enable Nat control on the ASA
Experimental requirements:
1. Configure each routed interface IP,asa Interface
2. Configure Dynamic Naton the Asa toenable R1 to telnet R4.
3. Dynamic PATis configured on the Asa, enabling R3 to telnet R4.
4. Configure routing to enable R2 to telnet R4
5. Configure enable Nat control on the Asa , see if R2 can access R4?
6. What do I need to configure R4 to implement telnet R1?
7. Show Xlate Detail view the conversion table.
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M01/8B/A8/wKioL1hUCdSDy_CUAABdudafJmA243.jpg-wh_500x0-wm_3 -wmp_4-s_524861233.jpg "title=" image 1.jpg "alt=" wkiol1hucdsdy_cuaabdudafjma243.jpg-wh_50 "/>
A. Configuring Interfaces
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/8B/AC/wKiom1hUCe3xkpn6AAB4FWpQRSg411.jpg-wh_500x0-wm_3 -wmp_4-s_438611942.jpg "title=" image 2.jpg "alt=" wkiom1huce3xkpn6aab4fwpqrsg411.jpg-wh_50 "/>650) this.width= 650; "Src=" Http://s4.51cto.com/wyfs02/M02/8B/A8/wKioL1hUCfrhD2yuAADuI__jad0004.jpg-wh_500x0-wm_3-wmp_4-s_ 1352260747.jpg "title=" image 3.jpg "alt=" wkiol1hucfrhd2yuaadui__jad0004.jpg-wh_50 "/>
Second, Configure routing to enable Intranet interoperability.
R1
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M02/8B/A8/wKioL1hUChmy54DTAACYyASrIfo369.jpg-wh_500x0-wm_3 -wmp_4-s_3207177166.jpg "title=" image 4.jpg "alt=" wkiol1huchmy54dtaacyyasrifo369.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M00/8B/AC/wKiom1hUCinjURcbAAB_voh0C-E866.jpg-wh_500x0-wm_3 -wmp_4-s_46053677.jpg "title=" image 5.jpg "alt=" wkiom1hucinjurcbaab_voh0c-e866.jpg-wh_50 "/>
R3
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M00/8B/A8/wKioL1hUCkmRzwtXAABvBB1yokw344.jpg-wh_500x0-wm_3 -wmp_4-s_1489343633.jpg "title=" image 6.jpg "alt=" wkiol1huckmrzwtxaabvbb1yokw344.jpg-wh_50 "/>
Asa
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/8B/AC/wKiom1hUClqwpaQFAACVbEPPuFE176.jpg-wh_500x0-wm_3 -wmp_4-s_428217699.jpg "title=" image 7.jpg "alt=" wkiom1huclqwpaqfaacvbeppufe176.jpg-wh_50 "/>
Third, Configuring Dynamic nat,R1 telnet R4
1.ASA Settings
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M00/8B/A8/wKioL1hUCnCyt7kFAACN7_khCgc127.jpg-wh_500x0-wm_3 -wmp_4-s_2902906783.jpg "title=" image 8.jpg "alt=" wkiol1hucncyt7kfaacn7_khcgc127.jpg-wh_50 "/>
2. R4 setting up remote
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M01/8B/AC/wKiom1hUCoKRnDiBAACR0P6hCsk277.jpg-wh_500x0-wm_3 -wmp_4-s_908288555.jpg "title=" image 9.jpg "alt=" wkiom1hucokrndibaacr0p6hcsk277.jpg-wh_50 "/>
3. R1 Verification
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M01/8B/A8/wKioL1hUCpeDjRd9AACtfRldsdA208.jpg-wh_500x0-wm_3 -wmp_4-s_1417306356.jpg "title=" image 10.jpg "alt=" wkiol1hucpedjrd9aactfrldsda208.jpg-wh_50 "/>
Four, Configure dynamic PATon the ASAto implement R3 telnet R4
1. ASA Configuration
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M01/8B/AC/wKiom1hUCq7i5CFGAADo8OMflqg264.jpg-wh_500x0-wm_3 -wmp_4-s_1988950689.jpg "title=" image 11.jpg "alt=" wkiom1hucq7i5cfgaado8omflqg264.jpg-wh_50 "/>
2. Verify telnet R4 on R3
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/8B/A8/wKioL1hUCr6iLeb4AACDdhxiOEU671.jpg-wh_500x0-wm_3 -wmp_4-s_3661770677.jpg "title=" image 12.jpg "alt=" wkiol1hucr6ileb4aacddhxioeu671.jpg-wh_50 "/>
Five, Configure routing implementation R2 telnet R4
R4 Configuring default routes
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/8B/A8/wKioL1hUCtTwAnn7AAEBV2cc3hI898.jpg-wh_500x0-wm_3 -wmp_4-s_1447270759.jpg "title=" image 13.jpg "alt=" wkiol1hucttwann7aaebv2cc3hi898.jpg-wh_50 "/>
R2 to verify that telnet R4 is possible.
