SlideShare uma empresa Scribd logo
1 de 23
CISCO CCNA
NAT CONFIGURATION
TO WATCH OUR CISCO CCNA VIDEO TRAININGS PLEASE CHECK OUT THE LINK BELOW:
WWW.ASMED.COM/C1
ASM EDUCATIONAL CENTER INC. (ASM)
WHERE TRAINING, TECHNOLOGY & SERVICE CONVERGE
PHONE: (301) 984-7400
ROCKVILLE,MD
CISCO CCNA NAT CONFIGURATION
CISCO CCNA NAT CONFIGURATION
NAT = NETWORK ADDRESS TRANSLATION
REMEMBER THE PRIVATE IP ADDRESS
10.0.0.0 — 10.255.255.255
172.16.0.0 —-172.31.255.255
192.168.0.0.—– 192.168.255.255
THE GOAL IS TO CONVERT YOUR PRIVATE IP ADDRESS TO PUBLIC ADDRESS SO
THAT YOUR INTERNAL PEOPLE CAN ACCESS THE INTERNET
CISCO CCNA NAT CONFIGURATION
I HAVE 2 KIND:
1) DYNAMIC NAT – USE IT WHEN YOU NEED YOUR PRIVATE NETWORK GO OUT
TO INTERNET – IT HAS TWO KIND
SUPPOSE I HAVE 6 PRIVATE AND THEN ISP GIVE YOU 6 PUBLIC THEN ALL SIX PEOPLE GO TO
INTERNET
SUPPOSE I HAVE 62 PRIVATE AND ISP ONLY GIVE YOU 6 PUBLIC IN THIS CASE ; YOU MUST
USE THE KEY WORD “OVERLOAD” ; THIS CONCEPT IS CALL PAT (PORT ADDRESS
TRANSLATION)
2) STATIC NAT – USE IT WHEN YOU NEED THE INTERNET PEOPLE COME TO
YOUR WEBSERVER; THAT IS LOCATED IN PRIVATE LAN =10.10.10.1; IN THIS CASE YOU
NEED TO USE STATIC NAT
CISCO CCNA NAT CONFIGURATION
HERE IS MY LAB ON NAT/PAT:
GIVEN BY ISP 6 PUBLIC ADDRESS 198.18.151.97
.98, .99,100,101,102 WITH SUBNET MASK /29
/29=255.255.255.248
.11111000
AND I HAVE 62 INTERNAL IP ADDRESS THAT NEED TO GO TO INTERNET
192.168.91.65—192.168.91.126 WITH MASK /26 255.255.255.192
.11000000
CISCO CCNA NAT CONFIGURATION
STEP 1) DEFINE THE POOL OF INSIDE GLOBAL ADDRESS (PUBLIC ADDRESS)
THAT INSIDE LOCAL ADDRESS WILL BE TRANSLATED TO:
HINT: ALWAYS ALWAYS START WITH IP NAT?
R1#
R1#CONFIG T
ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z.
R1(CONFIG)#IP NAT ?
INSIDE INSIDE ADDRESS TRANSLATION
OUTSIDE OUTSIDE ADDRESS TRANSLATION
POOL DEFINE POOL OF ADDRESSES
R1(CONFIG)#IP NAT POO
R1(CONFIG)#IP NAT POOL ?
WORD POOL NAME
R1(CONFIG)#IP NAT POOL CCNA ?
CISCO CCNA NAT CONFIGURATION
A.B.C.D START IP ADDRESS
R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 ?
A.B.C.D END IP ADDRESS
R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 ?
NETMASK SPECIFY THE NETWORK MASK
R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NET
R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK ?
A.B.C.D NETWORK MASK
R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK
255.255.255.248 ?
<CR>
R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK
255.255.255.248
R1(CONFIG)#
CISCO CCNA NAT CONFIGURATION
HERE IS MY SHOW RUN:
IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248
HINT: ANY TIME YOU SEE THE WORD POOL IT WILL TELL YOU; THAT IS PUBLIC IP ADDRESS
STEP 2) DEFINE THE SOURCE OF THE INSIDE LOCAL ADDRESS AND BIND IT TO CCNA DEFINED IN PART 1
HINT: IP NAT?
R1#
R1#
R1#CONFIG T
ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z.
R1(CONFIG)#IP NAT ?
INSIDE INSIDE ADDRESS TRANSLATION
OUTSIDE OUTSIDE ADDRESS TRANSLATION
POOL DEFINE POOL OF ADDRESSES
R1(CONFIG)#IP NAT
% INCOMPLETE COMMAND.
R1(CONFIG)#IP NAT INS
R1(CONFIG)#IP NAT INSIDE ?
SOURCE SOURCE ADDRESS TRANSLATION
CISCO CCNA NAT CONFIGURATION
R1(CONFIG)#IP NAT INSIDE SOU
R1(CONFIG)#IP NAT INSIDE SOURCE ?
LIST SPECIFY ACCESS LIST DESCRIBING LOCAL ADDRESSES
STATIC SPECIFY STATIC LOCAL->GLOBAL MAPPING
R1(CONFIG)#IP NAT INSIDE SOURCE LIST ?
<1-199> ACCESS LIST NUMBER FOR LOCAL ADDRESSES
WORD ACCESS LIST NAME FOR LOCAL ADDRESSES
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 ?
INTERFACE SPECIFY INTERFACE FOR GLOBAL ADDRESS
POOL NAME POOL OF GLOBAL ADDRESSES
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POO
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL ?
WORD NAME POOL OF GLOBAL ADDRESSES
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA ?
OVERLOAD OVERLOAD AN ADDRESS TRANSLATION
<CR>
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVE
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD ?
<CR>
R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD
CISCO CCNA NAT CONFIGURATION
HINT: IF ISP HAS GIVEN YOU A SINGLE IP ADDRESS AFTER LIST 1 ? I WILL USE INTERFACE S0/0
HINT: WHEN YOU SEE THE WORD LIST THAT SHOULD TELL YOU ; I NEED TO HAVE ACL 1 THAT WILL
DEFINE MY LOCAL ADDRESS
STEP 3) NOW DEFINE YOU ACL 1
HINT: I HAVE /26
255.255.255.255-
255.255.255.192
————–
0.0.0.63 AS WILD CARDS
R1(CONFIG )# ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63
SUBNET ID WILD CARDS
CISCO CCNA NAT CONFIGURATION
R1(CONFIG)#
R1(CONFIG)#ACC
R1(CONFIG)#ACCESS-LIST ?
<1-99> IP STANDARD ACCESS LIST
<100-199> IP EXTENDED ACCESS LIST
R1(CONFIG)#ACCESS-LIST 1 ?
DENY SPECIFY PACKETS TO REJECT
PERMIT SPECIFY PACKETS TO FORWARD
REMARK ACCESS LIST ENTRY COMMENT
R1(CONFIG)#ACCESS-LIST 1 PERMI
R1(CONFIG)#ACCESS-LIST 1 PERMIT ?
A.B.C.D ADDRESS TO MATCH
ANY ANY SOURCE HOST
HOST A SINGLE HOST ADDRESS
R1(CONFIG)#ACCESS-LIST 1 PERMIT 192.168.91.69 0.0.0.63
CISCO CCNA NAT CONFIGURATION
HERE I INTENTIONALLY PUT WRONG SUBNET ID; BUT IOS WILL FIX IT FOR ME:
HERE IS MY SHOW RUN:
IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248
IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD
IP CLASSLESS
!
!
ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63
