ͥåȥڥꥹ - SE̼η -

ͥåȥڥꥹȤλкȤǤͥåȥڥꥹȻι
̡ʤΥġ⡢μʤɤξǺܤޤкߥʡԤäƤޤ ͥåȥڥꥹ
кʤ麸κǤܤ֥ͥڡץ꡼ʵɾҡˤǡ
ͥåȥڥꥹȻ˹ʤȡͥåȥ˴ؤμ䵻ѤǤʤɲϤʸϤȤˤĤޤ
ˡλ˹ʤǤȤ뤳ȤǤޤ

ƥꡧ8.ͥåȥءL3 > 8.2 NAT

NATNetwork Address TranslationˤȤϡΥڥ뤬̣褦ˡͥåȥɥ쥹ѴǤ

2 

NATʤƻȤȤΤǤ
㤨С2Ĥ򤯤äĤơĤΥͥåȥˤȤޤɤ192.168.1.0/24ΥͥåȥǤIPɥ쥹νʣ̿Ǥޤ󡣤Ȥäơץ󥿤饵ФǡޤIPɥ쥹ѹΤ礬ȤޤΤȤˡɥ쥹Ѵ̿ФΤǤ
nat1
ǡR1R1³ưĤΥͥåȥΤݤˡߤ꤫ϡ㤦ɥ쥹˸ޤ
ͥåȥ172.16.1.0/24
ͥåȥ172.16.2.0/24
Τˡ롼R1Ǥϡ172.16.1.0/24192.168.1.0/24NAT롼R2Ǥ172.16.2.0/24192.168.1.0/24ΥͥåȥNATޤ
nat2

NATꤷƤߤ
ڹ
󥿡ͥåPC͡롼͡PCʤ䥵Фʤɡˤʣ
203.0.113.2203.0.113.1192.168.1.2
192.168.1.1
NATơ֥
192.168.1.210.1.1.2
192.168.1.310.1.1.3

뤳Ȥǡ192.168.1.0Υͥåȥ򡢳10.1.1.0/24Υͥåȥ˸뤳ȤǤ롣ФΤȤϡ10.1.1.0ʬƤ줿ХˤʤΤǤ

Config@1841
ݥȤȤʤConfig򵭺ܤޤ

interface FastEthernet0/0
 ip address 192.168.1.1 255.255.255.0
 ip nat inside

interface FastEthernet0/1
 ip address 203.0.113.1 255.255.255.0
 ip nat outside

ip nat inside source static 192.168.1.2 10.1.1.2
ip nat inside source static 192.168.1.3 10.1.1.3

NATơ֥
NATIPξĤϤʤΤǡʲˤʤ뤳Ȥ

Router#show ip nat translations
Pro Inside global      Inside local       Outside local      Outside global
--- 10.1.1.2           192.168.1.2        ---                ---
--- 10.1.1.3           192.168.1.3        ---                ---

ºݤˤϥݡֹݻƤ̤ˡݡֹѴƤ櫓ǤϤʤΤNATNAPTΰ㤤ʬꤺ餤ʤȡ

Router#show ip nat translations
Pro Inside global      Inside local       Outside local      Outside global
tcp 10.1.1.2:50663     192.168.1.2:50663  203.0.113.2:443    203.0.113.2:443
tcp 10.1.1.2:50664     192.168.1.2:50664  203.0.113.2:443    203.0.113.2:443
--- 10.1.1.2           192.168.1.2        ---                ---
tcp 10.1.1.3:52602     192.168.1.3:52602  203.0.113.2:443    203.0.113.2:443
tcp 10.1.1.3:52603     192.168.1.3:52603  203.0.113.2:443    203.0.113.2:443
tcp 10.1.1.3:52604     192.168.1.3:52604  203.0.113.2:443    203.0.113.2:443
tcp 10.1.1.3:52605     192.168.1.3:52605  203.0.113.2:443    203.0.113.2:443
tcp 10.1.1.3:52606     192.168.1.3:52606  203.0.113.2:443    203.0.113.2:443


NATλ⤦ľҲ𤷤ޤϤ褯㤫Ȼפޤ DMZθФǤƤΤǡХIPɥ쥹ɬפǤмΤˤϥץ饤١IPɥ쥹ơNAT뤳Ȥ褯ޤ
4

ʤȤ򤹤̣ϤΤǤ
ΤޤޥХIPɥ쥹ȤФȻפޤ
DMZˤͽФĶʤʣε郎³Ƥ礬ޤХIPɥ쥹ͭ¤ʤΤǡ餹٤Ƥ˥ХIPɥ쥹Ƥ뤳Ȥ񤷤ޤޤФDC˰ߤˡХIPɥ쥹ѤäˤǤФѹɬפʤNATѴǤߤޤ

ǤϡʲΥץʲ۴ĶNATͻҤǧ
3
ʲۡ˥󥿡ͥåȤ1.1.1.1ΥХIPɥ쥹̿򤷤ƤĤǤºݤˤFWNATơ172.16.1.1̿򤷤Ƥޤ NATΥѥåȤȡNATΥѥåȤʲ˵ܤޤƱNOǤIPɥ쥹ѴƤޤ

