Mục tiêu thực hành:
- Cấu hình NAT Overload (Dual WAN) trên Cisco Router.
- Kiểm tra cấu hình NAT trong file cấu hình running-config trên Cisco Router.
- Kiểm tra bảng NAT Translation trên Cisco Router.
- Kiểm tra kết nối Internet trên các VPC.
Truy cập vào "Lab 3-4 - Cau hinh NAT Overload Dual WAN tren Cisco Router v1" tại Public Unetlab Server 24/7 để thực hành.
Cấu hình NAT Overload (Dual WAN) trên Cisco Router.
Router>enableRouter#configure terminalRouter(config)#interface e0/1Router(config-if)#ip nat outside*Jan 23 03:50:24.192: %LINEPROTO-5-UPDOWN: Line protocol on Interface NVI0, changed state to upRouter(config-if)#exitRouter(config)#interface e0/2Router(config-if)#ip nat outsideRouter(config-if)#exitRouter(config)#interface e0/0Router(config-if)#ip nat insideRouter(config-if)#exitRouter(config)#ip access-list extended NatTrafficWan1Router(config-ext-nacl)#permit ip 172.16.0.0 0.0.0.255 anyRouter(config-ext-nacl)#exitRouter(config)#ip access-list extended NatTrafficWan2Router(config-ext-nacl)#permit ip 172.16.0.0 0.0.0.255 anyRouter(config-ext-nacl)#exitRouter(config)#ip nat inside source list NatTrafficWan1 interface e0/1 overloadRouter(config)#ip nat inside source list NatTrafficWan2 interface e0/2 overloadRouter(config)#end
Kiểm tra cấu hình NAT trong file cấu hình running-config trên Cisco Router.
Router#show running-config interface e0/1Building configuration...Current configuration : 88 bytes!interface Ethernet0/1ip address dhcpip nat outsideip virtual-reassembly inendRouter#
Router#show running-config interface e0/2Building configuration...Current configuration : 88 bytes!interface Ethernet0/2ip address dhcpip nat outsideip virtual-reassembly inendRouter#
Router#show running-config interface e0/0Building configuration...Current configuration : 109 bytes!interface Ethernet0/0ip address 172.16.0.254 255.255.255.0ip nat insideip virtual-reassembly inendRouter#
Router#show running-config | section access-listip access-list extended NatTrafficWan1permit ip 172.16.0.0 0.0.0.255 anyip access-list extended NatTrafficWan2permit ip 172.16.0.0 0.0.0.255 anyRouter#
Router#show running-config | include ip natip nat insideip nat outsideip nat outsideip nat inside source list NatTrafficWan1 interface Ethernet0/1 overloadip nat inside source list NatTrafficeWan2 interface Ethernet0/2 overloadRouter#
Kiểm tra bảng NAT Translation trên Cisco Router.
Router#ping 8.8.4.4 source e0/0Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 8.8.4.4, timeout is 2 seconds:Packet sent with a source address of 172.16.0.254!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 29/30/34 msRouter#
Router#show ip nat translationsPro Inside global Inside local Outside local Outside globalicmp 192.168.100.8:1 172.16.0.254:1 8.8.4.4:1 8.8.4.4:1Router#
Kiểm tra kết nối Internet trên các VPC.
VPCS> ip 172.16.0.1/24 172.16.0.254Checking for duplicate address...PC1 : 172.16.0.1 255.255.255.0 gateway 172.16.0.254VPCS> ip dns 8.8.4.4
VPCS> ping google.comgoogle.com resolved to 64.233.189.10084 bytes from 64.233.189.100 icmp_seq=1 ttl=103 time=46.312 ms84 bytes from 64.233.189.100 icmp_seq=2 ttl=103 time=46.584 ms84 bytes from 64.233.189.100 icmp_seq=3 ttl=103 time=41.387 ms84 bytes from 64.233.189.100 icmp_seq=4 ttl=103 time=38.837 ms84 bytes from 64.233.189.100 icmp_seq=5 ttl=103 time=48.543 msVPCS>
Tham khảo các videos lý thuyết Hướng dẫn thực hành CCNA R&S để biết thêm thông tin chi tiết.
0 comments