IPv6简单走两步——NAT64(IPv4节点主动访问IPv6节点)
拓扑及需求
l
l
l
步骤及思路
1 )
2 )
3 )
4 )
步骤及思路
FW的配置如下:
#配置IPv4接口
[FW] interface GE0/0/1
[FW-GigabitEthernet0/0/1] ip address 10.1.1.254 24
[FW] firewall zone trust
[FW-zone-trust] add interface GigabitEthernet0/0/1
#配置IPv6接口
[FW] interface GE0/0/2
[FW-GigabitEthernet0/0/2] ipv6 enable
[FW-GigabitEthernet0/0/2] ipv6 address 2001::FFFF 64
[FW] firewall zone untrust
[FW-zone-untrust] add interface GigabitEthernet0/0/2
#配置NAT64的IPv6前缀,这个前缀将作为PC1去访问IPv6主机的IPv6地址池
[FW] nat64 prefix 3001:: 64
#配置NAT64静态映射,将2001::1这个IPv6的节点映射到IPv4地址10.1.1.111
[FW] nat64 static 2001::1 10.1.1.111
[FW] policy interzone trust untrust outbound
[FW-policy-interzone-trust-untrust-outbound] policy 10
[FW-policy-interzone-trust-untrust-outbound-10] policy source 10.1.1.0 0.0.0.255
[FW-policy-interzone-trust-untrust-outbound-10] policy destination 10.1.1.111 0
[FW-policy-interzone-trust-untrust-outbound-10] action permit
完成配置后,PC1即可ping通10.1.1.111。
[FW] display firewall session table
[FW] display firewall ipv6 session table
Current Total IPv6 Sessions: 1
---------------------------------------------------------------------
[FW] display nat64 session table
Current Total Sessions: 1
本文链接:https://www.kinber.cn/post/1424.html 转载需授权!
推荐本站淘宝优惠价购买喜欢的宝贝: