本文共 8213 字,大约阅读时间需要 27 分钟。
实
验任务 实验需求:1.配置路由器和ASA的接口,实现网络互通2.配置路由R1可以Telnet到RR,RR不可以Telnet到R1,3.使用命令show xlate 查看NAT转换表实验拓扑:
思
路及实验步骤 配置思路:1.配置ASA防火墙对应端口的IP并设置端口名与优先级no shutdown
ip address 172.16.1.254 255.255.255.0exitobject network inside (指定需要进行地址转换的网段)subnet 10.1.1.0 255.255.255.0exitobject network in-out (定义全局地址池)rang 172.16.1.100 172.16.1.200exitobject network inside (建立转换对应关系)nat (inside,outside) dynamic in-outqR1:
enableconfiguration terminalhostname R1interface fastEthernet 0/0no shutdownip address 10.1.1.1 255.255.255.0exitno ip routing (关闭路由功能)ip default-gateway 10.1.1.254(设置网关)endping 10.1.1.254 (验证到网关是否互通)设置远程enableconfiguration terminalenable password 123line vty 0 password 123endRR:
enableconfiguration terminal hostname RRno ip routing interface fastEthernet 1/0no shutdownip address 172.16.1.1 255.255.255.0endping 172.16.1.254 (验证到网关是否互通)设置远程
enableconfiguration terminalenable password 123line vty 0 password 123end实
验任务 实验需求:1.配置路由器和ASA的接口,实现网络互通2.配置路由R1可以Telnet到RR,RR不可以Telnet到R1,3.使用命令show xlate 查看NAT转换表实验拓扑:
思
路及实验步骤 配置思路:1.配置ASA防火墙对应端口的IP并设置端口名与优先级no shutdown
ip address 172.16.1.254 255.255.255.0exitobject network inside (指定需要进行地址转换的网段)subnet 10.1.1.0 255.255.255.0exitobject network in-out (定义全局地址池)rang 172.16.1.100 172.16.1.200exitobject network inside (建立转换对应关系)nat (inside,outside) dynamic in-outqR1:
enableconfiguration terminalhostname R1interface fastEthernet 0/0no shutdownip address 10.1.1.1 255.255.255.0exitno ip routing (关闭路由功能)ip default-gateway 10.1.1.254(设置网关)endping 10.1.1.254 (验证到网关是否互通)设置远程enableconfiguration terminalenable password 123line vty 0 password 123endRR:
enableconfiguration terminal hostname RRno ip routing interface fastEthernet 1/0no shutdownip address 172.16.1.1 255.255.255.0endping 172.16.1.254 (验证到网关是否互通)设置远程
enableconfiguration terminalenable password 123line vty 0 password 123end实
验任务 实验需求:1.配置路由器和ASA的接口,实现网络互通2.配置路由R1可以Telnet到RR,RR不可以Telnet到R1,3.使用命令show xlate 查看NAT转换表实验拓扑:
思
路及实验步骤 配置思路:1.配置ASA防火墙对应端口的IP并设置端口名与优先级no shutdown
ip address 172.16.1.254 255.255.255.0exitobject network inside (指定需要进行地址转换的网段)subnet 10.1.1.0 255.255.255.0exitobject network in-out (定义全局地址池)rang 172.16.1.100 172.16.1.200exitobject network inside (建立转换对应关系)nat (inside,outside) dynamic in-outqR1:
enableconfiguration terminalhostname R1interface fastEthernet 0/0no shutdownip address 10.1.1.1 255.255.255.0exitno ip routing (关闭路由功能)ip default-gateway 10.1.1.254(设置网关)endping 10.1.1.254 (验证到网关是否互通)设置远程enableconfiguration terminalenable password 123line vty 0 password 123endRR:
enableconfiguration terminal hostname RRno ip routing interface fastEthernet 1/0no shutdownip address 172.16.1.1 255.255.255.0endping 172.16.1.254 (验证到网关是否互通)设置远程
enableconfiguration terminalenable password 123line vty 0 password 123end实
