sys sysname SW1 undo info-center enable vlan batch 10 20 2 int vlanif 10 ip add 10.0.10.254 24 int vlanif 20 ip add 10.0.20.254 24 int g0/0/1 port link-type access port default vlan 10 int g0/0/02 port link-type access port default vlan 20 int vlanif 2 ip add 10.0.12.1 24 int g0/0/3 port link-type access port default vlan 2 quit
AR2配置
1 2 3 4 5 6 7
sys sysname AR2 int g0/0/0 ip add 10.0.12.2 24 int g0/0/1 ip add 100.1.1.2 29 quit
AR1配置
1 2 3 4 5 6 7
sys sysname AR3 int g0/0/0 ip add 100.1.1.1 29 int g0/0/1 ip add 200.1.1.254 24 quit
配置静态路由
AR2配置
1 2 3 4
ip route-static 10.0.10.0 24 10.0.12.1 ip route-static 10.0.20.0 24 10.0.12.1 #配置缺省路由确保AR2能访问公网 ip route-static 0.0.0.0 0 100.1.1.1
SW1配置
1
ip route-static 0.0.0.0 0 10.0.12.2
配置NAT
NAT配置都在出口设备的出接口进行配置。
AR2配置
1 2 3
int g0/0/1 nat static global 100.1.1.3 inside 10.0.10.1 nat static global 100.1.1.4 inside 10.0.20.1
sys sysname SW1 undo info-center enable vlan batch 10 20 2 int vlanif 10 ip add 10.0.10.254 24 int vlanif 20 ip add 10.0.20.254 24 int g0/0/1 port link-type access port default vlan 10 int g0/0/02 port link-type access port default vlan 20 int vlanif 2 ip add 10.0.12.1 24 int g0/0/3 port link-type access port default vlan 2 quit
AR2配置
1 2 3 4 5 6 7
sys sysname AR2 int g0/0/0 ip add 10.0.12.2 24 int g0/0/1 ip add 100.1.1.2 29 quit
AR1配置
1 2 3 4 5 6 7
sys sysname AR3 int g0/0/0 ip add 100.1.1.1 29 int g0/0/1 ip add 200.1.1.254 24 quit
配置静态路由
AR2配置
1 2 3 4
ip route-static 10.0.10.0 24 10.0.12.1 ip route-static 10.0.20.0 24 10.0.12.1 #配置缺省路由确保AR2能访问公网 ip route-static 0.0.0.0 0 100.1.1.1
sys sysname SW1 undo info-center enable vlan batch 2 10 20 int vlanif 2 ip add 10.0.12.1 24 int vlanif 10 ip add 10.0.10.254 24 int vlanif 20 ip add 10.0.20.254 24 int g0/0/1 port link-type access port default vlan 10 int g0/0/2 port link-type access port default vlan 20 int g0/0/3 port link-type access port default vlan 2 quit
AR2配置
1 2 3 4 5 6 7
sys sysname AR2 int g0/0/0 ip add 10.0.12.2 24 int g0/0/1 ip add 100.1.1.2 29 quit
AR1配置
1 2 3 4 5 6 7
sys sysname AR1 int g0/0/0 ip add 100.1.1.1 29 int g0/0/1 ip add 200.1.1.254 29 quit
静态路由配置
AR2
1 2 3
ip route-static 10.0.10.0 24 10.0.12.1 ip route-static 10.0.20.0 24 10.0.12.1 ip route-static 0.0.0.0 0 100.1.1.1
int g0/0/1 [AR2-GigabitEthernet0/0/1]nat server ? global Specify global information of NAT protocol Specify protocol [AR2-GigabitEthernet0/0/1]nat server protocol ? <1-255> Protocol number icmp Internet Control Message Protocol (1) tcp Transmission Control Protocol (6) udp User Datagram Protocol (17) [AR2-GigabitEthernet0/0/1]nat server protocol tcp ? global Specify global information of NAT [AR2-GigabitEthernet0/0/1]nat server protocol tcp global ? X.X.X.X Global IP address of NAT current-interface Address of current interface interface Specify the interface [AR2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface ? <0-65535> Global port of NAT CHARgen Character generator (19) any Any protocol (0) bgp Border Gateway Protocol (179) cmd Remote commands (rcmd, 514) daytime Daytime (13) discard Discard (9) domain Domain Name Service (53) echo Echo (7) exec Exec (rsh, 512) finger Finger (79) ftp File Transfer Protocol (21) gopher Gopher (70) hostname NIC hostname server (101) irc Internet Relay Chat (194) klogin Kerberos login (543) kshell Kerberos shell (544) login Login (rlogin, 513) lpd Printer service (515) nntp Network News Transport Protocol (119) pop2 Post Office Protocol v2 (109) pop3 Post Office Protocol v3 (110) smtp Simple Mail Transport Protocol (25) sunrpc Sun Remote Procedure Call (111) tacacs TAC Access Control System (49) talk Talk (517) telnet Telnet (23) time Time (37) uucp Unix-to-Unix Copy Program (540) whois Nicname (43) www World Wide Web (HTTP, 80) [AR2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000 ? inside Specify inside information of NAT [AR2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000 inside ? IP_ADDR<X.X.X.X> Inside IP address of NAT [AR2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000 inside 10.0.10.1 ? <0-65535> Inside port of NAT CHARgen Character generator (19) acl Specify acl configuration information any Any protocol (0) bgp Border Gateway Protocol (179) cmd Remote commands (rcmd, 514) daytime Daytime (13) description Specify NAT description discard Discard (9) domain Domain Name Service (53) echo Echo (7) exec Exec (rsh, 512) finger Finger (79) ftp File Transfer Protocol (21) gopher Gopher (70) hostname NIC hostname server (101) irc Internet Relay Chat (194) klogin Kerberos login (543) kshell Kerberos shell (544) login Login (rlogin, 513) lpd Printer service (515) nntp Network News Transport Protocol (119) pop2 Post Office Protocol v2 (109) pop3 Post Office Protocol v3 (110) smtp Simple Mail Transport Protocol (25) sunrpc Sun Remote Procedure Call (111) tacacs TAC Access Control System (49) talk Talk (517) telnet Telnet (23) time Time (37) uucp Unix-to-Unix Copy Program (540) vpn-instance Specify a VPN instance whois Nicname (43) www World Wide Web (HTTP, 80) <cr> Please press ENTER to execute command [AR2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000 inside 10.0.10.1 80 ###nat server protocol [协议:TCP,UDP,ICMP] global [出口的公网地址设置类型:ip_address(购买的公网IP地址),current-interface(当前出接口的公网IP地址,适用于小型企业)] [port:访问的端口号] inside [ip_address:访问的私网IP地址] [port:内部服务的端口号]