STEP 4) TELL ROUTER WHICH SIDE IS INSIDE AND WHICH SIDE IS OUTSIDE AND MAKE SURE BE UNDER
INTERFACE AND GIVE:
INT F0/0
IP NAT INSIDE
INT S0/0
IP NAT OUTSIDE
CISCO CCNA NAT CONFIGURATION
R1#CONFIG T
ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z.
R1(CONFIG)#INT F0/0
R1(CONFIG-IF)#IP NAT
R1(CONFIG-IF)#IP NAT ?
INSIDE INSIDE INTERFACE FOR ADDRESS TRANSLATION
OUTSIDE OUTSIDE INTERFACE FOR ADDRESS TRANSLATION
R1(CONFIG-IF)#IP NAT INS
R1(CONFIG-IF)#IP NAT INSIDE
R1(CONFIG-IF)#
R1(CONFIG-IF)#
R1(CONFIG-IF)#INT S0/0
R1(CONFIG-IF)#IP NAT ?
INSIDE INSIDE INTERFACE FOR ADDRESS TRANSLATION
OUTSIDE OUTSIDE INTERFACE FOR ADDRESS TRANSLATION
R1(CONFIG-IF)#IP NAT OUT
R1(CONFIG-IF)#IP NAT OUTSIDE
CISCO CCNA NAT CONFIGURATION
NOW LET’S LOOK AT SHOW RUN:
INTERFACE FASTETHERNET0/0
IP ADDRESS 192.168.91.126 255.255.255.192
IP NAT INSIDE
DUPLEX AUTO
SPEED AUTO
!
!
INTERFACE SERIAL0/0
IP ADDRESS 192.0.1.109 255.255.255.252
IP NAT OUTSIDE
CLOCK RATE 64000
IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248
IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD
IP CLASSLESS
!
!
ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63
LAST TWO STEPS IS DONE TO CHECK AND MAKE SURE LIFE IS GOOD;
CISCO CCNA NAT CONFIGURATION
STEP 5) MAKE SURE YOUR ROUTER HAS A DEFAULT ROUTE TO ISP.
R1#CONFIG T
ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z.
R1(CONFIG)#
R1(CONFIG)#IP ROUTE 0.0.0.0 0.0.0.0 ?
A.B.C.D FORWARDING ROUTER’S ADDRESS
ETHERNET IEEE 802.3
FASTETHERNET FASTETHERNET IEEE 802.3
GIGABITETHERNET GIGABITETHERNET IEEE 802.3Z
LOOPBACK LOOPBACK INTERFACE
NULL NULL INTERFACE
SERIAL SERIAL
R1(CONFIG)#IP ROUTE 0.0.0.0 0.0.0.0 192.0.1.110
CISCO CCNA NAT CONFIGURATION
STEP 6) MAKE SURE ISP KNOWS YOUR NETWORK; SO ISP WILL NEED A STATIC ROUTE BACK TO
YOUR NETWORK
ISP#
ISP#CONFIG T
ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z.
ISP(CONFIG)#IP ROUTE ?
A.B.C.D DESTINATION PREFIX
ISP(CONFIG)#IP ROUTE 198.18.151.96 ?
A.B.C.D DESTINATION PREFIX MASK
ISP(CONFIG)#IP ROUTE 198.18.151.96 255.255.255.248 ?
A.B.C.D FORWARDING ROUTER’S ADDRESS
ETHERNET IEEE 802.3
FASTETHERNET FASTETHERNET IEEE 802.3
GIGABITETHERNET GIGABITETHERNET IEEE 802.3Z
LOOPBACK LOOPBACK INTERFACE
NULL NULL INTERFACE
SERIAL SERIAL
ISP(CONFIG)#IP ROUTE 198.18.151.96 255.255.255.248 S0/0
ISP(CONFIG)#
CISCO CCNA NAT CONFIGURATION
AS WE SEE FOR ISP MAKE SURE YOU USE THE PUBLIC ADDRESS NOT PRIVATE; SNICE ISP DOES NOT KNOW YOUR
PRIVATE IP ADDRESS
NOW I GO AND CHECK THE PING FROM PC TO INTERNET; THEN I GO TO R1#SHOW IP NAT TRANSLATION
!
PC>
PC>PING 192.0.1.110
PINGING 192.0.1.110 WITH 32 BYTES OF DATA:
REPLY FROM 192.0.1.110: BYTES=32 TIME=13MS TTL=254
REPLY FROM 192.0.1.110: BYTES=32 TIME=15MS TTL=254
REPLY FROM 192.0.1.110: BYTES=32 TIME=11MS TTL=254
REPLY FROM 192.0.1.110: BYTES=32 TIME=12MS TTL=254
PING STATISTICS FOR 192.0.1.110:
PACKETS: SENT = 4, RECEIVED = 4, LOST = 0 (0% LOSS),
APPROXIMATE ROUND TRIP TIMES IN MILLI-SECONDS:
MINIMUM = 11MS, MAXIMUM = 15MS, AVERAGE = 12MS
CISCO CCNA NAT CONFIGURATION
R1#SHOW IP NAT TRANSLATIONS
PRO INSIDE GLOBAL INSIDE LOCAL OUTSIDE LOCAL OUTSIDE GLOBAL
ICMP 198.18.151.97:10 192.168.91.65:10 192.0.1.110:10 192.0.1.110:10
ICMP 198.18.151.97:11 192.168.91.65:11 192.0.1.110:11 192.0.1.110:11
ICMP 198.18.151.97:12 192.168.91.65:12 192.0.1.110:12 192.0.1.110:12
ICMP 198.18.151.97:9 192.168.91.65:9 192.0.1.110:9 192.0.1.110:9
CISCO CCNA NAT CONFIGURATION
HERE IS THE SUMMARY:
INTERFACE FASTETHERNET0/0
IP ADDRESS 192.168.91.126 255.255.255.192
IP NAT INSIDE
DUPLEX AUTO
SPEED AUTO
!
INTERFACE SERIAL0/0
IP ADDRESS 192.0.1.109 255.255.255.252
IP NAT OUTSIDE
CLOCK RATE 64000
!
IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248
IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD
IP CLASSLESS
IP ROUTE 0.0.0.0 0.0.0.0 192.0.1.110
!
!
ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63
!
CISCO CCNA NAT CONFIGURATION
HINT: IF ISP HAS GIVEN YOU SINGLE IP ADDRESS THEN YOU DO NOT NEED THE POOL STATEMENT ( THE 1ST
STATEMENT) ; AND ALSO YOUR 2ND STATMENT WILL BE LIKE THIS
IP NAT INSIDE SOURCE LIST 1 INT S0/0 OVERLOAD
NOW IF I ADD ANOTHER LAN (10.10.10.0/24) USING MY INT F0/1
MAKE SURE YOU HAVE DEFINE ACL FOR NETWORK 10.10.10.0 /24 TO GO OUT AND
MAKE SURE YOUR APPLY TO INT F0/1 WITH COMMAND IP NAT INSIDE
INTERFACE FASTETHERNET0/0
IP ADDRESS 192.168.91.126 255.255.255.192
IP NAT INSIDE
DUPLEX AUTO
SPEED AUTO
!
CISCO CCNA NAT CONFIGURATION
INTERFACE FASTETHERNET0/1
IP ADDRESS 10.10.10.100 255.255.255.0
IP NAT INSIDE ( PLEASE ADD THIS)
DUPLEX AUTO
SPEED AUTO
!
INTERFACE SERIAL0/0
IP ADDRESS 192.0.1.109 255.255.255.252
IP NAT OUTSIDE
CLOCK RATE 64000
!
CISCO CCNA NAT CONFIGURATION
IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248
IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD
IP CLASSLESS
IP ROUTE 0.0.0.0 0.0.0.0 192.0.1.110
!
!
ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63
ACCESS-LIST 1 PERMIT 10.10.10.0 0.0.0.255 (PLEASE ADD THIS LINE)
!
ASM EDUCATIONAL CENTER INC. (ASM)
WHERE TRAINING, TECHNOLOGY & SERVICE CONVERGE
TO WATCH OUR CISCO CCNA VIDEO TRAININGS PLEASE CHECK OUT THE LINK
BELOW:
WWW.ASMED.COM/C1
PHONE: (301) 984-7400
ROCKVILLE,MD

