Permitir a usuarios internos con direcciones ip privadas acceder a Internet: Utilizando NAT Esttico, una direccin interna a una direccin pblica. Utilizado NAT Dinmico, dado un rango de varias direcciones privadas a varias direcciones pblicas.
Utilizando NAT Dinmico (Overload), dado un rango direcciones privadas a una nica direccin pblica.
2
NAT
RED INTERNA INSIDE ROUTER DE FRONTERA RED EXTERNA OUTSIDE
S0/1 .66
PSI
INTERNET
NAT ESTATICO
RED INTERNA INSIDE RED EXTERNA OUTSIDE
200.88.20.64 /30
FE0/0
.1
S0/0
NAT
S0/1
.66
PSI
INTERNET
.65
NAT ESTATICO
I. Definir las interfaces INSIDE, OUTSIDE y la configuracin NAT esttico. Utilizando una direccin privada y una direccin pblica, en el router de FRONTERA.
Interface serial 0/0 Ip address 172.22.6.194 255.255.255.252 Encapsulation ppp Ip nat outside No shutdown FE0/0 .1 CORREO .3 FTP .4 NAT DTE 192.168.1.0/24 Interface fastethernet 0/0 Ip address 192.168.1.1 255.255.255.0 Ip nat inside No shutdown S0/0 .194 S0/0 PPP .195 DCE PSI
INTERNET
WEB .2
172.22.6.193/24
Pool de ips publicas 200.60.131.145/28 - 200.60.131.159/28 Direccin de Sub red : 200.60.131.144 Primer ip : 200.60.131.145 Ultimo ip : 200.60.131.158 Broadcast : 200.60.131.159
NAT DINAMICO
Utilizando un Rango de varias Direcciones Privadas a Varias direcciones Publicas.
RED INTERNA INSIDE
WAN HDLC 20.20.20.0/30 S 0/0: .2 DCE PSI
Fa 0/0: .1 NAT
S 0/0: .1 DTE
INTERNET
10
NAT DINAMICO
1. Definir las interfaces inside y outside 2. Definir el pool de direcciones pblicas
Router(config)#ip nat pool Nombre inicio-ip fin-ip {Netmask <mascara> / Prefix-length <unos de mascara>}
Ejm: Router(config)# ip nat pool <RED-PUBLICA> 207.139.221.10 207.139.221.128 netmask 255.255.255.0 Router(config)# Ip nat pool <RED-PUBLICA> 207.139.221.10 207.139.221.128 prefix-length 24
11
12
NAT DINAMICO
Configurando el Router NAT
Router> enable Router# configure terminal Router(config)# hostname NAT NAT(config)# interface fastethernet 0/0 NAT(config-if)# ip address 192.168.1.1 255.255.255.0 NAT(config-if) # ip nat inside NAT(config-if)# no shutdown NAT(config)# Interface serial 0/0 NAT(config-if)# ip address 20.20.20.1 255.255.255.252 NAT(config-if)# encapsulation ppp NAT(config-if) # ip nat outside NAT(config-if)# no shutdown
13
NAT DINAMICO
NAT(conf)# access-list 20 permit 192.168.1.0 0.0.0.255 NAT(conf)# ip nat pool PUBLICA1 216.20.20.2 216.20.20.14 netmask 255.255.255.240
NAT(conf)# ip nat inside source list 20 PUBLICA1 NAT(config)# ip route 0.0.0.0 Configurando el Router PSI Router> enable Router# configure terminal Router(config)# hostname PSI PSI(config)# Interface serial 0/0 PSI(config-if)# ip address 20.20.20.2 255.255.255.252 PSI(config-if)# encapsulation ppp PSI(config-if)# clock rate 64000 PSI(config-if)# no shutdown PSI(config)# ip route 192.168.1.0 255.255.255.0 20.20.20.1 0.0.0.0 172.6.22.195
14
Fa 0/0: .1
NAT
DTE
DCE
INTERNET
PSI
15
Route(config)# access-list 20 permit 192.168.1.0 0.0.0.255 3. Definir el pool de la nica direccin pblica Router(config)# ip nat pool RED-PUBLICA 200.89.15.71 200.89.15.71 netmask 255.255.255.192
16
Nota: la ventaja de NAPT es que con una nica direccin ip pblica se puede mantener hasta 6400 sesiones simultnea. Mientras que con un NAT cada direccin de inside network se necesita una direccin ip pblica.
