data:image/s3,"s3://crabby-images/b4252/b42520bf34947d0b7204ff3203083e2fb8408f67" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 335"
16-31
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 16 Configuring NAT
Using Static PAT
See the
“Configuring Dynamic NAT or PAT” section on page 16-26
for information about the
options.
For example, the following policy static NAT example shows a single real address that is translated to
two mapped addresses depending on the destination address. (See
Figure 16-9 on page 16-11
for a
related figure.)
hostname(config)#
access-list NET1 permit ip host 10.1.2.27 209.165.201.0 255.255.255.224
hostname(config)#
access-list NET2 permit ip host 10.1.2.27 209.165.200.224
255.255.255.224
hostname(config)#
static (inside,outside) 209.165.202.129 access-list NET1
hostname(config)#
static (inside,outside) 209.165.202.130 access-list NET2
The following command maps an inside IP address (10.1.1.3) to an outside IP address (209.165.201.12):
hostname(config)#
static (inside,outside) 209.165.201.12 10.1.1.3 netmask 255.255.255.255
The following command maps the outside address (209.165.201.15) to an inside address (10.1.1.6):
hostname(config)#
static (outside,inside) 10.1.1.6 209.165.201.15 netmask 255.255.255.255
The following command statically maps an entire subnet:
hostname(config)#
static (inside,dmz) 10.1.1.0 10.1.2.0 netmask 255.255.255.0
Using Static PAT
This section describes how to configure a static port translation. Static PAT lets you translate the real IP
address to a mapped IP address, as well as the real port to a mapped port. You can choose to translate
the real port to the same port, which lets you translate only specific types of traffic, or you can take it
further by translating to a different port.
Figure 16-23
shows a typical static PAT scenario. The translation is always active so that both translated
and remote hosts can originate connections, and the mapped address and port is statically assigned by
the
static
command.
Figure 16-23
Static PAT
For applications that require application inspection for secondary channels (FTP, VoIP, and so on), the
FWSM automatically translates the secondary ports.
Do not use a mapped address in the
static
command that is also defined in a
global
command for the
same mapped interface.
For more information about static PAT, see the
“Static PAT” section on page 16-9
.
10.1.1.1:23
209.165.201.1:23
Inside
Outside
10.1.1.2:8080
209.165.201.2:80
132943
FWSM
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......