我正在使用 Cisco ASA 8.2 并计划升级到 8.4 或更高版本。如果您知道 NAT 在较新版本中完全重新设计(从 8.3 开始)
我首先要清理现有的规则,并有一个关于 NAT 豁免的问题。
nat (apple) 0 access-list nonat_a
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 10.10.254.0 255.255.255.0
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 10.10.50.0 255.255.255.0
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 10.11.71.0 255.255.255.0
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 host 10.11.67.11
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 host 172.21.53.13
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 10.11.65.0 255.255.255.0
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 host 172.21.53.22
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 10.11.66.0 255.255.255.0
access-list nonat_a extended permit ip 10.11.69.0 255.255.255.0 host 172.21.230.17
当这是我的 nat 豁免配置时,我对它们没有任何影响
access-list nonat_a; 9 elements; name hash: 0x730fb5b7
access-list nonat_a line 1 extended permit ip 10.11.69.0 255.255.255.0 10.10.254.0 255.255.255.0 (hitcnt=0) 0x55398b19
access-list nonat_a line 2 extended permit ip 10.11.69.0 255.255.255.0 10.10.50.0 255.255.255.0 (hitcnt=0) 0x973d918e
access-list nonat_a line 3 extended permit ip 10.11.69.0 255.255.255.0 10.11.71.0 255.255.255.0 (hitcnt=0) 0x8456bc46
access-list nonat_a line 4 extended permit ip 10.11.69.0 255.255.255.0 host 10.11.67.11 (hitcnt=0) 0x32c44f8d
access-list nonat_a line 5 extended permit ip 10.11.69.0 255.255.255.0 host 172.21.53.13 (hitcnt=0) 0x718c853b
access-list nonat_a line 6 extended permit ip 10.11.69.0 255.255.255.0 10.11.65.0 255.255.255.0 (hitcnt=0) 0x2ee8036c
access-list nonat_a line 7 extended permit ip 10.11.69.0 255.255.255.0 host 172.21.53.22 (hitcnt=0) 0x6fa0837f
access-list nonat_a line 8 extended permit ip 10.11.69.0 255.255.255.0 10.11.66.0 255.255.255.0 (hitcnt=0) 0xd61e0f54
access-list nonat_a line 9 extended permit ip 10.11.69.0 255.255.255.0 host 172.21.230.17 (hitcnt=0) 0x5f884523
然后我可以得出结论,我的 nat 豁免没有被使用吗?我也很高兴我无法通过 packettracer 中的构建触发 nat 豁免。这是真的还是我也应该用数据包跟踪测试豁免?
亲切的问候