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

IPv4
IPv4IPv4
IPv4
 
A very good introduction to IPv6
A very good introduction to IPv6A very good introduction to IPv6
A very good introduction to IPv6
 
Ccnp workbook network bulls
Ccnp workbook network bullsCcnp workbook network bulls
Ccnp workbook network bulls
 
Vlan lab
Vlan labVlan lab
Vlan lab
 
Subnetting
SubnettingSubnetting
Subnetting
 
Subnetting Presentation
Subnetting PresentationSubnetting Presentation
Subnetting Presentation
 
OSPF
OSPF OSPF
OSPF
 
Ipv6 the next generation protocol
Ipv6 the next generation protocolIpv6 the next generation protocol
Ipv6 the next generation protocol
 
Configuration DHCP
Configuration DHCPConfiguration DHCP
Configuration DHCP
 
IP Address
IP AddressIP Address
IP Address
 
Cn ipv4 addressing
Cn ipv4 addressingCn ipv4 addressing
Cn ipv4 addressing
 
Packet Tracer Tutorial # 1
Packet Tracer Tutorial # 1Packet Tracer Tutorial # 1
Packet Tracer Tutorial # 1
 
IP classes and subnetting.
IP classes and subnetting.IP classes and subnetting.
IP classes and subnetting.
 
Static NAT
Static NATStatic NAT
Static NAT
 
Cisco router configuration tutorial
Cisco router configuration tutorialCisco router configuration tutorial
Cisco router configuration tutorial
 
Network address translation
Network address translationNetwork address translation
Network address translation
 
Hot standby router protocol (hsrp) using
Hot standby router protocol (hsrp) usingHot standby router protocol (hsrp) using
Hot standby router protocol (hsrp) using
 
Tcp/ip
Tcp/ipTcp/ip
Tcp/ip
 
Access Control List & its Types
Access Control List & its TypesAccess Control List & its Types
Access Control List & its Types
 
Nat pat
Nat patNat pat
Nat pat
 

Destaque

Juniper JNCIA – Juniper RIP Route Configuration
Juniper JNCIA – Juniper RIP Route ConfigurationJuniper JNCIA – Juniper RIP Route Configuration
Juniper JNCIA – Juniper RIP Route ConfigurationHamed Moghaddam
 
Cisco CCNA- How to Configure Multi-Layer Switch
Cisco CCNA- How to Configure Multi-Layer SwitchCisco CCNA- How to Configure Multi-Layer Switch
Cisco CCNA- How to Configure Multi-Layer SwitchHamed Moghaddam
 
