ããã«ã¡ã¯ãååïŒ
ãªã¹ããŒãååããã®ãã©ãŒã©ã ã®å€ãã®è³ªåïŒæçš¿ã®æåŸã®ãªã³ã¯ïŒãã倿ãããšãCiscoã«ãŒã¿ãŒã§ã®NATã®åäœïŒãã¡ã€ã¢ãŠã©ãŒã«ã¯çç¥ããŸã
ãFediaã¯Cisco ASAã«é¢ããäžé£ã®èšäºã§ååã«è©³çްã«èª¬æããŠããŸãïŒã»ãšãã©ã®åœ¢åŒã§ããã®ãã¯ãããžãŒã®çµéšãšçè§£ã説æããŠãã ããã å
æ¬çãªèª¬æãš100ïŒ
ã®æ£ç¢ºããè£
ãããã§ã¯ãããŸããããé¢çœãã®ã¯ç«ã§ãã
ãããã£ãŠãèšè¿°ã®æ§é ã«ã€ããŠã¯ãNATãšã¯äœãã®å®çŸ©ãæ±ããŸãã
å®çŸ© NAT ïŒNetwork Address TranslationïŒã¯ããããã¯ãŒã¯ã¢ãã¬ã¹ã倿ããããã®æè¡ã§ãã IPãã±ããããããŒã®ã¢ãã¬ã¹ã®ã¹ããŒãã£ã³ã°ïŒTCP / UDPããããŒã®ããŒãã倿ŽããããšããããŸãããããã«ã€ããŠã¯åŸã§è©³ãã説æããŸãïŒã
èšãæããã°ãã«ãŒã¿ãŒãééãããã±ããã¯ããã®éä¿¡å
ããã³/ãŸãã¯å®å
ã¢ãã¬ã¹ã倿Žã§ããŸãã
ãªããããå¿
èŠãªã®ã§ããïŒ
1.ãã©ã€ããŒãIPã¢ãã¬ã¹ãæããã䜿çšãããLANãããã°ããŒãã«IPã¢ãã¬ã¹ã®ã¿ãã«ãŒãã£ã³ã°ãããã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãæäŸããããã
2.ïŒ
çšåºŠã¯äœãã ïŒãããã¯ãŒã¯ããããžãé ãããããã¯ãŒã¯ãžã®äŸµå
¥ã«å¯Ÿããäœããã®ä¿è·ããªã¢ãäœæããŸãïŒããã«ã€ããŠã¯ãåŸã»ã©äŸã§èª¬æããŸãïŒã
NATã¯ç°ãªãå ŽåããããŸã:)ãããŠãããã«ã€ããŠã¯ãã§ã«å€ãã®ããšãæžãããŠããŸãããNATã«é¢ãã質åã®ããåå¿è
ãç¹å®ã®ã¢ãã¬ã¹ã«éããããšããèŠæããããŸãã
1.
éçNAT-éçNATã¯ãããã¢ãã¬ã¹ãšå¥ã®ã¢ãã¬ã¹ã®éã«äžæã®å¯Ÿå¿ãèšå®ããŸãã ã€ãŸããã«ãŒã¿ãŒãééãããšãã«ãã¢ãã¬ã¹ã¯å³å¯ã«æå®ãããã¢ãã¬ã¹ã«1察1ã«å€æŽãããŸãã ïŒããšãã°ã10.1.1.1ã¯åžžã«11.1.1.1ã«çœ®ãæãããããã®éãåæ§ã§ããã12.1.1.1ã«ã¯çœ®ãæããããŸããïŒã ãã®ãããªãããŒããã£ã¹ãã®èšé²ã¯ãèšå®ã«è¡ãããéããç¡æéã«ä¿åãããŸãã
2.
