1.要求

2.拓扑

3.分析
1.因为要访问外网,所以需要在边缘路由器r1上设置一条缺省路由
2.需要在边界路由设置nat
4.配置
路由器端口的ip配置
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.1.10 24
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]ip add 12.1.1.1 30
[r2]int g0/0/1
[r2-GigabitEthernet0/0/1]ip add 1.1.1.1 24
[r2]int g0/0/0
[r2-GigabitEthernet0/0/0]ip add 12.1.1.2 30
server的配置



dns的设置(ip为公用ip而非私网ip)

R1公用ip端口的net设置:
[r1-GigabitEthernet0/0/1]acl 2001
[r1-acl-basic-2001]rule permit source 192.168.1.0 0.0.0.255
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]nat outbound 2001
缺省路由:
[r1]ip route-static 0.0.0.0 0.0.0.0 12.1.1.2
端口映射
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 80 inside 192.168.1.2
Warning:The port 80 is well-known port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
[r1-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 888 inside 192.168.1.3 80
Warning:The port 888 is well-known port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
5.验证
PC1去ping PC2

client通过域名访问网页1.2

client通过ip访问

本文档详细介绍了如何配置路由器以允许内部网络访问外网,包括在边缘路由器R1上设置缺省路由、NAT转换,并配置公共IP端口的网络设置。此外,还涉及了DNS的公共IP设置,以及服务器端口映射,确保内部服务器可以通过公网IP被访问。同时,提供了验证配置是否正确的步骤,如PC到PC的ping测试和客户端通过域名、IP访问服务器的测试。
3738

被折叠的 条评论
为什么被折叠?



