# Q/ ?5 P  z
0 N# S2 K4 j+ G. d
PC4#show running-config
- \7 u4 i. P, A3 Q!6 i9 h, X2 Y; O0 y% X
hostname PC4  l: s  X# g+ `2 ~$ e
!& d% P  f- b# C! g
no ip routing
0 K5 O0 `* T" m, Y) r! @! w2 m!
1 y: |/ @( X* |, j1 eno ip domain-lookup
8 T+ s; Q; F' O+ r& ]!% A% l, a& p1 @# T$ v. p0 F& ^8 s
interface FastEthernet0/0
1 j( Y) [/ Z% A- B  }  i9 f( @ ip address 172.16.1.3 255.255.255.0) G' j' a6 A% D# w; |( {
no ip route-cache
& A6 ^6 L! ?9 h" ?$ o, ?5 h! S1 H speed 1005 a0 a5 `2 e5 y0 b1 a1 t9 k
full-duplex) j, u6 @: W8 h0 a
!
2 i& N) q. b' H) ^0 Y6 U! Fip classless$ r! N+ i: @* q
ip http server
% I/ q) f7 h9 k- W!
, U' Q* ]! u- X" E$ `* T!3 v0 H9 ?+ j# v6 l% _
line con 0$ R8 ?5 q' L$ D
line aux 05 }: a8 A; z, e' o! K
line vty 0 4
9 x1 X9 x0 i" q!7 x. m( S- P# w
end+ @# o6 N1 \/ d$ H) A

- V! b- G: A$ J- E7 {: O- W! f
& T* G' x& Q  {  F. J
7 W% B% S! d3 k' J9 B0 k. |SwitchA#show running-config ) B' V0 N1 ?/ j; X
!) a7 u0 |7 @: B, T2 c9 Q7 ^1 H
hostname SwitchA
% S* u0 }$ x9 t0 g; Z# `  [!; J4 Z' i  }, U
no ip routing
  h- f% z& X2 d3 i!
4 l7 Q* l0 S% O3 |/ [, x3 p' \interface FastEthernet0/0+ C) _" k* S4 O1 S
duplex full
: h% U! o# R( A% k- N& f4 D; E! |8 L3 ^ speed 1005 g( c9 f+ d; Y2 {% l
!
) s3 T8 d  {, z# N7 U, O$ ^interface FastEthernet0/1  Z+ T- P+ h% V8 R! p
duplex full
8 E) d4 x$ ?" h1 X7 p speed 100
7 o6 Q, m1 u# n0 j0 o8 j!* [! s& O: O) J  f& O9 J
interface FastEthernet0/2
* y1 V! @* Z: H' d$ \8 C duplex full
. l+ W3 n% G9 M; U4 z9 J7 H speed 100  I8 M% t$ t3 i' d* y: ?
/ j* Z7 _6 r7 S; s6 t& S2 _6 b
end" F6 d1 g; k8 T  y, c% H0 p. k8 K
: L+ J. f* L$ g5 a
/ A0 v6 l. q4 E7 Y8 t

