防火墙NAT是最常用的配置,也是软考的配置考点
1)内部私有IP上网
[SRG]nat address-group 1 202.1.1.11 202.1.1.13公网地址池
[SRG]nat-policy interzone trust untrust outbound
[SRG-nat-policy-interzone-trust-untrust-outbound]policy
[SRG-nat-policy-interzone-trust-untrust-outbound-0]actionsource-nat 基于源IP做NAT
[SRG-nat-policy-interzone-trust-untrust-outbound-0]address-group 1
PAT
[SRG]nat-policy interzone trust untrust outbound
[SRG-nat-policy-interzone-trust-untrust-outbound]policy 0
[SRG-nat-policy-interzone-trust-untrust-outbound-0]action source-nat
[SRG-nat-policy-interzone-trust-untrust-outbound-0]easy-ip g0/0/0
[SRG]firewall packet-filter default permit interzone trust untrust direction outbound
测试
2)DMZ区服务器对外公开
[SRG]nat server 1 protocol icmp global 202.1.1.100 inside 172.16.1.10
在外网测试到202.1.1.100 是通的,但真实的数据已到R3,因为202.1.1.100是一个虚拟的IP