Ø 分别配置NAT NO-PAT 、NAPT、Easy-IP
Ø 客户端验证
配置NAT NO-PAT
配置内网接口IP地址指定区域
[FW2]interface
g1/0/0
[FW2-GigabitEthernet1/0/0]ip
add 192.168.10.1 24
FW2]firewall
zone trust
FW2-zone-trust]add
interface GigabitEthernet 1/0/0
配置外网接口IP地址加入到指定区域
[FW2]interface
g0/0/0
[FW2-GigabitEthernet0/0/0]ip
add 192.168.100.1 24
[FW2]firewall
zone untrust
[FW2-zone-untrust]add
interface GigabitEthernet 0/0/0
配置安全策略
FW2]security-policy
[FW2-policy-security]rule
name nat
[FW2-policy-security-rule-nat]source-zone
trust
[FW2-policy-security-rule-nat]destination-zone
untrust
[FW2-policy-security-rule-nat]source-address
192.168.10.0 24
[FW2-policy-security-rule-nat]action permit
配置NAT地址池组
[FW2]nat
address-group natno-pat
W2-address-group-natno-pat]section
0 192.168.100.3 12.168.100.4
W2-address-group-natno-pat]mode
no-pat local
配置NAT策略
[FW2]nat-policy
[FW2-policy-nat]rule name natpolicy
[FW2-policy-nat-rule-natpolicy]source-address
192.168.100.0 24
[FW2-policy-nat-rule-natpolicy]source-zone
trust
[FW2-policy-nat-rule-natpolicy]destination-zone
untrust
[FW2-policy-nat-rule-natpolicy]action nat
address-group natno
[FW2-policy-nat-rule-natpolicy]action
nat address-group natno-pat
配置路由黑洞
[FW2]ip route-static
192.168.100.3 32 NULL 0
[FW2]ip
route-static 192.168.100.4 32 NULL 0
配置默认路由
W2]ip
route-static 0.0.0.0 0.0.0.0 192.168.100.2
[R1]ip
route-static 0.0.0.0 0 GigabitEthernet 0/0/0 192.168.100.1
配置NAPT
配置地址池
FW2]nat
address-group NAPT
FW2-address-group-napt]section
0 192.168.100.3 192.168.100.3
FW2-address-group-napt]mode
pat
配置NAT策略
[FW2]nat-policy
[FW2-policy-nat]rule
name pat
FW2-policy-nat-rule-pat]source-zone
trust
[FW2-policy-nat-rule-pat]destination-zone
untrust
FW2-policy-nat-rule-pat]source-address
192.168.10.0 24
[FW2-policy-nat-rule-pat]action
nat address-group NAPT
查看地址转换
W2]display
firewall session table
配置Easy-ip 的NAT
配置NAT策略
[FW2]nat-policy
[FW2-policy-nat]rule
name easyip
-policy-nat-rule-easyip]source-address
192.168.10.0 24
FW2-policy-nat-rule-easyip]source-zone
trust
FW2-policy-nat-rule-easyip]destination-zone
untrust
W2-policy-nat-rule-easyip]action
nat easy-ip