ãã€ãããã¯NAT-ã«ãŒã¿ãŒãééãããšãã«ãããŒã«ïŒè±èªã®ããŒã«ïŒãšåŒã°ããã¢ãã¬ã¹ã®äžéšããæ°ããã¢ãã¬ã¹ãåçã«éžæãããŸãã ãããŒããã£ã¹ãã¬ã³ãŒãã¯ãå¿çãã±ãããåä¿¡è
ã«é
ä¿¡ã§ããããã«ããã°ããä¿æãããŸãã ãã®ãããŒããã£ã¹ãã®ãã©ãã£ãã¯ããã°ããã®éååšããªãå ŽåããããŒããã£ã¹ãã¯åé€ãããã¢ãã¬ã¹ãããŒã«ã«è¿ãããŸãã 倿ãäœæãããããããŒã«ã«ç©ºãã¢ãã¬ã¹ããªãå Žåããã±ããã¯ç Žæ£ãããŸãã èšãæããã°ãå
éšã¢ãã¬ã¹ã®æ°ãããŒã«å
ã®ã¢ãã¬ã¹ã®æ°ãããããã«å€§ãããã°ãå€éšãžã®ã¢ã¯ã»ã¹ã§åé¡ãçºçããå¯èœæ§ãé«ããªããŸãã
3.
ãªãŒããŒããŒããŸãã¯PATã䜿çšãããã€ãããã¯NAT ã ãã€ãããã¯NATãšã»ãŒåãããã«æ©èœããŸããããã©ã³ã¹ããŒãã¬ã€ã€ãŒã®æ©èœã䜿çšããªãããåæã«å€å¯Ÿ1ã®å€æãè¡ãããŸãã ããã«ã€ããŠã¯ã以äžã®äŸã§è©³ãã説æããŸãã
ç§ã¯ã»ãšãã©ã®å Žåã·ã¹ã³ã®ããŒããŠã§ã¢ã䜿çšããŠããããããã®èšäºã§ã¯ãããã®ããŒããŠã§ã¢äžã§ã®äœæ¥ã®æ©èœãšNATã®å¯èœãªãªãã·ã§ã³ãæ£ç¢ºã«èª¬æããŸãã
ãã®å Žåã«äœããããèŠãŠã¿ãŸãããã
1.å
éšãœãŒã¹NAT
æãäžè¬çã§ããªãåçŽãªãªãã·ã§ã³ã ãã®ãããªããããžããããšããŸãããïŒ
èšãæããã°
aïŒå
éšã¢ãã¬ã¹ã®ãµãããã-10.0.0.0/8
bïŒå€éšã¢ãã¬ã¹ã®ãµãããã-11.0.0.0/8
ãããŠããã©ãã£ãã¯ãã«ãŒã¿ãŒãééãããšãã«ãäœããã®æ¹æ³ã§å
éšã¢ãã¬ã¹ãå€éšã¢ãã¬ã¹ã«å€æããããšèããŠããŸãã
ããã«ã¯äœãå¿
èŠã§ããïŒ
1.ãããŒããã£ã¹ããã
å
容ãæç€ºçã«æå®ããŸãã ã€ãŸã ã©ã®ãã©ãã£ãã¯ãšã©ã®ãã¹ãããã
2.翻蚳ãã察象ãæç¢ºã«ç€ºããŸããã€ãŸãã å€éšã¢ãã¬ã¹ã®ããŒã«ïŒãŸãã¯éç倿çšã®å¯äžã®ã¢ãã¬ã¹ïŒã
3.å
éšããã³å€éšã€ã³ã¿ãŒãã§ã€ã¹ãããŒã¯ããŸãã
4.ãããŒããã£ã¹ãããªã³ã«ããŸãã
ãã©ã°ã©ã3ã§ã¯ã誀解ããã°ãã°çºçãããããããã§è©³çްã«èª¬æããŸãã
ã©ã®ããã«æ©èœããŸããïŒ
ãããã£ãŠã11æ¥ã«ã¯10çªç®ã®ãããã¯ãŒã¯å
šäœããããŒããã£ã¹ãããããšã«ãããšããŸãããã ããã«å¿ããŠããããèšå®ããŸãïŒèšå®ã¯åŸã§ãæåã®çè«ïŒã ãŸããã€ã³ã¿ãŒãã§ã€ã¹ãå
