路由器NAT inbound入方向动态地址转换经验案例 |
您所在的位置:网站首页 › 在msr路由器上使用什么命令配置NAT › 路由器NAT inbound入方向动态地址转换经验案例 |
根据限制描述,我们有如下两种方法在NAT inbound设备上添加路由: 方法一:手动添加路由,目的地址为转换地址组中的地址,出接口为本配置所在接口,下一跳地址为报文的源地址 [RTB]ip route-static 192.168.30.1 32 GigabitEthernet 0/1 192.168.10.2 方法二:在nat inbound后面指定add-route参数,有报文命中该配置时,设备会自动添加对应的路由表项 [RTB-GigabitEthernet0/1]nat inbound 3000 address-group 1 no-pat add-route 指定add-route参数,RTA发起ping RTC后,display ip routing-table能够看到自动添加的表项:
[RTB]display ip routing-table Destinations : 17 Routes : 17 Destination/Mask Proto Pre Cost NextHop Interface 0.0.0.0/32 Direct 0 0 127.0.0.1 InLoop0 127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0 127.0.0.0/32 Direct 0 0 127.0.0.1 InLoop0 127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0 127.255.255.255/32 Direct 0 0 127.0.0.1 InLoop0 192.168.10.0/24 Direct 0 0 192.168.10.1 GE0/1 192.168.10.0/32 Direct 0 0 192.168.10.1 GE0/1 192.168.10.1/32 Direct 0 0 127.0.0.1 InLoop0 192.168.10.255/32 Direct 0 0 192.168.10.1 GE0/1 192.168.20.0/24 Direct 0 0 192.168.20.1 GE0/2 192.168.20.0/32 Direct 0 0 192.168.20.1 GE0/2 192.168.20.1/32 Direct 0 0 127.0.0.1 InLoop0 192.168.20.255/32 Direct 0 0 192.168.20.1 GE0/2 192.168.30.1/32 Static 1 0 192.168.10.2 GE0/1 224.0.0.0/4 Direct 0 0 0.0.0.0 NULL0 224.0.0.0/24 Direct 0 0 0.0.0.0 NULL0 255.255.255.255/32 Direct 0 0 127.0.0.1 InLoop0 但是在ping包时发现,自动添加表项的速度较慢,没有路由表项或路由表项老化后首次发起ping报文时,ping包时因为没有迅速下发表项而导致了丢包,这也是为什么推荐手工添加路由
[RTA]ping 192.168.20.2 //没有路由表项时,自动添加路由表项会产生少量丢包 Ping 192.168.20.2 (192.168.20.2): 56 data bytes, press CTRL_C to break Request time out 56 bytes from 192.168.20.2: icmp_seq=1 ttl=254 time=1.638 ms 56 bytes from 192.168.20.2: icmp_seq=2 ttl=254 time=1.588 ms 56 bytes from 192.168.20.2: icmp_seq=3 ttl=254 time=1.201 ms 56 bytes from 192.168.20.2: icmp_seq=4 ttl=254 time=1.749 ms 添加路由后在RTB上再次查看NAT会话,地址转换和来回报文计数都正常:
[RTB]display nat session verbose Slot 0: Initiator: Source IP/port: 192.168.10.2/233 Destination IP/port: 192.168.20.2/2048 DS-Lite tunnel peer: - VPN instance/VLAN ID/Inline ID: -/-/- Protocol: ICMP(1) Inbound interface: GigabitEthernet0/1 Responder: Source IP/port: 192.168.20.2/233 Destination IP/port: 192.168.30.1/0 DS-Lite tunnel peer: - VPN instance/VLAN ID/Inline ID: -/-/- Protocol: ICMP(1) Inbound interface: GigabitEthernet0/2 State: ICMP_REPLY Application: OTHER Role: - Failover group ID: - Start time: 2019-11-28 21:25:30 TTL: 23s Initiator->Responder: 5 packets 420 bytes Responder->Initiator: 5 packets 420 bytes
在RTC入接口上抓包,可以看到源地址成功转换为了192.168.30.1: |
今日新闻 |
点击排行 |
|
推荐新闻 |
图片新闻 |
|
专题文章 |
CopyRight 2018-2019 实验室设备网 版权所有 win10的实时保护怎么永久关闭 |