NAT y NAPT pueden ser utilizados a la vez dependiendo de la versin de IOS. La ventaja de esta combinacin es que cuando NAT agota su conjunto de direcciones pblicas que se le ha asignado, NAPT puede ser utilizado hasta que algunas de la traducciones NAT sea liberada.
17
18
NAT(conf)# NAT(conf)# netmask NAT(conf)# access-list 20 permit 192.168.1.0 0.0.0.255 ip nat pool PUBLICA1 216.20.20.2 216.20.20.2 255.255.255.240 ip nat inside source list 20 PUBLICA1
NAT(config)# ip route 0.0.0.0 0.0.0.0 172.6.22.195 Configurando el Router PSI Router> enable Router# configure terminal Router(config)# hostname PSI PSI(config)# Interface serial 0/0 PSI(config-if)# ip address 20.20.20.2 255.255.255.252 PSI(config-if)# encapsulation ppp PSI(config-if)# clock rate 64000 PSI(config-if)# no shutdown PSI(config)# ip route 192.168.1.0 255.255.255.0 20.20.20.1
19
WAN 200.20.20.0/30
RED INTERNA 192.168.1.0/24
NAT S0/0 .2 S0/0 .1
INTERNET
PSI
HDLC
*
IP ROUTE 0.0.0.0 0.0.0.0 200.20.20.1 o IP ROUTE 0.0.0.0 0.0.0.0 Serial 0/0 Ruta por default para salir a internet
20
NAT(config-if)# no shutdown
NAT(config-if)# exit
21
22
NAT(config)# ip route 0.0.0.0 0.0.0.0 200.20.20.1 NAT(config)# exit NAT# write memory
En el router del Operador(ISP) ISP(config) # ip route 192.168.1.0 255.255.255.0
216.200.20.2
23
CONFIGURACIN DE NAT ENTRE UNA RED PRIVADA E INTERNET PARA PERMITIR A LOS USUARIOS INTERNOS ACCEDER A INTERNET
La empresa ABC ha decidido permitir a sus empleados acceder a Internet se ha contratado a un proveedor de servicio de Internet (ISP) una lnea dedicada y se ha adquirido un router para encaminar el trfico Internet hacia el proveedor de servicio de Internet. El ISP ha asignado un rango de 128 direcciones pblicas 207.139.221.0 /25. El Administrador de la red de la empresa ABC ha utilizado la red privada 192.168.1.0 /24 para sus hosts internos (ver grfico). Se pide la configuracin del router para de frontera para tal fin. *
Router1 .1 F 0/0 NAT Translation table
Inside local
Internet
.2
.3
.4
192.168.1.2 192.168.1.3
192.168.1.0 /24
192.168.1.4 192.168.1.5
24
CONFIGURACIN DE NAT ENTRE UNA RED PRIVADA E INTERNET PARA PERMITIR A LOS USUARIOS INTERNOS ACCEDER A INTERNET
Router# configure terminal Router(conf)# interface fastethernet 0/0 Router(conf-if)# ip address 192.168.1.1 255.255.255.0 Router(conf-if)# ip nat inside Router(conf-if)# no shutdown Router(conf-if)# exit Router(conf)# interface serial 0/0 Router(conf-if)# ip address 207.139.221.1 255.255.255.128 Router(conf-if)# ip nat outside Router(conf-if)# no shutdown Router(conf-if)# exit Router(conf)# access-list 20 permit 192.168.1.0 0.0.0.255 Router(conf)# ip nat pool PUBLICA1 207.139.221.2 207.139.221.126 netmask 255.255.255.128 Router(conf)# ip nat inside source list 20 PUBLICA1
Router(conf)# ip nat pool PUBLICA2 207.139.221.127 207.139.221.127 netmask 255.255.255.128 Router(conf)# ip nat inside source list 20 PUBLICA2 overload
Router(conf)# ip route 0.0.0.0 0.0.0.0 207.139.221.2
Nota: NAPT ocurrir una vez que NAT all utilizado todas sus 25 direcciones disponibles del pool de direcciones de la lista pblica1
Internet
192.168.1.0 /24
Web Server
E-mail Server
26
192.168.2.0 /24
Router# configure terminal Router(conf)# interface fastethernet 0/0 Router(conf-if)# ip address 192.168.1.1 255.255.255.0 Router(conf-if)# ip nat inside Router(conf-if)# no shutdown Router(conf-if)# exit Router(conf)# interface fastethernet 0/1 Router(conf-if)# ip address 192.168.2.1 255.255.255.0 Router(conf-if)# ip nat inside Router(conf-if)# no shutdown Router(conf-if)# exit Router(conf)# interface serial 0/0 Router(conf-if)# ip address 207.139.221.1 255.255.255.128
27
Borrar la tabla NAT: Router# clear ip nat translation Mostrar las traducciones activos:
EJEMPLO 1
RED PUBLICA
e1 S0: .2 DTE S1: .2 DTE R2 e0 S0 DCE e0 LAN 1 192.168.100.0 /24 R3 e1 Lan 2 192.168.200.0 /24 WAN 1 5.5.5.0 /30 WAN 2 6.6.6.0/30 LAN 4 172.16.100.0 /24
S0: .1 DCE R1 e1
E0: .70
PSI
I N T E R N E T
web
.10 .72
ftp
.20 .73
email
.30 .74
30
EJEMPLO 1
R1# show running-config R1(config)# interface Ethernet 0/0 R1(config-if)# ip address 192.168.254.1 255.255.255.0 R1(config-if)# ip nat inside R1(config-if)# no shutdown R1(config-if)# exit R1(config)# interface Serial 0/0 R1(config-if)# ip address 6.6.6.1 255.255.255.252 R1(config-if)# ip nat inside R1(config-if)# clockrate 64000 R1(config-if) # no shutdown R1(config-if) # exit
R1(configf)# interface Ethernet 0/1 R1(config-if)# ip address 200.89.15.70 255.255.255.192 R1(config-if)# ip nat outside R1(config-if) # no shutdown ! R1(configf)# router rip R1(config-router)# version 2 R1(config-router)# network 6.0.0.0 Habilitando el protocolo RIP v2 en el router . R1(config-router)# network 192.168.254.0 R1(config-router)# default-information originate ! R1(config)# ip nat inside source static 192.168.100.30 200.89.15.74 R1(config)# ip nat inside source static 192.168.100.20 200.89.15.73 R1(config)# ip nat inside source static 192.168.100.10 200.89.15.72 R1(config)# ip route 0.0.0.0 0.0.0.0 200.89.15.65 !
Habilitando NAT ESTATICO para dar salida a Internet Y publicar los servidores a Internet.
31
EJEMPLO 1
R1(config)# ip access-list standard MIRED
Declara la lista estndar MIRED.
0.0.0.31
Caso I: De la LAN 2 solamente podran acceder los 30 primeros Hosts.
0.0.0.17
Caso II: De la LAN 4 solamente podra salir los 14 primeros hosts
0.0.0.254
Caso III: De la LAN5 solamente podran tener acceso hosts con IP pares
32
EJEMPLO 1
R2# show running-config ! R2(config)# interface Ethernet 0/0 R2(config-if)# ip address 172.16.100.1 255.255.255.0 R2(config-if)# no shutdown ! R2(config)# interface Serial 0/0 R2(config-if)# ip address 5.5.5.2 255.255.255.252 R2(config-if)# no shutdown ! R2(config)# interface Ethernet 0/1 R2(config-if)# ip address 172.16.200.1 255.255.255.0 R2(config-if)# no shutdown ! R2(config)# interface Serial 0/1 R2(config-if)# ip address 6.6.6.2 255.255.255.252 R2(config-if)# no shutdown ! R2(config)# router rip R2(config-router)# version 2 R2(config)-router# network 5.0.0.0 R2(config-router)# network 6.0.0.0 R2(config-router)# network 172.16.0.0
EJEMPLO 1