Juniper JNCIA – Juniper Floating Static Route Configuration
Juniper JNCIA – Juniper Floating Static Route ConfigurationJuniper JNCIA – Juniper Floating Static Route Configuration
Juniper JNCIA – Juniper Floating Static Route ConfigurationHamed Moghaddam
 
Cisco CCNA EIGRP IPV6 Configuration
Cisco CCNA EIGRP IPV6 ConfigurationCisco CCNA EIGRP IPV6 Configuration
Cisco CCNA EIGRP IPV6 ConfigurationHamed Moghaddam
 
Juniper JNCIA – Juniper OSPF Route Configuration
Juniper JNCIA – Juniper OSPF Route ConfigurationJuniper JNCIA – Juniper OSPF Route Configuration
Juniper JNCIA – Juniper OSPF Route ConfigurationHamed Moghaddam
 
Cisco CCNA-CCNP IP SLA Configuration
Cisco CCNA-CCNP IP SLA ConfigurationCisco CCNA-CCNP IP SLA Configuration
Cisco CCNA-CCNP IP SLA ConfigurationHamed Moghaddam
 
Microsoft MCSA - Install active directory domain services (adds) role
Microsoft MCSA - Install active directory domain services (adds) roleMicrosoft MCSA - Install active directory domain services (adds) role
Microsoft MCSA - Install active directory domain services (adds) roleHamed Moghaddam
 
Cisco CCNA CCNP VACL Configuration
Cisco CCNA CCNP VACL ConfigurationCisco CCNA CCNP VACL Configuration
Cisco CCNA CCNP VACL ConfigurationHamed Moghaddam
 
Juniper JNCIA – Juniper RIP and OSPF Route Configuration
Juniper JNCIA – Juniper RIP and OSPF Route ConfigurationJuniper JNCIA – Juniper RIP and OSPF Route Configuration
Juniper JNCIA – Juniper RIP and OSPF Route ConfigurationHamed Moghaddam
 
Cisco CCNA IP SLA with tracking configuration
Cisco CCNA IP SLA  with tracking  configurationCisco CCNA IP SLA  with tracking  configuration
Cisco CCNA IP SLA with tracking configurationHamed Moghaddam
 
Cisco CCNA Port Security
Cisco CCNA Port SecurityCisco CCNA Port Security
Cisco CCNA Port SecurityHamed Moghaddam
 
Cisco CCNA IPV6 Static Configuration
Cisco CCNA  IPV6 Static ConfigurationCisco CCNA  IPV6 Static Configuration
Cisco CCNA IPV6 Static ConfigurationHamed Moghaddam
 
Cisco CCNA OSPF IPV6 Configuration
Cisco CCNA OSPF IPV6 ConfigurationCisco CCNA OSPF IPV6 Configuration
Cisco CCNA OSPF IPV6 ConfigurationHamed Moghaddam
 

Destaque (13)

Juniper JNCIA – Juniper RIP Route Configuration
Juniper JNCIA – Juniper RIP Route ConfigurationJuniper JNCIA – Juniper RIP Route Configuration
Juniper JNCIA – Juniper RIP Route Configuration
 
Cisco CCNA- How to Configure Multi-Layer Switch
Cisco CCNA- How to Configure Multi-Layer SwitchCisco CCNA- How to Configure Multi-Layer Switch
Cisco CCNA- How to Configure Multi-Layer Switch
 
Juniper JNCIA – Juniper Floating Static Route Configuration
Juniper JNCIA – Juniper Floating Static Route ConfigurationJuniper JNCIA – Juniper Floating Static Route Configuration
Juniper JNCIA – Juniper Floating Static Route Configuration
 
Cisco CCNA EIGRP IPV6 Configuration
Cisco CCNA EIGRP IPV6 ConfigurationCisco CCNA EIGRP IPV6 Configuration
Cisco CCNA EIGRP IPV6 Configuration
 
Juniper JNCIA – Juniper OSPF Route Configuration
Juniper JNCIA – Juniper OSPF Route ConfigurationJuniper JNCIA – Juniper OSPF Route Configuration
Juniper JNCIA – Juniper OSPF Route Configuration
 
Cisco CCNA-CCNP IP SLA Configuration
Cisco CCNA-CCNP IP SLA ConfigurationCisco CCNA-CCNP IP SLA Configuration
Cisco CCNA-CCNP IP SLA Configuration
 
Microsoft MCSA - Install active directory domain services (adds) role
Microsoft MCSA - Install active directory domain services (adds) roleMicrosoft MCSA - Install active directory domain services (adds) role
Microsoft MCSA - Install active directory domain services (adds) role
 
Cisco CCNA CCNP VACL Configuration
Cisco CCNA CCNP VACL ConfigurationCisco CCNA CCNP VACL Configuration
Cisco CCNA CCNP VACL Configuration
 
Juniper JNCIA – Juniper RIP and OSPF Route Configuration
Juniper JNCIA – Juniper RIP and OSPF Route ConfigurationJuniper JNCIA – Juniper RIP and OSPF Route Configuration
Juniper JNCIA – Juniper RIP and OSPF Route Configuration
 
Cisco CCNA IP SLA with tracking configuration
Cisco CCNA IP SLA  with tracking  configurationCisco CCNA IP SLA  with tracking  configuration
Cisco CCNA IP SLA with tracking configuration
 
Cisco CCNA Port Security
Cisco CCNA Port SecurityCisco CCNA Port Security
Cisco CCNA Port Security
 
Cisco CCNA IPV6 Static Configuration
Cisco CCNA  IPV6 Static ConfigurationCisco CCNA  IPV6 Static Configuration
Cisco CCNA IPV6 Static Configuration
 
Cisco CCNA OSPF IPV6 Configuration
Cisco CCNA OSPF IPV6 ConfigurationCisco CCNA OSPF IPV6 Configuration
Cisco CCNA OSPF IPV6 Configuration
 

Semelhante a Cisco CCNA- NAT Configuration

Aula04 - configuração da topologia ppp - resolvido
Aula04 -  configuração da topologia ppp - resolvidoAula04 -  configuração da topologia ppp - resolvido
Aula04 - configuração da topologia ppp - resolvidoCarlos Veiga
 
