ͥåȥڥꥹ - SE̼η -

ͥåȥڥꥹȤλкȤǤͥåȥڥꥹȻι
̡ʤΥġ⡢μʤɤξǺܤޤкߥʡԤäƤޤ ͥåȥڥꥹ
кʤ麸κǤܤ֥ͥڡץ꡼ʵɾҡˤǡ
ͥåȥڥꥹȻ˹ʤȡͥåȥ˴ؤμ䵻ѤǤʤɲϤʸϤȤˤĤޤ
ˡλ˹ʤǤȤ뤳ȤǤޤ

ƥꡧ8.ͥåȥءL3 > 8.2 NAT

NATNetwork Address TranslationˤȤϡΥڥ뤬̣褦ˡͥåȥɥ쥹ѴǤ
2 

NATʤƻȤȤΤǤ
㤨С2Ĥ򤯤äĤơĤΥͥåȥˤȤޤɤ192.168.1.0/24ΥͥåȥǤIPɥ쥹νʣ̿Ǥޤ󡣤Ȥäơץ󥿤饵ФǡޤIPɥ쥹ѹΤ礬ȤޤΤȤˡɥ쥹Ѵ̿ФΤǤ
nat1
ǡR1R1³ưĤΥͥåȥΤݤˡߤ꤫ϡ㤦ɥ쥹˸ޤ
ͥåȥ172.16.1.0/24
ͥåȥ172.16.2.0/24
Τˡ롼R1Ǥϡ172.16.1.0/24192.168.1.0/24NAT롼R2Ǥ172.16.2.0/24192.168.1.0/24ΥͥåȥNATޤ
nat2

NATλ⤦ľҲ𤷤ޤϤ褯㤫Ȼפޤ DMZθФǤƤΤǡХIPɥ쥹ɬפǤмΤˤϥץ饤١IPɥ쥹ơNAT뤳Ȥ褯ޤ
4

ʤȤ򤹤̣ϤΤǤ
ΤޤޥХIPɥ쥹ȤФȻפޤ
DMZˤͽФĶʤʣε郎³Ƥ礬ޤХIPɥ쥹ͭ¤ʤΤǡ餹٤Ƥ˥ХIPɥ쥹Ƥ뤳Ȥ񤷤ޤޤФDC˰ߤˡХIPɥ쥹ѤäˤǤФѹɬפʤNATѴǤߤޤ

ǤϡʲΥץʲ۴ĶNATͻҤǧ
3
ʲۡ˥󥿡ͥåȤ1.1.1.1ΥХIPɥ쥹̿򤷤ƤĤǤºݤˤFWNATơ172.16.1.1̿򤷤Ƥޤ NATΥѥåȤȡNATΥѥåȤʲ˵ܤޤƱNOǤIPɥ쥹ѴƤޤ

NATѴ
before


NATѴ
after

IPޥ졼ɤƱȡNAPTʤˤäƤϡNAT+ɽΤ⤢褦
ǤϤޤǡIPޥ졼ɤȤɽ¿äǶǤNAPTѲƤ롣Ƥ˽񤯤ȤϡIPޥ졼ɡפȤɽȤ鷺ɬNAPTȽ񤯤٤Ǥ롣

ǤϡNAPT˴ؤƼεҤ롣
TCPUDPΥݡֹ̤ץ饤١IPɥ쥹ȥХIPɥ쥹Ȥбط뤳Ȥˤäơץ饤١IPɥ쥹ѤLANʣüĤΥХIPɥ쥹ͭƥ󥿡ͥåȤ˥Ȥߡ
(H19NW 36)
NAPTơ֥񤤤Ƥߤ򤬿ޤȻפ

2011.10.30ɵ
NAPTϡƥ̤θ̤⤢롣H21AP9ǤϡNAPT˴ؤơ֥ХIPɥ쥹­äȤȤˡLANˤ뵡Υɥ쥹򱣤ڤȤ̤¸Ƥ롣פȽҤ٤Ƥ롣

ѥåȤΥإåˤIPɥ쥹ȰIPɥ쥹2Ĥ뤳ȤˤȤʤNATˤϡ (Source) NATȰ (Destination) NAT롣
H21NW13ˤǤϡNAT֥NATפȤɽǵܤƤ롣

CiscoΥޥɤǤNAT
IPɥ쥹192.168.1.1200.1.1.1Ѵ
(config)#ip nat inside source static 192.168.1.1 200.1.1.1
insideIFΤɤ¦򺹤ƤΤǡޤ굤ˤʤǤ

CiscoΥޥɤǤΰNAT
(config)#ip nat outside destination static 192.168.1.1 1.1.1.1
outsideIFΤɤ¦򺹤ƤΤǡޤ굤ˤʤǤ

NATNAPTΰ㤤ǤŪˤϼΤ褦˸뤳ȤǤ礦
NAT11Υɥ쥹ѴNAPT1¿Υɥ쥹Ѵ
ŪˤϡNAPTξ硢ʣΥץ饤١IPɥ쥹1ĤΥХIPɥ쥹Ѵޤ
5

NATNAPTΰ㤤ǤȤʤǤޤ
NATNAPTΰ㤤ϡNATơ֥NAPTơ֥񤤤ƤߤȤ褯狼롣
NATơ֥
ѴѴ
200.1.1.1192.168.1.100
NAPTơ֥
ѴѴ
200.1.1.12000192.168.1.1001001
200.1.1.12001192.168.1.2001002
Τ褦ˡNATơ֥IPɥ쥹ΤߤѴơ֥ޤNATNetwork Address TranslationˤȤդ̤ǤNAPTơ֥ϡNAPTNetwork Address Port TranslationˤȤ̾ˡPortפäƤ褦ˡIPɥ쥹ȥݡֹѴơ֥ޤ

Ǥϡ򸫤Ƥߤ褦
륢åץ롼֥ɥХɥ롼IPޥ졼ɵǽ¸뤿˴ƤϤɤ줫

IPɥ쥹ȡͥåȥ󥿡եɸͭMACɥ쥹б
˥URLȤΥڡ
ץ饤١IPɥ쥹ڤӤΥݡֹȡХIPɥ쥹ڤӤΥݡֹб
ۥ̾ISP³뤿ӤѤ륰ХIPɥ쥹б
H16NW25IPޥ졼ɡ
ϥ


ݥ󥵡ɥ

ΥڡΥȥåץ