
Server1配置: Server1#conf t Server1(config)#no ip routing Server1(config)#ip default-gateway 192.168.0.1 Server1(config)#int fa0/0 Server1(config-if)#ip add 192.168.0.101 255.255.255.0 Server1(config-if)#no sh Server1(config-if)#exit Server1(config)#line vty 0 4 Server1(config-line)#password cisco Server1(config-line)#login Server1(config-line)#exit Server2配置: Server2#conf t Server2(config)#no ip routing Server2(config)#ip default-gateway 192.168.0.1 Server2(config)#int fa0/0 Server2(config-if)#ip add 192.168.0.102 255.255.255.0 Server2(config-if)#no sh Server2(config-if)#exit Server2(config)#line vty 0 4 Server2(config-line)#password cisco Server2(config-line)#login Server2(config-line)#exit Server3配置: Server3#conf t Enter configuration commands, one per line. End with CNTL/Z. Server3(config)#no ip routing Server3(config)#ip default-gateway 192.168.0.1 Server3(config)#int fa0/0 Server3(config-if)#ip add 192.168.0.103 255.255.255.0 Server3(config-if)#no sh Server3(config-if)#exit Server3(config)#line vty 0 4 Server3(config-line)#password cisco Server3(config-line)#login Server3(config-line)#exit Internet配置: Internet#conf t Internet(config)#int fa0/0 Internet(config-if)#ip add 202.100.100.100 255.255.255.0 Internet(config-if)#no sh Internet(config-if)#exit R1配置: R1#conf t R1(config)#int fa0/0 R1(config-if)#ip add 192.168.0.1 255.255.255.0 R1(config-if)#ip nat inside R1(config-if)#no sh R1(config-if)#exit R1(config)#int fa0/1 R1(config-if)#ip add 202.100.100.80 255.255.255.0 //主ip R1(config-if)#ip add 202.100.100.1 255.255.255.0 secondary//副ip R1(config-if)#ip nat outside R1(config-if)#no sh R1(config-if)#exit R1(config)#ip access-list extended VIP //标识用来转换的公网IP R1(config-ext-nacl)#permit ip any host 202.100.100.1 R1(config-ext-nacl)#deny ip any any R1(config-ext-nacl)#exit R1(config)#ip nat pool serverfarm 192.168.0.101 192.168.0.103 netmask 255.255.255.0 type rotary//定义NAT地址池来标识内部服务器的本地地址,注意要用到关键字rotary,表明我们要使用轮循的方式从NAT地址池中取出相应IP地址来转换合法IP报文。最后,把目标地址为访问表中IP的报文转换成地址池中定义的IP地址。 R1(config)#ip nat inside destination list VIP pool serverfarm
疑问:最后一句ip nat inside destination list VIP pool serverfarm,不应该写成ip nat outside destination list VIP pool serverfarm吗?到达nat outside域的数据,过滤目的地址为202.100.100.1的数据,把这写数据分组目的地址改写为serverfarm的地址。
|