© 2002, Cisco Systems, Inc. All rights reserved..

Slides:



Advertisements
Similar presentations
CST Computer Networks NAT CST 415 4/10/2017 CST Computer Networks.
Advertisements

© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 W. Schulte Chapter 5: Network Address Translation for IPv4  Connecting.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Lecture15: Network Address Translation for IPv4 Connecting Networks.
© 2007 Cisco Systems, Inc. All rights reserved.ICND1 v1.0—5-1 WAN Connections Enabling the Internet Connection.
Ch. 1 – Scaling IP Addresses NAT/PAT and DHCP CCNA 4 version 3.0.
Ch. 1 – Scaling IP Addresses NAT/PAT and DHCP
© 2002, Cisco Systems, Inc. All rights reserved..
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—4-1 Managing IP Traffic with ACLs Scaling the Network with NAT and PAT.
M. Dahshan - TCOM52721 TCOM 5272 Telecomm Lab Dr. Mostafa Dahshan OU-Tulsa 4W 2 nd floor
Sybex CCNA Chapter 11: Network Address Translation Instructor & Todd Lammle.
© 2003, Cisco Systems, Inc. All rights reserved. ICND v2.1—4-1 © 2003, Cisco Systems, Inc. All rights reserved. 1 Scaling the Network with NAT and PAT.
CCNA Guide to Cisco Networking Fundamentals Fourth Edition Chapter 9 Network Services.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 CCNA 5.0 Planning Guide Chapter 5: Network Address Translation for IPv4.
Lecture Week 7 Implementing IP Addressing Services.
Sybex CCENT Chapter 13: Network Address Translation Instructor & Todd Lammle.
© 2007 Cisco Systems, Inc. All rights reserved.ICND2 v1.0—7-1 Address Space Management Scaling the Network with NAT and PAT.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 4: Addressing in an Enterprise Network Introducing Routing and Switching in the.
CN2668 Routers and Switches Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Network Address Translation
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 4 v3.0 Module 1 Scaling IP Addresses.
NAT (Network Address Translation) Natting means "Translation of private IP address into public IP address ". In order to communicate with internet we must.
NAT 강사 김성훈.
CCNA Guide to Cisco Networking Chapter 8: Routing Protocols and Network Address Translation.
© 2002, Cisco Systems, Inc. All rights reserved..
Page 1 NAT & VPN Lecture 8 Hassan Shuja 05/02/2006.
Introduction to Network Address Translation
Implementing IP Addressing Services Accessing the WAN – Chapter 7.
Network Address Translations Project no. : 12 Prof. Edmund Gean Presented by DhruvaPatel( ) Sweta Patel( ) Rushika Patel ( ) Guided.
S6C11 - NAT Network Security Translation. NAT Described Globally unique ONLY in terms of public internet –Translates private addresses into publicly usable.
© 2002, Cisco Systems, Inc. All rights reserved..
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 4: Addressing in an Enterprise Network Introducing Routing and Switching in the.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Planning the Addressing Structure Working at a Small-to-Medium Business.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
Instructor & Todd Lammle
© 2002, Cisco Systems, Inc. All rights reserved. 1 Routing Overview.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 4 v3.1 Module 1 Scaling IP Addresses.
CCNA 4 v3.1 Module 1 Scaling IP Addresses
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 11: Network Address Translation for IPv4 Routing And Switching.
Configuring NAT and PAT Chapter 18 powered by DJ 1.
1 © 2004, Cisco Systems, Inc. All rights reserved. Scaling IP Addresses Network Address Translation(NAT)
Scaling Networks with Network Address Translation Scaling Networks with Network Address Translation Solutions for IPv4 Security and Scalability ECPI College.
NAT & PAT Network Address Translation Port Address Translation.
N ETWORK S ECURITY Network Address Translation. C ONTENTS What is NAT NAT Terminology How NAT works NAT translation Dynamic, static and overloading Advantages.
NAT/PAT by S K SATAPATHY
© 2002, Cisco Systems, Inc. All rights reserved..
© 2002, Cisco Systems, Inc. All rights reserved..
1 Pertemuan 14 Scaling Networks with NAT and PAT.
CCNA4-1 Chapter 7-1 IP Addressing Services Scaling Networks With Network Address Translation (NAT)
Configuring NAT. Configuring Static NAT There are two basic tasks to perform when configuring static NAT translations: Create the mapping between the.
© 2001, Cisco Systems, Inc. CSPFA 2.0—5-1 Chapter 5 Cisco PIX Firewall Translations.
CCNA4-1 Chapter 7-1 NAT Chapter 11 Routing and Switching (CCNA2)
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
Network Address Translation (NAT)
© 2002, Cisco Systems, Inc. All rights reserved.
Chapter 13 Network Address Translation
Only Two Ways through the PIX Firewall
Instructor Materials Chapter 9: NAT for IPv4
NAT / PAT.
Routing and Switching Essentials v6.0
Implementing IP Addressing Services
CIS 82 Routing Protocols and Concepts Chapter 11 NAT
Routing and Switching Essentials v6.0
NAT / PAT.
Cabrillo College Building Cisco Remote Access Network
Instructor Materials Chapter 9: NAT for IPv4
Implementing IP Addressing Services
Chapter 11: Network Address Translation for IPv4
Prepared by :Adeel Ahmad
Sybex CCNA Chapter 11: Network Address Translation.
Presentation transcript:

© 2002, Cisco Systems, Inc. All rights reserved.

