实验目的:
将公网IP的某端口映射为内网的某主机的某端口,实验以23端口为例,将R1的外接口公网IP(202.103.24.1)的23端口,映射为本地PC1(192.168.1.2)的23端口
路由器R1的show running-config信息:
interface FastEthernet0/0
ip address 192.168.1.1 255.255.255.0
ip nat inside
speed auto
full-duplex
!
interface FastEthernet0/1
ip address 202.103.24.1 255.255.255.240
ip nat outside
duplex auto
speed auto
!
ip nat inside source static tcp 192.168.1.2 23 interface FastEthernet0/1 23
ip http server
no ip http secure-server
ip classless
ip route 0.0.0.0 0.0.0.0 202.103.24.2
2009-12-12 22:29 华为28-11路由器配置实例
1、进入系统(进入配置模式)
system
System View: return to User View with Ctrl+Z.
2、为路由器取名与设置密码
[Quidway]local-user huawei
New local user added.
[Quidway-luser-huawei]password cipher huawei #/为配置密码为huawei
3、设置服务类型、安全、访问列表
[Quidway-luser-huawei]service-type telnet #/可以执行远程登入
[Quidway-luser-huawei]level 3 #/设置安全级别
[Quidway-luser-huawei]acl number 2001 match-order auto
[Quidway-acl-basic-2001]rule 0 permit source 192.168.1.0 0.0.0.255
[Quidway-acl-basic-2001]rule 1 deny
4、进入接口、并为接口添加IP地址
[Quidway-acl-basic-2001]int ethernet 0/0
[Quidway-Ethernet0/0]ip add XX.XX.158.58 255.255.255.252 /端口配置的IP地址为一个IP段
[Quidway-Ethernet0/0]nat outbound 2001
[Quidway-Ethernet0/0]int e 0/1
[Quidway-Ethernet0/1]ip add 192.168.1.1 255.255.255.0 /端口配置的IP地址为一个IP段
[Quidway-Ethernet0/1]ip route-static 0.0.0.0 0.0.0.0 XX.XX.158.57 /为内网的端口配置静态路由
5、配置DHCP服务器(用来为内网的PC机分配IP地址)
[Quidway]dhcp server forbidden-ip 192.168.1.1
[Quidway]dhcp server forbidden-ip 192.168.1.2 192.168.1.100
6、为DHCP服务器的地址池说明网络地址、子网隐码、网关、DNS
[Quidway]dhcp server ip-pool 1
[Quidway-dhcp-pool-1]network 192.168.1.0 mask 255.255.255.0
[Quidway-dhcp-po
ol-1]gateway-list 192.168.1.1
[Quidway-dhcp-pool-1]dns-list 211.138.151.161 211.136.17.107