" s: O( Q5 X+ \/ xSwitchB#show running-config 6 }4 v  f- x/ ~. i, p; Y
Building configuration...
( q4 Y' ~2 C( {6 _!
  T8 Y. @8 N3 O1 T, a; J( ^hostname SwitchB' H: @  [0 ]8 d, ?; e4 ]# U
!) S8 }9 J. d( v6 I$ }" A
no ip routing3 h7 w, H- x0 t; A% O8 Z0 M7 O
!$ H6 o9 d# w) r
interface FastEthernet0/0
3 T- U( ]$ ^, D- W! D, ? duplex full
' v. D9 A$ n  E( A. Z- q: S+ j3 o speed 100
8 r; M8 }8 o, P9 U!( |3 V1 S4 u. J1 o/ H
interface FastEthernet0/1
, L7 s3 ?+ d  i6 x; ?5 k" i# N duplex full) ?" w* m. B' O6 y7 w( A0 J
speed 100
) b* p2 L2 W5 T* V/ b3 h5 F!
6 {( r( z6 V* x: d% u- Zinterface FastEthernet0/2
! y  B/ ]- _6 S3 \ duplex full* n% s/ `8 O; h* f  n) W$ M
speed 100# l9 \3 [- T. z  i% q3 f
!
1 W1 h1 w4 A2 x* r* I$ eend
) X' W& N4 e" j/ w. |" `& f6 u$ R; N' U: s2 E
DEBUG调试结果
" o# c. ?1 d, \+ tRouterA#debug ip nat detailed
9 \  G, w9 }9 KIP NAT detailed debugging is on
' r6 h  e7 |3 O6 ^RouterA#
- i9 u7 @/ v- M" x9 b00:20:48: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [40]
- A; I( ?" o) m5 H7 W$ W00:20:48: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [40]: d5 [  I$ i4 ~
00:20:49: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [40]
0 T+ x6 Z( |# R0 M- `# a00:20:49: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [40]
+ j8 t1 y* u$ }( c. j3 K00:20:49: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [41], g$ V' H9 u, q
00:20:49: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [41]
3 k3 f4 T; }9 }/ _00:20:49: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [41]" p4 g; v/ N  b0 G
00:20:49: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [41]
  R0 t# d% w  N5 A& G% ^( d00:20:49: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [42]
* A) ]7 U) U& r* t2 q% j7 R00:20:49: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [42]- i% g4 J# z8 h; n/ Y5 T9 |8 Z
00:20:50: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [42]+ B. D# Q& |2 d$ ?  G1 c* M; f
00:20:50: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [42]; j9 N* `7 \# n( N! A4 x3 A5 E
00:20:50: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [43]
" f% C7 O- x* d+ N2 t! O00:20:50: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [43]
' X' C& _" Z/ u6 x4 z6 a00:20:50: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [43]7 h7 \- E2 O8 e3 F" S+ s; L
00:20:50: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [43]8 G$ F6 c. j$ j8 p2 |
00:20:51: NAT*: i: icmp (10.1.1.2, 8) -> (172.16.1.3, 8) [44]
& X9 o0 I4 I2 R00:20:51: NAT*: s=10.1.1.2->192.168.1.10, d=172.16.1.3 [44]; h3 W# Q* }9 u  v* P! S7 M  ]
00:20:51: NAT*: o: icmp (192.168.1.21, 8) -> (192.168.1.10, 8) [44]- M" A% K1 r: Q' q1 H
00:20:51: NAT*: s=192.168.1.21, d=192.168.1.10->10.1.1.2 [44]
2 x9 O% W' Y$ t: U* R4 `
  Y  T3 N4 @: f9 u: m( U2 D5 Z, k* r! p! y
' B, i# X1 W8 P. ~6 N" `3 [
RouterB#3 Z2 n% c- W- p' {" U: ?
00:20:54: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [40]
9 N" _; W. s" e# K00:20:54: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [40]. I$ P( q% W7 |9 c, L- H' w! t7 ]4 g
00:20:54: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [41]* v1 o) \& P9 i0 d: I
00:20:54: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [41]
0 V8 q$ I+ t/ ^8 A" ?* ?* c00:20:55: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [42]
3 g! N0 N  u, r4 n. r! h' l5 ]00:20:55: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [42]: e  F' K  Y0 \, w( c
00:20:56: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [43]
4 Z! T/ H5 [% i00:20:56: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [43]: d+ r6 o# C$ Y$ U5 U: V% ^
00:20:56: NAT*: i: icmp (172.16.1.3, 8) -> (192.168.1.10, 8) [44]6 i. r5 I& N& [9 k# u/ H  H$ U
00:20:56: NAT*: s=172.16.1.3->192.168.1.21, d=192.168.1.10 [44]3 k  q- I7 Z  I
; g, ^/ z$ w! ^
你看了就明白了
沙发 2009-9-26 18:07:56 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2009-11-30 11:13:16 | 显示全部楼层
  
板凳 2009-11-30 11:13:16 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2012-2-25 14:26:31 | 显示全部楼层
我爱鸿鹄论坛。
地板 2012-2-25 14:26:31 回复 收起回复
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-2-3 11:07 , Processed in 0.056892 second(s), 14 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表