R3# show running-config ! R3(config)# interface Ethernet 0/0 R3(config-if)# ip address 192.168.100.1 255.255.255.0 R3(config-if)# no shutdown ! R3(config)# interface Serial 0/0 R3(config-if)# ip address 5.5.5.1 255.255.255.252 R3(config-if)# no shutdown R3(config-if)# clockrate 64000 ! R3(config)# interface Ethernet 0/1 R3(config-if)# ip address 192.168.200.1 255.255.255.0 R3(config-if)# no shutdown ! R3(config)# router rip R3(config-if)# version 2 Habilitando el protocolo R3(config-if)# network 5.0.0.0 v2 en el router . R3(config-if)# network 192.168.100.0 R3(config-if)# network 192.168.200.0 ! R3#
RIP
34
EJEMPLO 1
Mostrando las tablas de Rutas: ROUTER 1. R1# show ip route Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area * - candidate default, U - per-user static route, o - ODR P - periodic downloaded static route Gateway of last resort is 200.89.15.65 to network 0.0.0.0 R C R R C C R S* 5.0.0.0/8 [120/1] via 6.6.6.2, 00:00:05, Serial0/0 6.0.0.0/30 is subnetted, 1 subnets 6.6.6.0 is directly connected, Serial0/0 172.16.0.0/16 [120/1] via 6.6.6.2, 00:00:05, Serial0/0 192.168.200.0/24 [120/2] via 6.6.6.2, 00:00:05, Serial0/0 200.89.15.0/26 is subnetted, 1 subnets 200.89.15.64 is directly connected, Ethernet0/1 192.168.254.0/24 is directly connected, Ethernet0/0 192.168.100.0/24 [120/2] via 6.6.6.2, 00:00:05, Serial0/0 0.0.0.0/0 [1/0] via 200.89.15.65
35
EJEMPLO 1
Mostrando las tablas de Rutas: ROUTER R2. R2# show ip route Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area * - candidate default, U - per-user static route, o - ODR P - periodic downloaded static route Gateway of last resort is 6.6.6.1 to network 0.0.0.0 5.0.0.0/30 is subnetted, 1 subnets C 5.5.5.0 is directly connected, Serial0/0 6.0.0.0/30 is subnetted, 1 subnets C 6.6.6.0 is directly connected, Serial0/1 172.16.0.0/24 is subnetted, 2 subnets C 172.16.200.0 is directly connected, Ethernet0/1 C 172.16.100.0 is directly connected, Ethernet0/0 R 192.168.200.0/24 [120/1] via 5.5.5.1, 00:00:24, Serial0/0 R 192.168.254.0/24 [120/1] via 6.6.6.1, 00:00:02, Serial0/1 R 192.168.100.0/24 [120/1] via 5.5.5.1, 00:00:24, Serial0/0 R* 0.0.0.0/0 [120/1] via 6.6.6.1, 00:00:02, Serial0/1 Ruta hacia Internet o la red Publica 36
EJEMPLO 1
Mostrando las tablas de Rutas: ROUTER R2. R2# show ip route Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area * - candidate default, U - per-user static route, o - ODR P - periodic downloaded static route Gateway of last resort is 6.6.6.1 to network 0.0.0.0 5.0.0.0/30 is subnetted, 1 subnets C 5.5.5.0 is directly connected, Serial0/0 6.0.0.0/30 is subnetted, 1 subnets C 6.6.6.0 is directly connected, Serial0/1 172.16.0.0/24 is subnetted, 2 subnets C 172.16.200.0 is directly connected, Ethernet0/1 C 172.16.100.0 is directly connected, Ethernet0/0 R 192.168.200.0/24 [120/1] via 5.5.5.1, 00:00:24, Serial0/0 R 192.168.254.0/24 [120/1] via 6.6.6.1, 00:00:02, Serial0/1 R 192.168.100.0/24 [120/1] via 5.5.5.1, 00:00:24, Serial0/0 R* 0.0.0.0/0 [120/1] via 6.6.6.1, 00:00:02, Serial0/1 Ruta hacia Internet o la red Publica 37
EJEMPLO 1
