▣ PAT + DNAT
① PAT
Inside (Src.A: 100.100.100.X/24, Dst.A: X.X.X.X: *) -> Outside (Src.A: fastethernet0/0, Dst.A: X.X.X.X: *)
interface FastEthernet0/0 ip virtual-reassembly
|
② DNAT (port forwarding)
Outside (Src.A: X.X.X.X: *, Dst.A: fastethernet0/0: 2323) -> Inside (Src.A: X.X.X.X: *, Dst.A: 100.100.100.2 : 23)
i think of that cisco doesn't support DNAT like as "iptables -t nat -A PREROUTING -s 192.168.56.110 -p tcp --dport 2323 -j DNAT --to 100.100.100.2:23"
just trick config with static SNAT
ip nat inside source static tcp 100.100.100.2 23
interface FastEthernet0/0 2323 |
config on SDM, ASDM, conveniently
*verify:
*Outputs
cf
1) static SNAT
ip nat inside source static tcp 100.100.100.2 23 192.168.56.111 2323
|
2) Cisco IOS NAT configurable options
ip nat {inside | outside} {source | destination} {list | route-map | static} {interface | pool} [overload | vrf]
R1(config)#ip nat inside ?
R1(config)#ip nat outside ? |
■ Ref:
-How NAT Works: http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080094831.shtml
-Network Address Translation Catalyst Switch Support Matrix: http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a008011c629.shtml
'Network > Routing' 카테고리의 다른 글
[Basic] ACLs (0) | 2010.03.19 |
---|---|
default routing on DHCP, PPPoE, dial Services (0) | 2010.03.16 |