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M02/8B/AC/wKiom1hUCuOQp1ezAACZZ-hkxIs594.jpg-wh_500x0-wm_3 -wmp_4-s_3896054225.jpg "title=" image 14.jpg "alt=" wkiom1hucuoqp1ezaaczz-hkxis594.jpg-wh_50 "/>
Six, enable Nat control.
1. The ASA enables Nat control
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M00/8B/AC/wKiom1hUCvfy8Ed2AABwwFQGeXs427.jpg-wh_500x0-wm_3 -wmp_4-s_3255921051.jpg "title=" image 15.jpg "alt=" wkiom1hucvfy8ed2aabwwfqgexs427.jpg-wh_50 "/>
2. R1 Validation can still be remotely R4
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/8B/AC/wKiom1hUCwexWJBvAAB8gp-1MOs726.jpg-wh_500x0-wm_3 -wmp_4-s_3419465873.jpg "title=" image 16.jpg "alt=" wkiom1hucwexwjbvaab8gp-1mos726.jpg-wh_50 "/>
3. Verify that R2 disables telnet R4
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M01/8B/AC/wKiom1hUCxfTzfIYAACfXE0OExA680.jpg-wh_500x0-wm_3 -wmp_4-s_100556173.jpg "title=" image 17.jpg "alt=" wkiom1hucxftzfiyaacfxe0oexa680.jpg-wh_50 "/>
Seven, Configuration NAT Waiver let R2 reply to communication
1. Configure Nat Exemption on the ASA
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M01/8B/A8/wKioL1hUCyvj-WrcAACyLZpKD4Q862.jpg-wh_500x0-wm_3 -wmp_4-s_1335992505.jpg "title=" image 18.jpg "alt=" wkiol1hucyvj-wrcaacylzpkd4q862.jpg-wh_50 "/>
2. Verify recovery communication on R2
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M01/8B/A8/wKioL1hUCzriMxdjAACVFUV54d4267.jpg-wh_500x0-wm_3 -wmp_4-s_2197898773.jpg "title=" image 19.jpg "alt=" wkiol1huczrimxdjaacvfuv54d4267.jpg-wh_50 "/>
Eight, Clear the above configuration in the R3 emulation server .
R4 telnet R3
1. The ASA configures static Nat and ACLs.
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M02/8B/AC/wKiom1hUC0zQXeKQAACfT3j_xNY346.jpg-wh_500x0-wm_3 -wmp_4-s_363997548.jpg "title=" image 20.jpg "alt=" wkiom1huc0zqxekqaacft3j_xny346.jpg-wh_50 "/>
2. Verify on R4
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M02/8B/AC/wKiom1hUC1-jLIAxAACmq7t9-5o918.jpg-wh_500x0-wm_3 -wmp_4-s_3787630594.jpg "title=" image 21.jpg "alt=" wkiom1huc1-jliaxaacmq7t9-5o918.jpg-wh_50 "/>
3. when there are many different servers in the intranet, you can use static PAT command. Convert multiple server addresses to a legitimate address to a public network.
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/8B/A8/wKioL1hUC3ORJCaqAADU0KQN794171.jpg-wh_500x0-wm_3 -wmp_4-s_1084659531.jpg "title=" image 22.jpg "alt=" wkiol1huc3orjcaqaadu0kqn794171.jpg-wh_50 "/>
Eighth. High-level Internet enabled NAT control on the ASA