NOTE
The AR2200-S supports GE interfaces, FE interfaces, Eth-Trunk interfaces, and sub-interfaces. If an Eth-
Trunk sub-interface is used to import traffic, run the
display interface eth-trunk
[
trunk-id
[.
subnumber
] ] command to check whether the Eth-Trunk sub-interface has received packets.
Step 2
Check that the ACL rule bound to outbound NAT allows service packets to pass through.
Run the
display nat outbound
command on the AR2200-S to check whether outbound NAT is
correctly configured.
[Huawei]display nat outbound
NAT Outbound Information:
-----------------------------------------------------------------
Interface Acl Address-group/IP Type
-----------------------------------------------------------------
GigabitEthernet0/0/0 2000 1 no-pat
-----------------------------------------------------------------
Total : 1
The preceding command output indicates that ACL 2000 has been bound to outbound NAT on
GigabitEthernet0/0/0.
Check whether the rule of ACL 2000 is configured correctly. If the IP address, port number, or
protocol type in the rule of ACL 2000 is configured incorrectly, packets cannot be transmitted
properly.
Run the
display acl 2000
command to view the configuration of outbound NAT bound to ACL
2000.
[Huawei] display acl 2000
Advanced ACL2000, 1 rule
Acl's step is 5
rule 5 permit source 192.168.1.100 0
The rule of ACL 2000 allows TCP packets with the source address of 192.168.1.100 to pass
through.
l
If the ACL rule is configured incorrectly, reconfigure the ACL rule.
l
If the ACL rule is configured correctly but the fault persists, go to step 3.
Step 3
Check that the address pool configuration is correct.
Run the
display nat address-group
command on the AR2200-S to check whether the address
pool bound to outbound NAT on the outbound interface is correct.
[Huawei] display nat address-group 1
NAT Address-Group Information:
--------------------------------------
Index Start-address End-address
--------------------------------------
1 110.0.0.100 110.0.0.110
--------------------------------------
Total : 1
To view Easy IP information on the outbound interface, run the
display nat outbound
command
on the AR2200-S. For example:
[Huawei] display nat outbound
NAT Outbound Information:
-----------------------------------------------------------------
Interface Acl Address-group/IP Type
-----------------------------------------------------------------
GigabitEthernet0/0/1 2000 30.30.30.1 easyip
-----------------------------------------------------------------
Total : 1
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
311