方法二:动态NAT KC-R1(config)# ip nat pool kachy 173.16.1.58 173.16.1.126 netmask 255.255.255.0 #创建地址池# ~9 i0 h, X; b! e: {
KC-R1(config)#access-list 1 permit 10.1.1.0 0.0.0.255 #创建ACL) F; G3 J {# A1 P' M' B" j% k4 h
KC-R1(config)#ip nat inside source list 1 pool kachy #二者关联* g( b; H! O" M; k/ g
KC-R1(config)#exit2 ]8 r6 h D6 v4 G) h
Ping测试6 Y2 M- G- P& d9 B* R8 F
PC-1#ping 202.101.1.149 #测试证明能通
" p* h7 ]# L" P. Q6 |7 JType escape sequence to abort.& F0 Y% U' n3 b( s! K
Sending 5, 100-byte ICMP Echos to 202.101.1.149, timeout is 2 seconds:
| J: R& A. R: `& `0 p!!!!!
- X( T; ?4 R8 {, |% u. Y2 `# h" B0 nSuccess rate is 100 percent (5/5), round-trip min/avg/max = 96/125/148 ms
# b) G2 S- A4 M2 x6 l2 P9 OPC-1#telnet 202.101.1.149 #测试证明能远程连接" s9 i% I _0 T
Trying 202.101.1.149 … Open4 Z" V$ z; w, {: w$ W* j
Password required, but none set! F. E2 o! W0 e
[Connection to 202.101.1.149 closed by foreign host]
! ~0 V' X/ Y5 l( ]1 D, [此时PC-2也可以ping通,telnet上。
/ Z9 b# a/ p- ^( ~ _. Y查看当前KC-R1的NAT表。
6 w. E; s$ V: W! g2 b( E% [$ p) BKC-R1#sh ip nat translations #查看NAT表2 M2 i# B# \0 M: w+ v5 ^3 k
Pro Inside global Inside local Outside local Outside global
4 [) E0 |3 e* i- P/ W6 \! V$ q- R— 173.16.1.58 10.1.1.1 — —4 {& L5 R r6 s9 B; o# w& D
— 173.16.1.59 10.1.1.2 — —
6 H# Z3 n: f- O; NKC-R1# |