Chapter11ccna
Chapter11ccnaChapter11ccna
Chapter11ccnarobertoxe
 
Cisco CCNA-Standard Access List
Cisco CCNA-Standard Access ListCisco CCNA-Standard Access List
Cisco CCNA-Standard Access ListHamed Moghaddam
 
CCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docx
CCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docxCCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docx
CCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docxketurahhazelhurst
 
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docxAll contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docxgalerussel59292
 
Detailed explanation of Basic router configuration
Detailed explanation of Basic router configurationDetailed explanation of Basic router configuration
Detailed explanation of Basic router configurationsamreenghauri786
 
Cisco CCNA-Router on Stick
Cisco CCNA-Router on StickCisco CCNA-Router on Stick
Cisco CCNA-Router on StickHamed Moghaddam
 
Packet-tracer---troubleshoot-connectivity-issues
Packet-tracer---troubleshoot-connectivity-issuesPacket-tracer---troubleshoot-connectivity-issues
Packet-tracer---troubleshoot-connectivity-issuesRanghel Soto Espinoza
 

Semelhante a Cisco CCNA- NAT Configuration (20)

N at
N atN at
N at
 
Cisco CCNA- DHCP Server
Cisco CCNA-  DHCP ServerCisco CCNA-  DHCP Server
Cisco CCNA- DHCP Server
 
Aula04 - configuração da topologia ppp - resolvido
Aula04 -  configuração da topologia ppp - resolvidoAula04 -  configuração da topologia ppp - resolvido
Aula04 - configuração da topologia ppp - resolvido
 
Chapter11ccna
Chapter11ccnaChapter11ccna
Chapter11ccna
 
Chapter11ccna
Chapter11ccnaChapter11ccna
Chapter11ccna
 
Cisco CCNA-Standard Access List
Cisco CCNA-Standard Access ListCisco CCNA-Standard Access List
Cisco CCNA-Standard Access List
 
Frame Relay (Multipoint)
Frame Relay (Multipoint)Frame Relay (Multipoint)
Frame Relay (Multipoint)
 
CCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docx
CCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docxCCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docx
CCNA Connecting NetworksSA ExamLab 13 CCNA Connecting Netwo.docx
 
Samplab19
Samplab19Samplab19
Samplab19
 
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docxAll contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
 
Detailed explanation of Basic router configuration
Detailed explanation of Basic router configurationDetailed explanation of Basic router configuration
Detailed explanation of Basic router configuration
 
Day 17.1 nat pat
Day 17.1 nat pat Day 17.1 nat pat
Day 17.1 nat pat
 
Day 17.1 nat pat (2)
Day 17.1 nat pat  (2)Day 17.1 nat pat  (2)
Day 17.1 nat pat (2)
 
Cisco CCNA-Router on Stick
Cisco CCNA-Router on StickCisco CCNA-Router on Stick
Cisco CCNA-Router on Stick
 
Nat 03
Nat 03Nat 03
Nat 03
 
Packet-tracer---troubleshoot-connectivity-issues
Packet-tracer---troubleshoot-connectivity-issuesPacket-tracer---troubleshoot-connectivity-issues
Packet-tracer---troubleshoot-connectivity-issues
 
Nat 07
Nat 07Nat 07
Nat 07
 
Networking
NetworkingNetworking
Networking
 
BACIK CISCO SKILLS
BACIK CISCO SKILLSBACIK CISCO SKILLS
BACIK CISCO SKILLS
 
Nat
NatNat
Nat
 

Mais de Hamed Moghaddam

Cisco CCNA GRE Tunnel Configuration
Cisco CCNA GRE Tunnel ConfigurationCisco CCNA GRE Tunnel Configuration
Cisco CCNA GRE Tunnel ConfigurationHamed Moghaddam
 
Cisco CCNA- PPP Multilink Configuration
Cisco CCNA- PPP Multilink ConfigurationCisco CCNA- PPP Multilink Configuration
Cisco CCNA- PPP Multilink ConfigurationHamed Moghaddam
 
CISSP Certification Security Engineering-Part2
CISSP Certification Security Engineering-Part2CISSP Certification Security Engineering-Part2
CISSP Certification Security Engineering-Part2Hamed Moghaddam
 
CISSP Certification- Security Engineering-part1
CISSP Certification- Security Engineering-part1CISSP Certification- Security Engineering-part1
CISSP Certification- Security Engineering-part1Hamed Moghaddam
 
Microsoft MCSA- Joining Client Machines To The Domain!
Microsoft MCSA- Joining Client Machines To The Domain!Microsoft MCSA- Joining Client Machines To The Domain!
Microsoft MCSA- Joining Client Machines To The Domain!Hamed Moghaddam
 
CISSP Certification-Asset Security
CISSP Certification-Asset SecurityCISSP Certification-Asset Security
CISSP Certification-Asset SecurityHamed Moghaddam
 
Cissp- Security and Risk Management
Cissp- Security and Risk ManagementCissp- Security and Risk Management
Cissp- Security and Risk ManagementHamed Moghaddam
 

Mais de Hamed Moghaddam (8)

Cisco CCNA GRE Tunnel Configuration
Cisco CCNA GRE Tunnel ConfigurationCisco CCNA GRE Tunnel Configuration
Cisco CCNA GRE Tunnel Configuration
 
Cisco CCNA- PPP Multilink Configuration
Cisco CCNA- PPP Multilink ConfigurationCisco CCNA- PPP Multilink Configuration
Cisco CCNA- PPP Multilink Configuration
 
CISSP Certification Security Engineering-Part2
CISSP Certification Security Engineering-Part2CISSP Certification Security Engineering-Part2
CISSP Certification Security Engineering-Part2
 
CISSP Certification- Security Engineering-part1
CISSP Certification- Security Engineering-part1CISSP Certification- Security Engineering-part1
CISSP Certification- Security Engineering-part1
 
Microsoft MCSA- Joining Client Machines To The Domain!
Microsoft MCSA- Joining Client Machines To The Domain!Microsoft MCSA- Joining Client Machines To The Domain!
Microsoft MCSA- Joining Client Machines To The Domain!
 