Mostrando las tablas de Rutas: ROUTER R3. R3# show ip route Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area * - candidate default, U - per-user static route, o - ODR P - periodic downloaded static route Gateway of last resort is 5.5.5.2 to network 0.0.0.0 5.0.0.0/30 is subnetted, 1 subnets C 5.5.5.0 is directly connected, Serial0/0 R 6.0.0.0/8 [120/1] via 5.5.5.2, 00:00:06, Serial0/0 R 172.16.0.0/16 [120/1] via 5.5.5.2, 00:00:06, Serial0/0 C 192.168.200.0/24 is directly connected, Ethernet0/1 R 192.168.254.0/24 [120/2] via 5.5.5.2, 00:00:06, Serial0/0 C 192.168.100.0/24 is directly connected, Ethernet0/0 15.0.0.0/24 is subnetted, 1 subnets C 15.15.15.0 is directly connected, Ethernet0/0 R* 0.0.0.0/0 [120/2] via 5.5.5.2, 00:00:06, Serial0/0 Ruta hacia Internet o la red Publica 38
EJEMPLO 1
Trasando rutas al servidor de: www.google.com
R1# traceroute www.cisco.com Type escape sequence to abort. Tracing the route to www.cisco.com (198.133.219.25) 1 200.89.15.65 0 msec 4 msec 8 msec 2 200.89.15.137 4 msec 8 msec 4 msec 3 200.89.9.1 8 msec 4 msec 4 msec 4 200.89.0.102 4 msec 4 msec 8 msec 5 200.89.0.1 4 msec 9 msec 4 msec 6 DS3.Peru-Miami.comsat-internacional.net (200.47.167.229) 80 msec 88 msec 84 msec 7 so-1-1-2.ar2.MIA1.gblx.net (64.214.174.145) 85 msec 84 msec 93 msec 8 so2-1-0-2488M.ar1.DCA3.gblx.net (67.17.67.57) 116 msec 116 msec 116 msec 9 sl-st20-ash-13-0.sprintlink.net (144.232.8.17) 116 msec 120 msec 120 msec 10 sl-bb23-rly-5-0.sprintlink.net (144.232.20.153) 125 msec 140 msec 116 msec 11 sl-bb21-rly-9-0.sprintlink.net (144.232.14.133) 181 msec 412 msec 313 msec 12 sl-bb22-rly-13-0.sprintlink.net (144.232.7.254) 116 msec 117 msec 124 msec 13 sl-bb22-sj-10-0.sprintlink.net (144.232.20.186) 176 msec 165 msec 160 msec 14 sl-bb20-sj-15-0.sprintlink.net (144.232.3.166) 164 msec 165 msec 168 msec 15 sl-gw11-sj-9-0.sprintlink.net (144.232.3.138) 164 msec 169 msec 164 msec 16 sl-ciscopsn2-11-0-0.sprintlink.net (144.228.44.14) 164 msec 176 msec 172 msec 17 sjce-dmzbb-gw1.cisco.com (128.107.239.89) 173 msec 168 msec 168 msec 18 sjck-dmzdc-gw2.cisco.com (128.107.224.73) 168 msec 244 msec 204 msec 39
EJEMPLO 1
Trasando rutas al servidor de: WWW.CISCO.COM
R1# TRACEROUTE WWW.CISCO.COM Type escape sequence to abort. Tracing the route to www.cisco.com (198.133.219.25) 1 200.89.15.65 4 msec 4 msec 4 msec 2 200.89.15.137 4 msec 4 msec 4 msec 3 200.89.9.1 4 msec 4 msec 4 msec 4 200.89.0.102 8 msec 8 msec 8 msec 5 200.89.0.1 4 msec 4 msec 4 msec 6 DS3.Peru-Miami.comsat-internacional.net (200.47.167.229) 81 msec 88 msec 92 msec 7 so-1-1-2.ar2.MIA1.gblx.net (64.214.174.145) 88 msec 84 msec 88 msec 8 so2-1-0-2488M.ar1.DCA3.gblx.net (67.17.67.57) 113 msec 116 msec 120 msec 9 sl-st20-ash-13-0.sprintlink.net (144.232.8.17) 120 msec 112 msec 117 msec 10 sl-bb23-rly-5-0.sprintlink.net (144.232.20.153) 120 msec 120 msec 116 msec 11 sl-bb21-rly-9-0.sprintlink.net (144.232.14.133) 148 msec 177 msec 140 msec 12 sl-bb22-rly-13-0.sprintlink.net (144.232.7.254) 120 msec 120 msec 120 msec 13 sl-bb22-sj-10-0.sprintlink.net (144.232.20.186) 168 msec 164 msec 160 msec 14 sl-bb20-sj-15-0.sprintlink.net (144.232.3.166) 165 msec 180 msec 168 msec 15 sl-gw11-sj-9-0.sprintlink.net (144.232.3.138) 164 msec 165 msec 160 msec 16 sl-ciscopsn2-11-0-0.sprintlink.net (144.228.44.14) 168 msec 173 msec 176 msec 17 sjce-dmzbb-gw1.cisco.com (128.107.239.89) 172 msec 164 msec 169 msec 18 sjck-dmzdc-gw2.cisco.com (128.107.224.73) 164 msec 168 msec 165 msec 40