éšïŒå
éšïŒããã³å€éšïŒå€éšïŒãšããŠããŒã¯ããŸããã
次ã«ã
å
éšãœãŒã¹NATãæ£ç¢º
ã«äœãè¡ãããèããŠã¿ãŸãããã å®éãã¢ã¯ã·ã§ã³ã®ååã¯ååã«çž«ãä»ããããŠããŸã:)ãã€ãŸãã
å
éšã«æ¥ãããã±ãŒãžã
ãœãŒã¹ ã倿Žã
ãŸã :)ã ããããå¿çãã±ãããå
éšãã¹ãã«å°éããå¿
èŠããããšããäºå®ã«ã€ããŠè©±ããããšãèŠããŠããŸããïŒ ããã¯ã¢ã¯ã·ã§ã³ã®åŸåã§ãã
å€éšã«å°çãããã±ããã®
å Žå ã
å®å
ã倿ŽãããŸãã
ã©ã€ããããŒããã£ã¹ããèããŠãã ããã
1.å
éšãšããŠããŒã¯ãããã€ã³ã¿ãŒãã§ã€ã¹ã«çä¿¡ãããã©ãã£ãã¯ã¯ã倿ãããã®ãšäžèŽããå Žåãpossible_translatedãšããŠããŒã¯ãã
ãŸã ã æŸéã¯çŸåšãã®æç¹ã§è¡ãããŠãããšèããããŠããŸãããããã§ã¯ãããŸããã
2.次ã®ã¹ãããã§ã¯ããã©ãã£ãã¯ãã«ãŒãã£ã³ã°ãããŸãïŒPBRããã³éåžžïŒã ãããŠåæã«ããã©ãã£ãã¯ãå€éšãšããŠããŒã¯ãããã€ã³ã¿ãŒãã§ãŒã¹ã«åããããŠããå Žåã®ã¿-ãããŒããã£ã¹ãããããŸãã 倿ãåçã§ããå Žåãã«ãŒã¿ãŒã¯å€æããŒãã«ã§ãã®ååšã確èªããŸãã ååšããªãå Žåã¯äœæããæ¢ã«ååšããå Žåã¯ãéã¢ã¯ãã£ãã«ãŠã³ã¿ãŒããªã»ããããŸãã ãã±ãããå€éšãšããŠããŒã¯ãããŠããªãã€ã³ã¿ãŒãã§ã€ã¹ã§åºåã«å°éããå Žåã倿ã¯è¡ãããŸããã
ä»
éæŸé ã
1.ã©ã€ããããŒããã£ã¹ããšã¯å¯Ÿç
§çã«ãå€éšã€ã³ã¿ãŒãã§ã€ã¹ã«å°éãããã©ãã£ãã¯ã¯ãæåã«NATã«ãããããŸãã å
éšãœãŒã¹NATã®å Žåã倿ãååšããå ŽåïŒåçãŸãã¯éçïŒãå®å
ã倿ŽãããŸãã ãã®åŸããã©ãã£ãã¯ãã«ãŒãã£ã³ã°ãããå®å
ã«ãªãã€ã¬ã¯ããããŸãã
ãããã£ãŠãäœæ¥ã®ã¡ã«ããºã ãèæ
®ããŠãã€ã³ã¿ãŒãã§ã€ã¹ãå
éšãŸãã¯å€éšãšããŠããŒã¯ããå¿
èŠããããŸãã
çºèšãšçµæ ã
1.é倿ã®å Žåãã€ã³ã¿ãŒãã§ã€ã¹ã«å
éšã©ãã«ãä»ããå¿
èŠã¯ãããŸããã ãšã«ãããã©ã€ããããŒããã£ã¹ããååšããå ŽåãéãããŒããã£ã¹ãã¯ã«ãŒãã£ã³ã°ã®åã«æ©èœããŸãã ããããã©ã€ããããŒããã£ã¹ããäœæããã«ã¯ãã©ãã£ãã¯ãå
éšã€ã³ã¿ãŒãã§ã€ã¹ãééããå¿
èŠãããããšã説æããããããã®ãããªãããŒããã£ã¹ãããã€ååšããã®ã§ããããã ãããã
2.