CISSP Certification-Asset Security
CISSP Certification-Asset SecurityCISSP Certification-Asset Security
CISSP Certification-Asset Security
 
Cissp- Security and Risk Management
Cissp- Security and Risk ManagementCissp- Security and Risk Management
Cissp- Security and Risk Management
 
Become CISSP Certified
Become CISSP CertifiedBecome CISSP Certified
Become CISSP Certified
 

Último

Dust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSEDust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSEaurabinda banchhor
 
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfErwinPantujan2
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Celine George
 
Measures of Position DECILES for ungrouped data
Measures of Position DECILES for ungrouped dataMeasures of Position DECILES for ungrouped data
Measures of Position DECILES for ungrouped dataBabyAnnMotar
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parentsnavabharathschool99
 
Concurrency Control in Database Management system
Concurrency Control in Database Management systemConcurrency Control in Database Management system
Concurrency Control in Database Management systemChristalin Nelson
 
Presentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptxPresentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptxRosabel UA
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfJemuel Francisco
 
Activity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationActivity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationRosabel UA
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPCeline George
 
Textual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSTextual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSMae Pangan
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptxmary850239
 
EMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxEMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxElton John Embodo
 
TEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docxTEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docxruthvilladarez
 
4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptx4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptxmary850239
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 

Último (20)

Dust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSEDust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSE
 
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
 
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptxFINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
 
Measures of Position DECILES for ungrouped data
Measures of Position DECILES for ungrouped dataMeasures of Position DECILES for ungrouped data
Measures of Position DECILES for ungrouped data
 
Paradigm shift in nursing research by RS MEHTA
Paradigm shift in nursing research by RS MEHTAParadigm shift in nursing research by RS MEHTA
Paradigm shift in nursing research by RS MEHTA
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parents
 
Concurrency Control in Database Management system
Concurrency Control in Database Management systemConcurrency Control in Database Management system
Concurrency Control in Database Management system
 
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptxYOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
 
Presentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptxPresentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptx
 
INCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptx
INCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptxINCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptx
INCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptx
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
 
Activity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationActivity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translation
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERP
 
Textual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSTextual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHS
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx
 
EMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxEMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docx
 
TEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docxTEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docx
 
4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptx4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptx
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 