ICND v2.0—6-2 © 2002, Cisco Systems, Inc. All rights reserved. 2 Scaling the Network with NAT and PAT

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-3 Objectives Upon completing this lesson, you will be able to: Describe the features and operation of NAT on Cisco routers Use Cisco IOS commands to configure NAT, given a functioning router Use show commands to identify anomalies in the NAT configuration, given an operational router Use debug commands to identify events and anomalies in the NAT configuration, given an operational router

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-4 Network Address Translation An IP address is either local or global. Local IP addresses are seen in the inside network.

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-5 Port Address Translation

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-6 Translating Inside Source Addresses

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-7 Configuring Static Translation Establishes static translation between an inside local address and an inside global address Router(config)#ip nat inside source static local-ip global-ip Marks the interface as connected to the inside Router(config-if)#ip nat inside Marks the interface as connected to the outside Router(config-if)#ip nat outside

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-8 Enabling Static NAT Address Mapping Example

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-9 Configuring Dynamic Translation Establishes dynamic source translation, specifying the access list defined in the prior step Router(config)#ip nat inside source list access-list-number pool name Defines a pool of global addresses to be allocated as needed Router(config)#ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length} Defines a standard IP access list permitting those inside local addresses that are to be translated Router(config)#access-list access-list-number permit source [source-wildcard]

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-10 Dynamic Address Translation Example

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-11 Overloading an Inside Global Address

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-12 Configuring Overloading Establishes dynamic source translation, specifying the access list defined in the prior step Router(config)#ip nat inside source list access-list-number interface interface overload Defines a standard IP access list permitting those inside local addresses that are to be translated Router(config)#access-list access-list-number permit source source-wildcard

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-13 Overloading an Inside Global Address Example

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-14 Clearing the NAT Translation Table Clears a simple dynamic translation entry containing an inside translation, or both inside and outside translation Router#clear ip nat translation inside global-ip local-ip [outside local-ip global-ip] Clears all dynamic address translation entries Router#clear ip nat translation * Clears a simple dynamic translation entry containing an outside translation Router#clear ip nat translation outside local-ip global-ip Clears an extended dynamic translation entry Router#clear ip nat translation protocol inside global-ip global-port local-ip local-port [outside local-ip local-port global-ip global-port]

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-15 Displaying Information with show Commands Displays translation statistics Router#show ip nat statistics Displays active translations Router#show ip nat translations Router#show ip nat translation Pro Inside global Inside local Outside local Outside global Router#show ip nat statistics Total active translations: 1 (1 static, 0 dynamic; 0 extended) Outside interfaces: Ethernet0, Serial2.7 Inside interfaces: Ethernet1 Hits: 5 Misses: 0 …

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-16 Sample Problem: Cannot Ping Remote Host

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-17 Solution: New Configuration

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-18 Using the debug ip nat Command Router#debug ip nat NAT: s= > , d= [6825] NAT: s= , d= > [21852] NAT: s= > , d= [6826] NAT*: s= , d= > [23311] NAT*: s= > , d= [6827] NAT*: s= > , d= [6828] NAT*: s= , d= > [23313] NAT*: s= , d= > [23325]

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-19 Translation Not Installed in the Translation Table? Verify that: –The configuration is correct. –There are not any inbound access lists denying the packets from entering the NAT router. –The access list referenced by the NAT command is permitting all necessary networks. –There are enough addresses in the NAT pool. –The router interfaces are appropriately defined as NAT inside or NAT outside.

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-20 Summary Cisco IOS NAT allows an organization with unregistered private addresses to connect to the Internet by translating those addresses into globally registered IP addresses. You can translate your own IP addresses into globally unique IP addresses when communicating outside of your network. Overloading is a form of dynamic NAT that maps multiple unregistered IP addresses to a single registered IP address (many-to-one) by using different ports, known also as PAT. Once you have configured NAT, verify that it is operating as expected using the clear and show commands. Sometimes NAT is blamed for IP connectivity problems when there is actually a routing problem.

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-21 Visual Objective 6-1: Configuring IP Access Lists WorkgroupWorkgroup Workgroup PodRouter s0Router e0Switch A B C D E F G H I J K L

© 2002, Cisco Systems, Inc. All rights reserved. ICND v2.0—6-22 Visual Objective 6-2: Configuring Port Address Translation WorkgroupWorkgroup Workgroup Pod Router s0Router e0Switch A B C D E F G H I J K L