ã«ãŒã¿èªäœã®
ãã©ãã£ãã¯ã¯ãå€éšãšããŠããŒã¯ãããã€ã³ã¿ãŒãã§ã€ã¹ã«å°éããNATã«ãŒã«ãæºããå Žåã«ãããŒããã£ã¹ããããŸã ã ãããŠã©ãã»ã©äŸ¿å©ã§ããšãŠãå±éºã§ãã äžæ¹ã§ã¯ãä»ãšåæ§ã«ã«ãŒã¿ãŒãã©ãã£ãã¯ããããŒããã£ã¹ãã§ããŸãã äžæ¹ãå€ãã®äººã¯ãããŒããã£ã¹ãããããã©ãã£ãã¯ã
allow anyãšããŠèšè¿°ããããšèããŠããŸãããããšãã°ãã«ãŒãã£ã³ã°ãããã³ã«ãã±ããããããŒããã£ã¹ããããé害ãçºçããŸãã
3.ã«ãŒãããã¯ã«ãŒã¿ãŒãªã©ã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ä»ã®ã€ã³ã¿ãŒãã§ã€ã¹ãšåæ§ã«æ±ãããå
éšãŸãã¯å€éšãšããŠããŒã¯ãããã©ãã£ãã¯ãã©ããããŠå©çãåŸãããšãã§ããŸã:)
ããã§ã¯ãäžè¬çãªæ§æãèŠãŠã¿ãŸããããæ¬¡ã«ãããã€ãã®ç¹å¥ãªã±ãŒã¹ãèŠãŠã¿ãŸãããã
å
éšãœãŒã¹NATèšå®
å
éšãœãŒã¹ãã€ãããã¯NAT
1.ãããŒããã£ã¹ããã
å
容ãæå®ããŸãã ãããè¡ãã«ã¯ããã©ãã£ãã¯ããªã¹ãããã¢ã¯ã»ã¹ãªã¹ããäœæããŸãã ããšãã°ããã®äŸã§ã¯1è¡ã§ååã§ãã
(config)# access-list 100 permit ip 10.0.0.0 0.255.255.255 any
åè ACLã«ã¯æåŠè¡ãå«ãŸããå ŽåããããŸãã äžè¬çãªèª€è§£ã«åããŠããã®ã©ã€ã³ãæºãããã©ãã£ãã¯ã¯ãããããããåã«ãããŒããã£ã¹ãããŸããã ãŸããACLã¯æšæºããã³æ¡åŒµãçªå·ä»ããååä»ããå¯èœã§ãã
2.éå§ã¢ãã¬ã¹ãšçµäºã¢ãã¬ã¹ãæå®ããŠãã¢ãã¬ã¹ã®ããŒã«ãäœæããŸãã ããšãã°ã次ã®ããã«ïŒ
(config)# ip nat pool NAME_OF_POOL 11.1.1.10 11.1.1.20 netmask 255.255.255.0
åè
1.ããŒã«å
ã®éå§ã¢ãã¬ã¹ãšçµäºã¢ãã¬ã¹ãäžèŽãããšããããŒããã£ã¹ãã¯1ã€ã®ã¢ãã¬ã¹ã«ãªããŸãã
2.ããããã¹ã¯ãªãã·ã§ã³ã¯å¿
é ã§ãããç§ã®æèŠã§ã¯åæ©ã§ãã ããŒã«å
ã®ã¢ãã¬ã¹ç¯å²ãããµããããã¢ãã¬ã¹ãŸãã¯ãã®ãã¹ã¯ã䜿çšããŠãããŒããã£ã¹ãããã¢ãã¬ã¹ãåãåãããšãã§ããŸãã
3.ã€ã³ã¿ãŒãã§ã€ã¹ãããŒã¯ããŸãã ç§ãã¡ã®å Žåãããã§ååã§ã
(config)# interface fa 0/0
(config-if)# ip nat inside
ãããŠ
(config)# interface fa 0/1
(config-if)# ip nat outside
4.å®éã®ãããŒããã£ã¹ããäœæããŸãã
ip nat inside source list 100 pool NAME_OF_POOL
åºæ¥äžãã:)ããšãã°ããã¹ã10.1.1.1ãããã¹ã11.1.1.2ã«å€æŽãããšã次ã®ç¿»èš³ãåŸãããŸãã
Router#sh ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 11.1.1.10:55209 10.0.1.1:55209 11.1.1.2:23 11.1.1.2:23
è峿·±ãããšã«ãéä¿¡å
ããŒããšå®å
ããŒãã¯ããŒãã«ã«æç€ºçã«èšè¿°ãããŠããŸããã倿ã¯å®å
šã«ã¢ãã¬ã¹ã«å¯ŸããŠäœæãããŸãã ãããŠã倿ããŒãã«ã§ã®åœŒå¥³ã®åç¶æéäžãå€éšã®ãã±ããã¯å€éšã¢ãã¬ã¹ïŒã°ããŒãã«å
éšïŒã«è¡ãããšãã§ããŸã
ããšãã°ãå€éšãããã¯ãŒã¯ã®äžéšã®ã¢ãã¬ã¹ããå
éšã°ããŒãã«ãžã®pingã¯æåããŸãïŒãããŒããã£ã¹ãã®éïŒïŒ
R4#ping 11.1.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 11.1.1.10, timeout is 2 seconds:
!!!!!
