由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
EmergingNetworking版 - nonat是什么意思啊?
相关主题
VPC networking 问题VPN connection problem?
请教VPN的问题cisco 的 vpn 不支持 vista 64bit, 有什么办法吗? (转载)
VPN question: without router it connects, with route it's n (转载)Site-to-Site VPN 路由器的配置是必须的是吧?
咨询下mobile访问CDNVyatta Open Networking
NAT tranverse introduction 1请高手解答,怎样在美国建立代理服务器,让中国的网友连上?
问一个NAT改变traffic的问题。Looking for VPN books
Microsoft enters VPN market?今天中招了
请教高手:两公司合并,并网的注意事项谁来给点建议:Juniper SSG140+SA2500 vs Fortigate FG200B
相关话题的讨论汇总
话题: nat话题: ip话题: nonat话题: pat话题: internet
进入EmergingNetworking版参与讨论
1 (共1页)
x*********n
发帖数: 28013
1
ip access-list extended NO_NAT
deny ip 10.80.96.0 0.0.0.255 10.11.12.0 0.0.0.255
deny ip 10.80.96.0 0.0.0.255 172.31.46.0 0.0.0.255
permit ip 10.80.96.0 0.0.0.255 any
就是说这些IP不nat?其余都nat?
用在site to site VPN上,因为2边都是private IP,所以要disable nat才能顺利?
s*****g
发帖数: 1055
2
This access-list is typically referenced by your IOS router's policy NAT/PATconfiguration, when a packet comes to NAT inside interface,if it is destined to internal address, then don't apply NAT/PAT rule, route to VPN, for other traffic NAT/PAT it, send to Internet. If the site does not need Internet access or Internet access is via a central off site, then you don't need any NAT or no-NAT configuration.
In order to be politically correct, there are situations you will NAT/PAT traffic even it is internal traffic protected by IPsecVPN, one scenario is that you only allow connections initiated from one IPsec end point.
1 (共1页)
进入EmergingNetworking版参与讨论
相关主题
谁来给点建议:Juniper SSG140+SA2500 vs Fortigate FG200BNAT tranverse introduction 1
2G 以上IPsec VPN 的性能如何呀?问一个NAT改变traffic的问题。
GRE tunnel 不需要VPN card么?Microsoft enters VPN market?
大家看看我的implementation,同事说不行,我半信半疑。请教高手:两公司合并,并网的注意事项
VPC networking 问题VPN connection problem?
请教VPN的问题cisco 的 vpn 不支持 vista 64bit, 有什么办法吗? (转载)
VPN question: without router it connects, with route it's n (转载)Site-to-Site VPN 路由器的配置是必须的是吧?
咨询下mobile访问CDNVyatta Open Networking
相关话题的讨论汇总
话题: nat话题: ip话题: nonat话题: pat话题: internet