当前位置:网站首页>第九章Cisco ASA应用NAT
第九章Cisco ASA应用NAT
2022-06-21 10:53:00 【邪痞】
一.NAT的类型
动态NAT,动态PAT,静态NAT,静态PAT
1.动态NAT:将一组IP地址转换为指定地址池中的IP地址
2.动态PAT:使用IP地址和源端口号创建一个唯一的会话
3.静态NAT:创建了一个从真实地址到映射地址的一对一的固定转换,可用于双向通信
4.静态PAT:与静态NAT类似,但是静态PAT允许为真实的映射地址指定TCP或UDP端口号
二.NAT控制
1.禁用NAT控制
动态NAT,动态PAT,静态NAT,静态就是在禁用NAT控制的情况下
禁用NAT控制的特性

(1).出站(Outbound)连接
如果NAT规则只允许网段10.1.1.0/24进行地址转换,则允许PC1出站连接并且进行地址转换。主机PC2发起连接不匹配NAT规则,但是允许PC2的出站连接,只是不进行地址转换
(2).入站(Inbound)连接
如果ASA没有配置静态NAT或静态PAT,则只要配置了ACL,主机PC4就可以访问PC3;如果ASA配置了静态NAT或静态PAT(当然要配置ACL),则主机PC4可以访问PC3并且进行地址转换
也就是说:在禁用NAT控制时,NAT规则并不是必需的
2.启用NAT控制
(1).出站(Outbound)连接
如果NAT规则只允许10.1.1.0/24网段进行地址转换,则允许PC1出站连接并且进行地址转换。主机PC2发起连接不匹配NAT规则,所以禁用PC2的出站连接
(2).入站(Inbound)连接
如果ASA没有配置静态NAT或静态PAT,则主机PC4就不能访问PC3,如果ASA配置了静态NAT或静态PAT(当然要配置ACL),则主机PC4可以访问PC3并且进行地址转换。
也就是说:在启用NAT控制时,NAT规则时必需的
三.NAT豁免
NAT豁免允许双向通信
边栏推荐
- [ZZ] OWT server: audio and video forwarding diagram
- Citus 11 for Postgres is completely open source and can be queried from any node (citus official blog)
- 启牛到底是用的什么证券开户?开户是哪家的安全吗
- How to learn function test? Ali engineer teaches 4 steps
- 15+城市道路要素分割应用,用这一个分割模型就够了!
- 年轻人不愿换手机,因选择了更耐用的iPhone,国产手机参数论失效
- The out of the box caching function of angular server-side rendering applications
- 一款完整开源的物联网基础平台
- Mythical games announced its cooperation with kakao games, a leading Korean game publisher, to promote business expansion in the Asia Pacific Region
- 国金证券开户安全吗?
猜你喜欢

Research and implementation of embedded software framework based on multi process architecture

06. Redis log: the trump card for fast recovery without fear of downtime

香农的信息论究竟牛在哪里?

The backbone of the top 100 security companies! Meichuang technology was selected into the 2022 China top 100 Digital Security Report

Mqtt of NLog custom target

Why does C throw exceptions when accessing null fields?

Prometheus flask exporter usage example

Matplotlib two methods of drawing torus!
![Fastapi web framework [pydantic]](/img/e1/290a8a6a978b9fb56a9c86f1734c45.png)
Fastapi web framework [pydantic]

The advanced process resistance of Intel and TSMC is increasing, and Chinese chips are expected to shorten the gap
随机推荐
Mythical games announced its cooperation with kakao games, a leading Korean game publisher, to promote business expansion in the Asia Pacific Region
Middle order traversal of leetcode-94-binary tree
Simple Android weather app (III) -- city management and database operation
K-means introduction
JobService的使用
[ZZ] OWT server: audio and video forwarding diagram
The "first city" in Central China. How can Changsha be built?
【obs】libobs_winrt.dll
Comparison between JWT and session
Is it safe for Guojin securities to open an account?
Where is the cow in Shannon's information theory?
3000帧动画图解MySQL为什么需要binlog、redo log和undo log
The more AI evolves, the more it resembles the human brain! Meta found the "prefrontal cortex" of the machine. AI scholars and neuroscientists were surprised
Why does C throw exceptions when accessing null fields?
Talk about the multimodal project of fire
移动应用开发学习通测试题答案
为什么 C# 访问 null 字段会抛异常?
New year's Eve, are you still changing the bug?
is not allowed to connect to this mysql server
05. Redis core chapter: the secret that can only be broken quickly