èšãæããã°ããããŒããã£ã¹ãã¯ç¹å®ã®ãã¹ãã«å¯ŸããŠäžåºŠéããããã®åŸãå€éšããã®ã¢ãã¬ã¹ã«å¯ŸããŠãã°ããæå¹ã«ãªããŸãã
ãªãŒããŒããŒãã®å
éšãœãŒã¹ãã€ãããã¯NAT
P. 1ã2ãããã³3-åã®ã»ã¯ã·ã§ã³ãšåæ§ã
4.å®éã®ãããŒããã£ã¹ããäœæããŸãã
ip nat inside source list 100 pool NAME_OF_POOL overload
ãªãŒããŒããŒããšããåèªã1ã€ã ã远å ãããŠããããšãããããŸãã ããããæŸéæ¹åŒã¯å€§ããå€ãããŸããã
åè¿°ã®ããã«ãPATã¯å°ãå€ãã£ãããå€å¯Ÿ1ã®ãããŒããã£ã¹ãã§ãã ãã ããããæ¥ç¶ã®ãã©ãã£ãã¯ãå¥ã®æ¥ç¶ã®ãã©ãã£ãã¯ãšåºå¥ã§ããããã«ããããã«ãã«ãŒã¿ãŒã¯IPã¢ãã¬ã¹ã ãã§ãªããTCP / UDPããŒãã倿ŽããŸãã
åè ããŒããæäœããã¹ããŒã ïŒãœãŒã¹ã倿Žããããšããå®å
ã倿ŽããããšãïŒã¯ãIPã¢ãã¬ã¹ãæäœããã¹ããŒã ãšåãã§ãã
ã€ãŸããå
éšããã¢ã¯ã»ã¹ãããšãéä¿¡å
IPãšéä¿¡å
ããŒãã倿Žããããã®ã¬ã³ãŒãã倿ããŒãã«ã«å
¥åãããŸãã éãããŒããã£ã¹ãã§ã¯ããã¹ãŠãéã«å€åããŸãã
äœãå€ãã£ãã®ãèŠãŠã¿ãŸãããïŒ
R3#sh ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 11.1.1.11:21545 10.0.1.1:21545 11.1.1.2:23 11.1.1.2:23
tcp 11.1.1.11:49000 10.0.2.1:49000 11.1.1.2:23 11.1.1.2:23
ç°ãªãå
éšã¢ãã¬ã¹ïŒ10.0.1.1ããã³10.0.2.1ïŒã1ã€ã®å€éšã¢ãã¬ã¹ïŒ11.1.1.11ïŒã«å€æãããããšãããããŸãã
åè
1.çŽæã©ããããœãŒã¹ããŒãã¯å€æŽãããŠããªãã£ãããã§ã:)ã å®éãã«ãŒã¿ãŒã¯å©çšå¯èœãªãã¹ãŠã®ææ®µã§éä¿¡å
ããŒããä¿æããããšããŠããŸãã ç¹ã«ãå
éšã°ããŒãã«ã¢ãã¬ã¹ããŒãããã§ã«äœ¿çšãããŠããå ŽåãããŒã«å
ã®æ¬¡ã®ã¢ãã¬ã¹ãååŸããããŒãã®ããžãŒç¶æ
ã確èªããŸãã ãããŠã空ãããŒãã®ããã¢ãã¬ã¹ãèŠã€ãããªãå Žåã¯ã次ã®ç©ºãããŒãã䜿çšãããŸãã
2.ãã®ãããªå€æã®åäœã¯ãå€éšããå
éšã®ã°ããŒãã«ã¢ãã¬ã¹ãžã®ã¢ã¯ã»ã¹ãäžå¯èœã§ãããšããç¹ã§ãéåžžã®ãã€ãããã¯NATã®åäœãšã¯ç°ãªããŸãã ããã¯ãPATã䜿çšããå Žåã®ã»ãã¥ãªãã£ã®åäžã«ã€ããŠè©±ãããšãã®æå³ã§ãã äºå®äžãã¹ãŠã®æ¥ç¶ã¯ãããã¯ãŒã¯å
ããéå§ãããå€éšããã¯ããããžã®åçã®ã¿ãå±ããŸãã
3.ãããã€ããŒããã¢ãã¬ã¹ã®ãããã¯å
