目的:通过双向NAT来更深的理解NAT在思科IOS中的数据包处理顺序
前提:在真实环境中不会出现
将R1和R3模拟成PC,在不加网关的情况下,使两者能够正常通信。
定义R2的f0/0为ip nat inside;f1/0为ip nat outside。
我先贴出思科IOS的数据包处理的顺序
NAT Overview |
|
In this table, when NAT performs the global to local, or local to global, translation is different in each flow. |
|
Inside-to-Outside |
Outside-to-Inside |
If IPSec then check input access list |
If IPSec then check input access list |
decryption - for CET (Cisco Encryption Technology) or IPSec |
decryption - for CET or IPSec |