data:image/s3,"s3://crabby-images/42869/428696c0fa14c0c78304cdec1000edd8df733930" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 339"
16-35
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 16 Configuring NAT
Bypassing NAT
information about policy NAT.) For example, you can use policy static identity NAT for an inside address
when it accesses the outside interface and the destination is server A, but use a normal translation when
accessing the outside server B.
Figure 16-25
shows a typical static identity NAT scenario.
Figure 16-25
Static Identity NAT
Note
If you remove a
static
command, existing connections that use the translation are not affected. To remove
these connections, enter the
clear local-host
command.
Static translations from the translation table can be removed using the
clear xlate
command; the
translation table will be cleared and all current translations are deleted.
To configure static identity NAT, enter one of the following commands:
•
To configure policy static identity NAT, enter the following command:
hostname(config)#
static (
real_interface
,
mapped_interface
)
real_ip
access-list
acl_id
[
dns
]
[[
tcp
]
tcp_max_conns
[
emb_limit
]] [
udp
udp_max_conns
] [
norandomseq
]
Create the extended access list using the
access-list extended
command. (See the
“Adding an
Extended Access List” section on page 13-6
.) This access list should include only
permit
ACEs.
Make sure the source address in the access list matches the
real_ip
in this command. Policy NAT
and static NAT consider the
inactive
or
time-range
keywords and stop working when an ACE is
inactive. See the
“Policy NAT” section on page 16-10
for more information.
See the
“Configuring Dynamic NAT or PAT” section on page 16-26
for information about the other
options.
•
To configure regular static identity NAT, enter the following command:
hostname(config)#
static (
real_interface
,
mapped_interface
)
real_ip real_ip
[
netmask
mask
] [
dns
]
[[
tcp
]
tcp_max_conns
[
emb_limit
]] [
udp
udp_max_conns
]
[
norandomseq
]
Specify the same IP address for both
real_ip
arguments.
See the
“Configuring Dynamic NAT or PAT” section on page 16-26
for information about the other
options.
For example, the following command uses static identity NAT for an inside IP address (10.1.1.3) when
accessed by the outside:
hostname(config)#
static (inside,outside) 10.1.1.3 10.1.1.3 netmask 255.255.255.255
209.165.201.1
209.165.201.1
Inside
Outside
209.165.201.2
209.165.201.2
132938
FWSM
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......