šäœã§ã¯ãªããã«ãŒã¿ãŒã®å€éšã€ã³ã¿ãŒãã§ã€ã¹ã«ããã«å²ãåœãŠããã1ã€ã®äžå¹žãªã¢ãã¬ã¹ãåãåã£ãå Žåã1ã€ã®ã¢ãã¬ã¹ã«ããŒã«ã®ããåºã眮ãããšã¯ã§ããŸããããæ¬¡ã®ããã«ããã«æžã蟌ã¿ãŸãïŒ
(config)# ip nat inside source list 100 interface fa0/1 overload
å
éšãœãŒã¹ã¹ã¿ãã£ãã¯NATããã³PAT
éçãããŒããã£ã¹ãã«ã€ããŠã¯å€ãã®ããšãèšãããŠããŸãããæåŸã«ãããã«ã€ããŠèª¬æããŸãããã
ãªããããå¿
èŠã§ããïŒ
ãã€ãããã¯NATã®å ŽåãPATã®å Žåã«å€æãäœæãããªãã£ãå Žåãå€éšããã®ã¢ã¯ã»ã¹ã¯äžå¯èœã§ããããšã説æããŸããã ãã€ãããã¯NATã®å Žåã§ã倿ãäœæããããšãå
éšã°ããŒãã«ã¢ãã¬ã¹ã倿Žãããå¯èœæ§ããããŸãã ãããŠãå€éšã¢ãã¬ã¹ã§å
éšãã¹ãã«é£çµ¡ããããšã¯äžå¯èœã§ãã
ããã«ãããããããäŒæ¥ãããã¯ãŒã¯å
ã«ãµãŒããŒããããéçå€éšã¢ãã¬ã¹ãä»ããŠå€éšããã¢ã¯ã»ã¹ããããšãéèŠãªå ŽåããããŸãã ãã®å Žåãã°ããŒãã«ã¢ãã¬ã¹ãå²ãåœãŠãããšã«ãããã€ã³ã¿ãŒãããã«çŽæ¥èšå®ã§ããŸãã ããããå€ãã®å Žåãããã¯ãããšãã°ã»ãã¥ãªãã£äžã®çç±ãããããŸã䟿å©ã§ã¯ãããŸããã ãããŠããã®ãããªå ŽåãéçNATãå©ãã«ãªããŸãã
åæ¹åã®ç¶ç¶çãªãããŒããã£ã¹ããäœæããŸãã ãããã£ãŠããã¹ãã¯åžžã«1ã€ã®å€éšã¢ãã¬ã¹ã§å©çšã§ãããã®ãããŒããã£ã¹ãã¯ã¿ã€ã ã¢ãŠãã«ãã£ãŠãããŒããã£ã¹ãããŒãã«ããé£ã³åºãããšã¯ãããŸããã
å®éã®èšå®ã
ããã«ãããŒããã£ã¹ããäœæããŸãã
(config)# ip nat inside source static 10.0.1.1 11.1.1.21
ã€ã³ã¿ãŒãã§ã€ã¹ãšåºæ¥äžãããããŒã¯ããŸãïŒ
R3#sh ip nat translations
Pro Inside global Inside local Outside local Outside global
icmp 11.1.1.21:14 10.0.1.1:14 11.1.1.2:14 11.1.1.2:14
--- 11.1.1.21 10.0.1.1 --- ---
ã芧ã®ããã«ã2ã€ã®ãšã³ããªã衚瀺ãããŸããã1ã€ã¯æ°žç¶çã§ããã1ã€ã¯ïŒçŽç²ã«æ
å ±éã®å€ãïŒäžæçãªãã®ã§ãå
éšããã®ãã©ãã£ãã¯ã«ãã£ãŠçºçããŸããã
åè ãã®ãããªæçãªãšã³ããªã®è¡šç€ºã¯ãã³ãã³ãã«ãã£ãŠç¡å¹ã«ããããšãã§ããŸã
(config)# no ip nat create flow-entries
ã©ãã ã¢ãã¬ã¹å
