RS_instructorPPT_Chapter11_final 2
RS_instructorPPT_Chapter11_final 2
RS_instructorPPT_Chapter11_final 2
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 1
Configuring Dynamic NAT
Configuring Dynamic NAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 2
Configuring Dynamic NAT
Analyzing Dynamic NAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 3
Configuring Dynamic NAT
Analyzing Dynamic NAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 4
Configuring Dynamic NAT
Verifying Dynamic NAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 5
Configuring Dynamic NAT
Verifying Dynamic NAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 6
Configuring PAT
Configuring PAT: Address Pool
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7
Configuring PAT
Configuring PAT: Single Address
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 8
Configuring PAT
Analyzing PAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9
Configuring PAT
Analyzing PAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10
Configuring PAT
Verifying PAT Translations
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 11
Port Forwarding
Port Forwarding
Port forwarding is the act of forwarding a network port from one
network node to another.
A packet sent to the public IP address and port of a router can be
forwarded to a private IP address and port in inside network.
Port forwarding is helpful in situations where servers have private
addresses, not reachable from the outside networks.
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12
Port Forwarding
SOHO Example
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 13
Port Forwarding
Configuring Port Forwarding with IOS
In IOS, Port forwarding is essentially a static NAT translation with a
specified TCP or UDP port number.
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14
Configuring NAT and IPv6
NAT for IPv6?
NAT is a workaround for IPv4 address scarcity.
IPv6 with a 128-bit address provides 340 undecillion addresses.
Address space is not an issue for IPv6.
IPv6 makes IPv4 public-private NAT unnecessary by design;
however, IPv6 does implement a form of private addresses, and it
is implemented differently than they are for IPv4.
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 15
Configuring NAT and IPv6
IPv6 Unique Local Addresses
IPv6 unique local addresses (ULAs) are designed to allow IPv6
communications within a local site.
ULAs are not meant to provide additional IPv6 address space.
ULAs have the prefix FC00::/7, which results in a first hextet range
of FC00 to FDFF.
ULAs are also known as local IPv6 addresses (not to be confused
with IPv6 link-local addresses).
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 16
Configuring NAT and IPv6
NAT for IPv6
IPv6 also uses NAT, but in a much different context.
In IPv6, NAT is used to provide transparent communication
between IPv6 and IPv4.
NAT64 is not intended to be a permanent solution; it is meant to be
a transition mechanism.
Network Address Translation-Protocol Translation (NAT-PT) was
another NAT-based transition mechanism for IPv6, but is now
deprecated by IETF.
NAT64 is now recommended.
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 17
Configuring NAT and IPv6
NAT for IPv6
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 18
11.3 Troubleshooting NAT
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 19
Configuring NAT and IPv6
Troubleshooting NAT: show commands
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 20
Configuring NAT and IPv6
Troubleshooting NAT: debug command
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 21
Chapter 11: Summary
This chapter has outlined:
How NAT is used to help alleviate the depletion of the IPv4 address
space.
NAT conserves public address space and saves considerable
administrative overhead in managing adds, moves, and changes.
NAT for IPv4, including:
• NAT characteristics, terminology, and general operations
• Different types of NAT, including static NAT, dynamic NAT, and
NAT with overloading
• Benefits and disadvantages of NAT
The configuration, verification, and analysis of static NAT, dynamic
NAT, and NAT with overloading.
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 22
Chapter 11: Summary (cont.)
How port forwarding can be used to access an internal devices from
the Internet.
Troubleshooting NAT using show and debug commands.
How NAT for IPv6 is used to translate between IPv6 addresses and
IPv4 addresses.
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 23
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 24