Cisco CCNA- NAT Configuration

  • 1. CISCO CCNA NAT CONFIGURATION TO WATCH OUR CISCO CCNA VIDEO TRAININGS PLEASE CHECK OUT THE LINK BELOW: WWW.ASMED.COM/C1 ASM EDUCATIONAL CENTER INC. (ASM) WHERE TRAINING, TECHNOLOGY & SERVICE CONVERGE PHONE: (301) 984-7400 ROCKVILLE,MD
  • 2. CISCO CCNA NAT CONFIGURATION
  • 3. CISCO CCNA NAT CONFIGURATION NAT = NETWORK ADDRESS TRANSLATION REMEMBER THE PRIVATE IP ADDRESS 10.0.0.0 — 10.255.255.255 172.16.0.0 —-172.31.255.255 192.168.0.0.—– 192.168.255.255 THE GOAL IS TO CONVERT YOUR PRIVATE IP ADDRESS TO PUBLIC ADDRESS SO THAT YOUR INTERNAL PEOPLE CAN ACCESS THE INTERNET
  • 4. CISCO CCNA NAT CONFIGURATION I HAVE 2 KIND: 1) DYNAMIC NAT – USE IT WHEN YOU NEED YOUR PRIVATE NETWORK GO OUT TO INTERNET – IT HAS TWO KIND SUPPOSE I HAVE 6 PRIVATE AND THEN ISP GIVE YOU 6 PUBLIC THEN ALL SIX PEOPLE GO TO INTERNET SUPPOSE I HAVE 62 PRIVATE AND ISP ONLY GIVE YOU 6 PUBLIC IN THIS CASE ; YOU MUST USE THE KEY WORD “OVERLOAD” ; THIS CONCEPT IS CALL PAT (PORT ADDRESS TRANSLATION) 2) STATIC NAT – USE IT WHEN YOU NEED THE INTERNET PEOPLE COME TO YOUR WEBSERVER; THAT IS LOCATED IN PRIVATE LAN =10.10.10.1; IN THIS CASE YOU NEED TO USE STATIC NAT
  • 5. CISCO CCNA NAT CONFIGURATION HERE IS MY LAB ON NAT/PAT: GIVEN BY ISP 6 PUBLIC ADDRESS 198.18.151.97 .98, .99,100,101,102 WITH SUBNET MASK /29 /29=255.255.255.248 .11111000 AND I HAVE 62 INTERNAL IP ADDRESS THAT NEED TO GO TO INTERNET 192.168.91.65—192.168.91.126 WITH MASK /26 255.255.255.192 .11000000
  • 6. CISCO CCNA NAT CONFIGURATION STEP 1) DEFINE THE POOL OF INSIDE GLOBAL ADDRESS (PUBLIC ADDRESS) THAT INSIDE LOCAL ADDRESS WILL BE TRANSLATED TO: HINT: ALWAYS ALWAYS START WITH IP NAT? R1# R1#CONFIG T ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z. R1(CONFIG)#IP NAT ? INSIDE INSIDE ADDRESS TRANSLATION OUTSIDE OUTSIDE ADDRESS TRANSLATION POOL DEFINE POOL OF ADDRESSES R1(CONFIG)#IP NAT POO R1(CONFIG)#IP NAT POOL ? WORD POOL NAME R1(CONFIG)#IP NAT POOL CCNA ?
  • 7. CISCO CCNA NAT CONFIGURATION A.B.C.D START IP ADDRESS R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 ? A.B.C.D END IP ADDRESS R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 ? NETMASK SPECIFY THE NETWORK MASK R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NET R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK ? A.B.C.D NETWORK MASK R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 ? <CR> R1(CONFIG)#IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 R1(CONFIG)#
  • 8. CISCO CCNA NAT CONFIGURATION HERE IS MY SHOW RUN: IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 HINT: ANY TIME YOU SEE THE WORD POOL IT WILL TELL YOU; THAT IS PUBLIC IP ADDRESS STEP 2) DEFINE THE SOURCE OF THE INSIDE LOCAL ADDRESS AND BIND IT TO CCNA DEFINED IN PART 1 HINT: IP NAT? R1# R1# R1#CONFIG T ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z. R1(CONFIG)#IP NAT ? INSIDE INSIDE ADDRESS TRANSLATION OUTSIDE OUTSIDE ADDRESS TRANSLATION POOL DEFINE POOL OF ADDRESSES R1(CONFIG)#IP NAT % INCOMPLETE COMMAND. R1(CONFIG)#IP NAT INS R1(CONFIG)#IP NAT INSIDE ? SOURCE SOURCE ADDRESS TRANSLATION
  • 9. CISCO CCNA NAT CONFIGURATION R1(CONFIG)#IP NAT INSIDE SOU R1(CONFIG)#IP NAT INSIDE SOURCE ? LIST SPECIFY ACCESS LIST DESCRIBING LOCAL ADDRESSES STATIC SPECIFY STATIC LOCAL->GLOBAL MAPPING R1(CONFIG)#IP NAT INSIDE SOURCE LIST ? <1-199> ACCESS LIST NUMBER FOR LOCAL ADDRESSES WORD ACCESS LIST NAME FOR LOCAL ADDRESSES R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 ? INTERFACE SPECIFY INTERFACE FOR GLOBAL ADDRESS POOL NAME POOL OF GLOBAL ADDRESSES R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POO R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL ? WORD NAME POOL OF GLOBAL ADDRESSES R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA ? OVERLOAD OVERLOAD AN ADDRESS TRANSLATION <CR> R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVE R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD ? <CR> R1(CONFIG)#IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD
  • 10. CISCO CCNA NAT CONFIGURATION HINT: IF ISP HAS GIVEN YOU A SINGLE IP ADDRESS AFTER LIST 1 ? I WILL USE INTERFACE S0/0 HINT: WHEN YOU SEE THE WORD LIST THAT SHOULD TELL YOU ; I NEED TO HAVE ACL 1 THAT WILL DEFINE MY LOCAL ADDRESS STEP 3) NOW DEFINE YOU ACL 1 HINT: I HAVE /26 255.255.255.255- 255.255.255.192 ————– 0.0.0.63 AS WILD CARDS R1(CONFIG )# ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63 SUBNET ID WILD CARDS
  • 11. CISCO CCNA NAT CONFIGURATION R1(CONFIG)# R1(CONFIG)#ACC R1(CONFIG)#ACCESS-LIST ? <1-99> IP STANDARD ACCESS LIST <100-199> IP EXTENDED ACCESS LIST R1(CONFIG)#ACCESS-LIST 1 ? DENY SPECIFY PACKETS TO REJECT PERMIT SPECIFY PACKETS TO FORWARD REMARK ACCESS LIST ENTRY COMMENT R1(CONFIG)#ACCESS-LIST 1 PERMI R1(CONFIG)#ACCESS-LIST 1 PERMIT ? A.B.C.D ADDRESS TO MATCH ANY ANY SOURCE HOST HOST A SINGLE HOST ADDRESS R1(CONFIG)#ACCESS-LIST 1 PERMIT 192.168.91.69 0.0.0.63
  • 12. CISCO CCNA NAT CONFIGURATION HERE I INTENTIONALLY PUT WRONG SUBNET ID; BUT IOS WILL FIX IT FOR ME: HERE IS MY SHOW RUN: IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD IP CLASSLESS ! ! ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63 STEP 4) TELL ROUTER WHICH SIDE IS INSIDE AND WHICH SIDE IS OUTSIDE AND MAKE SURE BE UNDER INTERFACE AND GIVE: INT F0/0 IP NAT INSIDE INT S0/0 IP NAT OUTSIDE