šäœã§ã¯ãªãã1ã€ã®ããŒãïŒããšãã°ãwwwãµãŒããŒã®å Žåã¯80çªç®ïŒã®ã¿ãå
¬éããå¿
èŠãããããšããããããŸãã åé¡ãããŸãããäžéšã®ããŒãã«å¯ŸããŠéçPAT倿ãäœæã§ããŸãã
(config)# ip nat inside source static tcp 10.0.1.1 80 11.1.1.21 80
(config)# ip nat inside source static udp 10.0.1.1 5060 11.1.1.21 7877
åãå€éšã¢ãã¬ã¹ã®ããŒããç°ãªãå
éšããŒãã«è»¢éã§ããããšãããããããŒã倿ã管çããããšãã§ããŸãã
çµè«ãšããŠãNATã®ããŸããŸãªã¿ã€ã ã¢ãŠããã³ãã³ãã§å€æŽã§ããããšã远å ããŸãã
Router(config)#ip nat translation ?
arp-ping-timeout Specify timeout for WLAN-NAT ARP-Ping
dns-timeout Specify timeout for NAT DNS flows
finrst-timeout Specify timeout for NAT TCP flows after a FIN or RST
icmp-timeout Specify timeout for NAT ICMP flows
max-entries Specify maximum number of NAT entries
port-timeout Specify timeout for NAT TCP/UDP port specific flows
pptp-timeout Specify timeout for NAT PPTP flows
routemap-entry-timeout Specify timeout for routemap created half entry
syn-timeout Specify timeout for NAT TCP flows after a SYN and no
further data
tcp-timeout Specify timeout for NAT TCP flows
timeout Specify timeout for dynamic NAT translations
udp-timeout Specify timeout for NAT UDP flows
倧éã®èšäºã倿ããããã€ãã®éšåã«åå²ããå¿
èŠããããŸãã ãã¡ãããå
éšãœãŒã¹NATã¯äœåºŠãè°è«ãããèšè¿°ãããŠããŸããããåå¿è
ã§ããã®èšäºã§åœ¹ã«ç«ã€ãã®ãèŠã€ããããªãããšãé¡ã£ãŠããŸãã æåãªãã®ã§ã¯ãããŸãããããã€ãã®æ ç¹ããå§ããªããã°ãªããŸããã§ããã
次ã®èšäºã§ã¯ãåœç¶ã®ããšãªããå¿çãšãµããŒããèŠã€ãããªãéããå
éšå®å
NATã«ã€ããŠèª¬æããŸãã
ãããã
ããã¯ããšãã€ãªã€
PSèšäºãæ¹åããäžæ£ç¢º/ãšã©ãŒãä¿®æ£ããããã®ææ¡ãåãä»ããŠããŸãã
PPSãªã³ã¯ïŒ
1.
ãã©ãŒã©ã ãµã€ãanticisco.ru
2.
Cisco NATã®åäœé åº