组网及说明
PC-----(2/0/1)路由器(2/0/2)(nat outbound)------内网环境
问题描述
display nat session没看到有会话,nat outbound 没生效。
当前配置为:
interface Ten-GigabitEthernet2/0/1
port link-mode route
ip address 10.0.0.6 255.255.255.252
interface Ten-GigabitEthernet2/0/2
ip address 192.168.59.45 255.255.255.252
nat outbound 3002 address-group 1
nat outbound 3001 address-group 1
nat outbound 3000 address-group 0
过程分析
查看配置,发现没有配置引流。
高端设备做nat,要把nat引流到业务板。
解决方法
加了nat引流配置后,nat outbound转换正常
#
traffic classifier 1 operator or
if-match acl 3000
if-match acl 3001
if-match acl 3002
#
traffic behavior 1
redirect local
#
qos policy 1
classifier 1 behavior 1
#
interface Ten-GigabitEthernet2/0/1接口下添加
qos apply policy 1 inbound
#