EJEMPLO 2
LAN 3 172.16.200.0/24
S1: .2 DTE
WAN 2 6.6.6.0/30 LAN 4 172.16.100.0 /24
S0: .1 DCE R1 e1
E0: .70
WAN 3 200.89.15.64/26
I N T E R N E T
LAN 5 192.168.254.0/24
192.168.200.0/24
41
EJEMPLO 2
Router 1
R1(config)#interface Ethernet 0/0 R1(config-if)# ip address 192.168.254.1 255.255.255.0 R1(config-if)# ip nat inside R1(config)# No shutdown ! R1(config)# interface Serial 0/0 R1(config-if)# ip address 6.6.6.1 255.255.255.252 R1(config-if)# ip nat inside R1(config-if)# clockrate 64000 R1(config-if)# No shutdown ! R1(config)# interface Ethernet 0/1 R1(config-if)# ip address 200.89.15.70 255.255.255.192 R1(config-if)# ip nat outside R1(config-if)# No sutdown !
42
EJEMPLO 2
Router 1
R1(config)# router igrp 100 R1(config-router)# pasive-interface Ethernet 0/1 R1(config-router)# network 6.0.0.0 R1(config-router)# network 192.168.254.0 R1(config-router# network 200.89.15.0 ! R1(config)# ip access-list standard MIRED R1(config-std-nacl)# permit 192.168.200.0 0.0.0.31 R1(config-std-nacl)# permit 172.16.100.0 0.0.0.17 R1(config-std-nacl)# permit 192.168.254.0 0.0.0.254 R1(config-std-nacl)# permit 172.16.200.0 0.0.0.7 R1(config)# R1(config)# R1(config)# R1(config)# R1(config)# ip nat inside source list MIRED pool OPTICAL overload ip nat pool OPTICAL 200.89.15.71 200.89.15.71 netmask 255.255.255.192 ip nat inside source static 192.168.100.10 200.89.15.72 ip nat inside source static 192.168.100.20 200.89.15.73 ip nat inside source static 192.168.100.30 200.89.15.74
43
EJEMPLO 2
Router 2
R2# show running-config ! R2(config)# interface Ethernet 0/0 R2(config-if)# ip address 172.16.100.1 255.255.255.0 R2(config-if)# no shutdown ! R2(config)# interface Serial 0/0 R2(config-if)# ip address 5.5.5.2 255.255.255.252 R2(config-if)# no shutdown ! R2(config)# interface Ethernet 0/1 R2(config-if)# ip address 172.16.200.1 255.255.255.0 R2(config-if)#no shutdown ! R2(config-if)# interface Serial 0/1 R2(config-if)# ip address 6.6.6.2 255.255.255.252 R2(config-if)#no shutdown ! R2(config)# router igrp 100 R2(config-if)# network 5.0.0.0 R2(config-if)# network 6.0.0.0 R2(config-if)# network 172.16.0.0
44
EJEMPLO 2
Router 3
R3#show running-config ! R3(config)# interface Ethernet 0/0 R3(config-if)# ip address 192.168.100.1 255.255.255.0 R3(config-if)# no shutdown ! R3(config)# interface Serial 0/0 R3(config-if)# ip address 5.5.5.1 255.255.255.252 R3(config-if)# no shutdown R3(config-if)# clockrate 64000 ! R3(config)# interface Ethernet 0/1 R3(config-if)# ip address 192.168.200.1 255.255.255.0 R3(config-if)# no shutdown ! R3(config)# router igrp 100 R3(config-if)# network 5.0.0.0 R3(config-if)# network 192.168.100.0
45
EJEMPLO 2
Analizando el NAT
R1#show ip nat translations Pro Inside global Inside local --- 200.89.15.72 192.168.100.10 --- 200.89.15.73 192.168.100.20 --- 200.89.15.74 192.168.100.30 --- 200.89.15.75 192.168.100.2 --- 200.89.15.76 192.168.100.5 Outside local ----------Outside global -----------
46