方法二:动态NAT KC-R1(config)# ip nat pool kachy 173.16.1.58 173.16.1.126 netmask 255.255.255.0 #创建地址池
, {/ w8 |2 [" P, jKC-R1(config)#access-list 1 permit 10.1.1.0 0.0.0.255 #创建ACL
9 }6 a; p: C: j& \. } r3 o5 pKC-R1(config)#ip nat inside source list 1 pool kachy #二者关联! Y1 H( N2 `5 m1 c p* E
KC-R1(config)#exit5 _$ L1 |; m5 i; v$ N
Ping测试" g# I$ u7 s6 d* N2 y; }
PC-1#ping 202.101.1.149 #测试证明能通
6 x4 d {0 C$ X9 R% }1 O" ?, `) v% D( TType escape sequence to abort.
( ~6 b. S! u; x8 QSending 5, 100-byte ICMP Echos to 202.101.1.149, timeout is 2 seconds:
# V* l: f2 k( n S1 i- _!!!!!$ P9 z, Z, ~& `' s' |& v- E4 y
Success rate is 100 percent (5/5), round-trip min/avg/max = 96/125/148 ms
" {9 U Y' ]% K2 YPC-1#telnet 202.101.1.149 #测试证明能远程连接& d: D1 g! z a' `
Trying 202.101.1.149 … Open
9 B& V1 _& \4 @3 |+ D/ ?Password required, but none set( u9 E- [) Z2 ]" }0 p K8 v2 W
[Connection to 202.101.1.149 closed by foreign host]
5 ~# e. q) n- S$ x此时PC-2也可以ping通,telnet上。3 `3 n- w5 F9 R' n9 {4 ^; T c3 d
查看当前KC-R1的NAT表。/ R# j+ f+ r$ _; v, g( L+ x
KC-R1#sh ip nat translations #查看NAT表
! F+ u1 N: C5 K! q' HPro Inside global Inside local Outside local Outside global
' g* f0 D( [- s7 @; |2 H# ?— 173.16.1.58 10.1.1.1 — —- h- d0 v& ?0 ^9 F
— 173.16.1.59 10.1.1.2 — —2 b( `8 q6 d0 b {
KC-R1# |