验任务 实验需求:1.配置路由器和ASA的接口,实现网络互通2.配置路由R1可以Telnet到RR,RR不可以Telnet到R1,3.使用命令show xlate 查看NAT转换表实验拓扑:
思
路及实验步骤 配置思路:1.配置ASA防火墙对应端口的IP并设置端口名与优先级no shutdown
ip address 172.16.1.254 255.255.255.0exitobject network inside (指定需要进行地址转换的网段)subnet 10.1.1.0 255.255.255.0exitobject network in-out (定义全局地址池)rang 172.16.1.100 172.16.1.200exitobject network inside (建立转换对应关系)nat (inside,outside) dynamic in-outqR1:
enableconfiguration terminalhostname R1interface fastEthernet 0/0no shutdownip address 10.1.1.1 255.255.255.0exitno ip routing (关闭路由功能)ip default-gateway 10.1.1.254(设置网关)endping 10.1.1.254 (验证到网关是否互通)设置远程enableconfiguration terminalenable password 123line vty 0 password 123endRR:
enableconfiguration terminal hostname RRno ip routing interface fastEthernet 1/0no shutdownip address 172.16.1.1 255.255.255.0endping 172.16.1.254 (验证到网关是否互通)设置远程
enableconfiguration terminalenable password 123line vty 0 password 123end实
验任务 实验需求:1.配置路由器和ASA的接口,实现网络互通2.配置路由R1可以Telnet到RR,RR不可以Telnet到R1,3.使用命令show xlate 查看NAT转换表实验拓扑:
思
路及实验步骤 配置思路:1.配置ASA防火墙对应端口的IP并设置端口名与优先级no shutdown
ip address 172.16.1.254 255.255.255.0exitobject network inside (指定需要进行地址转换的网段)subnet 10.1.1.0 255.255.255.0exitobject network in-out (定义全局地址池)rang 172.16.1.100 172.16.1.200exitobject network inside (建立转换对应关系)nat (inside,outside) dynamic in-outqR1:
enableconfiguration terminalhostname R1interface fastEthernet 0/0no shutdownip address 10.1.1.1 255.255.255.0exitno ip routing (关闭路由功能)ip default-gateway 10.1.1.254(设置网关)endping 10.1.1.254 (验证到网关是否互通)设置远程enableconfiguration terminalenable password 123line vty 0 password 123endRR:
enableconfiguration terminal hostname RRno ip routing interface fastEthernet 1/0no shutdownip address 172.16.1.1 255.255.255.0endping 172.16.1.254 (验证到网关是否互通)设置远程
enableconfiguration terminalenable password 123line vty 0 password 123end实
验任务 实验需求:1.配置路由器和ASA的接口,实现网络互通2.配置路由R1可以Telnet到RR,RR不可以Telnet到R1,3.使用命令show xlate 查看NAT转换表实验拓扑:
思
路及实验步骤 配置思路:1.配置ASA防火墙对应端口的IP并设置端口名与优先级no shutdown
ip address 172.16.1.254 255.255.255.0exitobject network inside (指定需要进行地址转换的网段)subnet 10.1.1.0 255.255.255.0exitobject network in-out (定义全局地址池)rang 172.16.1.100 172.16.1.200exitobject network inside (建立转换对应关系)nat (inside,outside) dynamic in-outqR1:
enableconfiguration terminalhostname R1interface fastEthernet 0/0no shutdownip address 10.1.1.1 255.255.255.0exitno ip routing (关闭路由功能)ip default-gateway 10.1.1.254(设置网关)endping 10.1.1.254 (验证到网关是否互通)设置远程enableconfiguration terminalenable password 123line vty 0 password 123endRR:
enableconfiguration terminal hostname RRno ip routing interface fastEthernet 1/0no shutdownip address 172.16.1.1 255.255.255.0endping 172.16.1.254 (验证到网关是否互通)设置远程
enableconfiguration terminalenable password 123line vty 0 password 123end结
果验证 在R1上远程RR在RR上远程R1
在ASA输入show xlate 查看NAT转化表
转载于:https://blog.51cto.com/13505118/2056847