  • 13. CISCO CCNA NAT CONFIGURATION R1#CONFIG T ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z. R1(CONFIG)#INT F0/0 R1(CONFIG-IF)#IP NAT R1(CONFIG-IF)#IP NAT ? INSIDE INSIDE INTERFACE FOR ADDRESS TRANSLATION OUTSIDE OUTSIDE INTERFACE FOR ADDRESS TRANSLATION R1(CONFIG-IF)#IP NAT INS R1(CONFIG-IF)#IP NAT INSIDE R1(CONFIG-IF)# R1(CONFIG-IF)# R1(CONFIG-IF)#INT S0/0 R1(CONFIG-IF)#IP NAT ? INSIDE INSIDE INTERFACE FOR ADDRESS TRANSLATION OUTSIDE OUTSIDE INTERFACE FOR ADDRESS TRANSLATION R1(CONFIG-IF)#IP NAT OUT R1(CONFIG-IF)#IP NAT OUTSIDE
  • 14. CISCO CCNA NAT CONFIGURATION NOW LET’S LOOK AT SHOW RUN: INTERFACE FASTETHERNET0/0 IP ADDRESS 192.168.91.126 255.255.255.192 IP NAT INSIDE DUPLEX AUTO SPEED AUTO ! ! INTERFACE SERIAL0/0 IP ADDRESS 192.0.1.109 255.255.255.252 IP NAT OUTSIDE CLOCK RATE 64000 IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD IP CLASSLESS ! ! ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63 LAST TWO STEPS IS DONE TO CHECK AND MAKE SURE LIFE IS GOOD;
  • 15. CISCO CCNA NAT CONFIGURATION STEP 5) MAKE SURE YOUR ROUTER HAS A DEFAULT ROUTE TO ISP. R1#CONFIG T ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z. R1(CONFIG)# R1(CONFIG)#IP ROUTE 0.0.0.0 0.0.0.0 ? A.B.C.D FORWARDING ROUTER’S ADDRESS ETHERNET IEEE 802.3 FASTETHERNET FASTETHERNET IEEE 802.3 GIGABITETHERNET GIGABITETHERNET IEEE 802.3Z LOOPBACK LOOPBACK INTERFACE NULL NULL INTERFACE SERIAL SERIAL R1(CONFIG)#IP ROUTE 0.0.0.0 0.0.0.0 192.0.1.110
  • 16. CISCO CCNA NAT CONFIGURATION STEP 6) MAKE SURE ISP KNOWS YOUR NETWORK; SO ISP WILL NEED A STATIC ROUTE BACK TO YOUR NETWORK ISP# ISP#CONFIG T ENTER CONFIGURATION COMMANDS, ONE PER LINE. END WITH CNTL/Z. ISP(CONFIG)#IP ROUTE ? A.B.C.D DESTINATION PREFIX ISP(CONFIG)#IP ROUTE 198.18.151.96 ? A.B.C.D DESTINATION PREFIX MASK ISP(CONFIG)#IP ROUTE 198.18.151.96 255.255.255.248 ? A.B.C.D FORWARDING ROUTER’S ADDRESS ETHERNET IEEE 802.3 FASTETHERNET FASTETHERNET IEEE 802.3 GIGABITETHERNET GIGABITETHERNET IEEE 802.3Z LOOPBACK LOOPBACK INTERFACE NULL NULL INTERFACE SERIAL SERIAL ISP(CONFIG)#IP ROUTE 198.18.151.96 255.255.255.248 S0/0 ISP(CONFIG)#
  • 17. CISCO CCNA NAT CONFIGURATION AS WE SEE FOR ISP MAKE SURE YOU USE THE PUBLIC ADDRESS NOT PRIVATE; SNICE ISP DOES NOT KNOW YOUR PRIVATE IP ADDRESS NOW I GO AND CHECK THE PING FROM PC TO INTERNET; THEN I GO TO R1#SHOW IP NAT TRANSLATION ! PC> PC>PING 192.0.1.110 PINGING 192.0.1.110 WITH 32 BYTES OF DATA: REPLY FROM 192.0.1.110: BYTES=32 TIME=13MS TTL=254 REPLY FROM 192.0.1.110: BYTES=32 TIME=15MS TTL=254 REPLY FROM 192.0.1.110: BYTES=32 TIME=11MS TTL=254 REPLY FROM 192.0.1.110: BYTES=32 TIME=12MS TTL=254 PING STATISTICS FOR 192.0.1.110: PACKETS: SENT = 4, RECEIVED = 4, LOST = 0 (0% LOSS), APPROXIMATE ROUND TRIP TIMES IN MILLI-SECONDS: MINIMUM = 11MS, MAXIMUM = 15MS, AVERAGE = 12MS
  • 18. CISCO CCNA NAT CONFIGURATION R1#SHOW IP NAT TRANSLATIONS PRO INSIDE GLOBAL INSIDE LOCAL OUTSIDE LOCAL OUTSIDE GLOBAL ICMP 198.18.151.97:10 192.168.91.65:10 192.0.1.110:10 192.0.1.110:10 ICMP 198.18.151.97:11 192.168.91.65:11 192.0.1.110:11 192.0.1.110:11 ICMP 198.18.151.97:12 192.168.91.65:12 192.0.1.110:12 192.0.1.110:12 ICMP 198.18.151.97:9 192.168.91.65:9 192.0.1.110:9 192.0.1.110:9
  • 19. CISCO CCNA NAT CONFIGURATION HERE IS THE SUMMARY: INTERFACE FASTETHERNET0/0 IP ADDRESS 192.168.91.126 255.255.255.192 IP NAT INSIDE DUPLEX AUTO SPEED AUTO ! INTERFACE SERIAL0/0 IP ADDRESS 192.0.1.109 255.255.255.252 IP NAT OUTSIDE CLOCK RATE 64000 ! IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD IP CLASSLESS IP ROUTE 0.0.0.0 0.0.0.0 192.0.1.110 ! ! ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63 !
  • 20. CISCO CCNA NAT CONFIGURATION HINT: IF ISP HAS GIVEN YOU SINGLE IP ADDRESS THEN YOU DO NOT NEED THE POOL STATEMENT ( THE 1ST STATEMENT) ; AND ALSO YOUR 2ND STATMENT WILL BE LIKE THIS IP NAT INSIDE SOURCE LIST 1 INT S0/0 OVERLOAD NOW IF I ADD ANOTHER LAN (10.10.10.0/24) USING MY INT F0/1 MAKE SURE YOU HAVE DEFINE ACL FOR NETWORK 10.10.10.0 /24 TO GO OUT AND MAKE SURE YOUR APPLY TO INT F0/1 WITH COMMAND IP NAT INSIDE INTERFACE FASTETHERNET0/0 IP ADDRESS 192.168.91.126 255.255.255.192 IP NAT INSIDE DUPLEX AUTO SPEED AUTO !
  • 21. CISCO CCNA NAT CONFIGURATION INTERFACE FASTETHERNET0/1 IP ADDRESS 10.10.10.100 255.255.255.0 IP NAT INSIDE ( PLEASE ADD THIS) DUPLEX AUTO SPEED AUTO ! INTERFACE SERIAL0/0 IP ADDRESS 192.0.1.109 255.255.255.252 IP NAT OUTSIDE CLOCK RATE 64000 !
  • 22. CISCO CCNA NAT CONFIGURATION IP NAT POOL CCNA 198.18.151.97 198.18.151.102 NETMASK 255.255.255.248 IP NAT INSIDE SOURCE LIST 1 POOL CCNA OVERLOAD IP CLASSLESS IP ROUTE 0.0.0.0 0.0.0.0 192.0.1.110 ! ! ACCESS-LIST 1 PERMIT 192.168.91.64 0.0.0.63 ACCESS-LIST 1 PERMIT 10.10.10.0 0.0.0.255 (PLEASE ADD THIS LINE) !
  • 23. ASM EDUCATIONAL CENTER INC. (ASM) WHERE TRAINING, TECHNOLOGY & SERVICE CONVERGE TO WATCH OUR CISCO CCNA VIDEO TRAININGS PLEASE CHECK OUT THE LINK BELOW: WWW.ASMED.COM/C1 PHONE: (301) 984-7400 ROCKVILLE,MD