NATѴ
before


NATѴ
after

IPޥ졼ɤƱȡNAPTʤˤäƤϡNAT+ɽΤ⤢褦
ǤϤޤǡIPޥ졼ɤȤɽ¿äǶǤNAPTѲƤ롣Ƥ˽񤯤ȤϡIPޥ졼ɡפȤɽȤ鷺ɬNAPTȽ񤯤٤Ǥ롣

ǤϡNAPT˴ؤƼεҤ롣
TCPUDPΥݡֹ̤ץ饤١IPɥ쥹ȥХIPɥ쥹Ȥбط뤳Ȥˤäơץ饤١IPɥ쥹ѤLANʣüĤΥХIPɥ쥹ͭƥ󥿡ͥåȤ˥Ȥߡ
(H19NW 36)

NAPTơ֥񤤤Ƥߤ򤬿ޤȻפ

2011.10.30ɵ
NAPTϡƥ̤θ̤⤢롣H21AP9ǤϡNAPT˴ؤơ֥ХIPɥ쥹­äȤȤˡLANˤ뵡Υɥ쥹򱣤ڤȤ̤¸Ƥ롣פȽҤ٤Ƥ롣

ºݤˤϡݡֹϽʣ̵¤ꡢݡֹѴϤޤ
ȤСʲ

ʣIPɥ쥹顢ۤʤݡȤ̿ʰŪˤϤäˤʤˡIPɥ쥹Ȱݡֹ϶餯ʣ
192.168.1.10110001203.0.113.110001
192.168.1.10225002203.0.113.125002

ʣIPɥ쥹顢ʶˤƱݡȤ̿
192.168.1.10110001203.0.113.110001
192.168.1.10210001203.0.113.110002

-----------
ǤϡCisco롼NAPTäƤߤޤ礦

interface FastEthernet1
 ip address 203.0.113.1 255.255.255.0
 ip nat outside

interface GigabitEthernet0
 ip address 192.168.1.1 255.255.255.0
 ip nat inside

ip nat pool patpool 203.0.113.1 203.0.113.1 netmask 255.255.255.0
ip nat inside source list 10 pool patpool overload
access-list 10 permit 192.168.1.0 0.0.0.255
Ϥ⤦άǤϤ

ޤNAPTơ֥򸫤Ƥߤޤ礦
Router#show  ip nat translations
Pro Inside global      Inside local       Outside local      Outside global
tcp 203.0.113.1:50024  192.168.1.2:50024  203.0.113.2:443    203.0.113.2:443
tcp 203.0.113.1:50025  192.168.1.2:50025  203.0.113.2:443    203.0.113.2:443

tcp 203.0.113.1:50986  192.168.1.4:50986  203.0.113.2:443    203.0.113.2:443
tcp 203.0.113.1:50991  192.168.1.4:50991  203.0.113.2:443    203.0.113.2:443


203.0.113.1Ȥ1ĤIPɥ쥹ˡ192.168.1.2192.168.1.4ʣΥݡȤбƤ뤳Ȥʬޤʡᣱ¿ˡޤݡֹݻƤޤºݤˤѤäƤޤ͡

ѥåȤΥإåˤIPɥ쥹ȰIPɥ쥹2Ĥ뤳ȤˤȤʤNATˤϡ (Source) NATȰ (Destination) NAT롣
H21NW13ˤǤϡNAT֥NATפȤɽǵܤƤ롣

CiscoΥޥɤǤNAT
IPɥ쥹192.168.1.1200.1.1.1Ѵ
(config)#ip nat inside source static 192.168.1.1 200.1.1.1
insideIFΤɤ¦򺹤ƤΤǡޤ굤ˤʤǤ

CiscoΥޥɤǤΰNAT
(config)#ip nat outside destination static 192.168.1.1 1.1.1.1
outsideIFΤɤ¦򺹤ƤΤǡޤ굤ˤʤǤ

NATNAPTΰ㤤ǤŪˤϼΤ褦˸뤳ȤǤ礦
NAT11Υɥ쥹ѴNAPT1¿Υɥ쥹Ѵ
ŪˤϡNAPTξ硢ʣΥץ饤١IPɥ쥹1ĤΥХIPɥ쥹Ѵޤ
5

NATNAPTΰ㤤ǤȤʤǤޤ
NATNAPTΰ㤤ϡNATơ֥NAPTơ֥񤤤ƤߤȤ褯狼롣
NATơ֥
ѴѴ
200.1.1.1192.168.1.100
NAPTơ֥
ѴѴ
200.1.1.12000192.168.1.1001001
200.1.1.12001192.168.1.2001002
Τ褦ˡNATơ֥IPɥ쥹ΤߤѴơ֥ޤNATNetwork Address TranslationˤȤդ̤ǤNAPTơ֥ϡNAPTNetwork Address Port TranslationˤȤ̾ˡPortפäƤ褦ˡIPɥ쥹ȥݡֹѴơ֥ޤ

Ǥϡ򸫤Ƥߤ褦
륢åץ롼֥ɥХɥ롼IPޥ졼ɵǽ¸뤿˴ƤϤɤ줫

IPɥ쥹ȡͥåȥ󥿡եɸͭMACɥ쥹б
˥URLȤΥڡ
ץ饤١IPɥ쥹ڤӤΥݡֹȡХIPɥ쥹ڤӤΥݡֹб
ۥ̾ISP³뤿ӤѤ륰ХIPɥ쥹б
H16NW25IPޥ졼ɡ
ϥ


ݥ󥵡ɥ

ΥڡΥȥåץ