欢迎来到天天文库
浏览记录
ID:37488990
大小:144.81 KB
页数:9页
时间:2019-05-24
《ASA8.3及以后版本NAT配置介绍》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、NetworkObjectNAT配置介绍1.DynamicNAT(动态NAT,动态一对一) 实例一: 传统配置方法: nat(Inside)110.1.1.0255.255.255.0 global(Outside)1202.100.1.100-202.100.1.200 新配置方法(NetworkObjectNAT) objectnetworkOutside-Nat-Pool range202.100.1.100202.100.1.200 objectnetw
2、orkInside-Network subnet10.1.1.0255.255.255.0 objectnetworkInside-Network nat(Inside,Outside)dynamicOutside-Nat-Pool 实例二: objectnetworkOutside-Nat-Pool range202.100.1.100202.100.1.200 objectnetworkOutside-PAT-Address host202.10
3、0.1.201 object-groupnetworkOutside-Address network-objectobjectOutside-Nat-Pool network-objectobjectOutside-PAT-Address objectnetworkInside-Network(先100-200动态一对一,然后202.100.1.201动态PAT,最后使用接口地址动态PAT) nat(Inside,Outside)dynamicOutside-Addres
4、sinterface 这种配置方式的好处是,新的NAT命令绑定了源接口和目的接口,所以不会出现传统配置影响DMZ的问题(当时需要nat0+acl来旁路) 2.DynamicPAT(Hide)(动态PAT,动态多对一) 传统配置方式: nat(Inside)110.1.1.0255.255.255.0 global(outside)1202.100.1.101 新配置方法(NetworkObjectNAT) objectnetworkInside-Network s
5、ubnet10.1.1.0255.255.255.0 objectnetworkOutside-PAT-Address host202.100.1.101 objectnetworkInside-Network nat(Inside,Outside)dynamicOutside-PAT-Address or nat(Inside,Outside)dynamic202.100.1.102 3.StaticNATorStaticNATwithPortTranslat
6、ion(静态一对一转换,静态端口转换) 实例一:(静态一对一转换) 传统配置方式: static(Inside,outside)202.100.1.10110.1.1.1 新配置方法(NetworkObjectNAT) objectnetworkStatic-Outside-Address host202.100.1.101 objectnetworkStatic-Inside-Address host10.1.1.1 objectnetworkSt
7、atic-Inside-Address nat(Inside,Outside)staticStatic-Outside-Address or nat(Inside,Outside)static202.100.1.102 实例二:(静态端口转换) 传统配置方式: static(inside,outside)tcp202.100.1.102232310.1.1.123 新配置方法(NetworkObjectNAT) objectnetworkStati
8、c-Outside-Address host202.100.1.101 objectnetworkStatic-Inside-Address host10.1.1.1 objectnetworkStatic-Inside-Address nat(Inside,Outside)staticStatic-Outside-Addressservicetcptelnet2323 or nat(Inside,Outs
此文档下载收益归作者所有