Download presentation
Presentation is loading. Please wait.
Published byAileen Jordan Modified over 9 years ago
1
NAT & PAT Network Address Translation Port Address Translation
2
Why use NAT? Ability to use private addresses internally and still access the Internet RFC1918 addresses are not globally unique Ability to connect overlapping IP address space Not a security cure
3
NAT Characteristics Converts internal private address to configured public address that is routable Performed statically or dynamically Creates state table on connection Delete state table entry on disconnect With use of ACLs to prevent routing, can add to security profile, control traffic
4
NAT Applications Hardware and software firewalls Routers Proxy servers RAS server that is a simple router/firewall
7
NAT Configuration NAT(config)#access-list 1 permit 192.168.1.0 0.0.0.255 NAT(config)#ip nat pool public-1 200.200.100.129 200.200.100.250 netmask 255.255.255.128 NAT(config)#ip nat inside source list 1 pool public-1 NAT(config)#interface fa 0/0 NAT(config-if)#ip nat inside NAT(config-if)#interface s 0/0 NAT(config-if)#ip nat outside
8
NAT Show IP nat translations Pro Inside global Inside local Outside local Outside global --- 200.200.100.129 192.168.1.5 --- --- --- 200.200.100.252 192.168.1.2 --- --- Show IP nat statistics
9
PAT Ip nat pool net-1 207.139.221.10 255.255.255.0 Access-list 1 permit ip 192.168.1.0 0.0.0.255 ip nat inside source list 1 pool net-1 overload Int f0/0 Ip nat inside Int s0/0 Ip nat outside NAT#show ip nat translations Pro Inside global Inside local Outside local Outside global Tcp 200.200.100.1:80 192.168.1.5:80 200.200.50.2:4806 200.200.50.2:4806 tcp 200.200.100.1:80 192.168.1.5:80 200.200.50.2:4809 200.200.50.2:4809 tcp 200.200.100.1:80 192.168.1.5:80 200.200.50.2:4814 200.200.50.2:4814 tcp 200.200.100.1:80 192.168.1.5:80 --- ---
10
Your NAT configuration X = the second digit of your loopback IP address (config)#access-list 1 permit 1x.0.0.0 0.0.0.255 (config)#ip nat pool public-1 21x.200.100.129 21x.200.100.250 netmask 255.255.255.128 (config)#ip nat inside source list 1 pool public-1 (config)#interface fa 0/0 (config-if)#ip nat inside (config-if)#interface s 0/0 (config-if)#ip nat outside
11
Testing NAT Extended ping from your loopback to a serial interface of your neighbor When ping works – Show ip nat translations
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.