目次~
#contents
**概要 [#y65c0f71]
静的NATの設定事例。~
10.10.10.1 <-> 192.168.100.100への静的NATを行う。~
ホストの実アドレスは10.10.10.1であり、ルータ越しの対抗にはルータが持つVIP 192.168.100.100と静的NATをする構成となる。
**設定 [#q79067c9]
-eth1に静的NAT用のアドレス(VIP)を設定
configure
set interfaces ethernet eth1 address 192.168.100.100/24
-eth0側のDestination NAT(10.10.10.1 → 192.168.100.100)
set service nat rule 10
edit service nat rule 10
set inbound-interface eth0
set destination address 10.10.10.1/32
set inside-address address 192.168.100.100/32
set type destination
commit
exit
-eth0側のSource NAT(192.168.100.100 → 10.10.10.1)
set service nat rule 20
edit service nat rule 20
set outbound-interface eth0
set source address 192.168.100.100/32
set outside-address address 10.10.10.1/32
set type source
commit
exit
-eth1側のDestination NAT(10.10.10.1 → 192.168.100.100)
set service nat rule 11
edit service nat rule 11
set outbound-interface eth1
set source address 10.10.10.1/32
set outside-address address 192.168.100.100/32
set type source
commit
exit
-eth1側のSource NAT(192.168.100.100 → 10.10.10.1)
set service nat rule 21
edit service nat rule 21
set inbound-interface eth1
set destination address 192.168.100.100/32
set inside-address address 10.10.10.1/32
set type destination
commit
exit
-設定を保存
save