Specifications
NAT Configuration Examples
September 08, 2010 Page 16 of 18
ToconfigureClient3andClient4for dynamicNAPTtranslationontheNATrouter,wedefine
access‐list2topermitthelocalIPaddresses10.1.1.3and10.1.1.4.WethenconfigureNATpool
dynamicpoolwithaglobalrangeof200.1.1.3to200.1.1.3.Wethenenabledynamictranslationof
insideaddressesforoverload
associatingaccess‐list2withtheNATpoolnaptpool.
Enable NAT Inside and Outside Interfaces
EnableNATinsideinterface:
System(rw)->configure
System(rw-config)->interface vlan 10
System(su-config-intf-vlan.0.10)->ip nat inside
System(su-config-intf-vlan.0.10)->exit
System(rw-config)->interface vlan 20
System(su-config-intf-vlan.0.20)->ip nat inside
System(su-config-intf-vlan.0.20)->exit
System(rw-config)->
EnableNAToutsideinterface:
System(rw-config)->interface vlan 100
System(su-config-intf-vlan.0.100)->ip nat outside
System(su-config-intf-vlan.0.100)->exit
System(rw-config)->interface vlan 200
System(su-config-intf-vlan.0.200)->ip nat outside
System(su-config-intf-vlan.0.200)->exit
System(rw-config)->
Define Inside Address Access-Lists
Defineinsideaddressaccess‐list1forNATclients:
System(rw-config)->access-list 1 permit host 10.1.1.1
System(rw-config)->access-list 1 permit host 10.1.1.2
System(rw-config)->
Defineinsideaddressaccess‐list2forNAPTclients:
System(rw-config)->access-list 2 permit host 10.1.1.3
System(rw-config)->access-list 2 permit host 10.1.1.4
System(rw-config)->