Module 6: NAT for IPv4
Enterprise Networking, Security, and Automation v7.0 (ENSA)
Instructor Materials
1
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Instructor Materials – Module 6 Planning Guide
This PowerPoint deck is divided in two parts:
Note: Remove the Planning Guide from this presentation before sharing with anyone.
For additional help and resources go to the Instructor Home Page and Course Resources for this course. You also can visit the professional development site on netacad.com, the official Cisco Networking Academy Facebook page, or Instructor Only FB group.
2
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What to Expect in this Module
Feature | Description |
Animations | Expose learners to new skills and concepts. |
Videos | Expose learners to new skills and concepts. |
Check Your Understanding(CYU) | Per topic online quiz to help learners gauge content understanding. |
Interactive Activities | A variety of formats to help learners gauge content understanding. |
Syntax Checker | Small simulations that expose learners to Cisco command line to practice configuration skills. |
PT Activity | Simulation and modeling activities designed to explore, acquire, reinforce, and expand skills. |
3
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What to Expect in this Module (Cont.)
Feature | Description |
Hands-On Labs | Labs designed for working with physical equipment. |
Class Activities | These are found on the Instructor Resources page. Class Activities are designed to facilitate learning, class discussion, and collaboration. |
Module Quizzes | Self-assessments that integrate concepts and skills learned throughout the series of topics presented in the module. |
Module Summary | Briefly recaps module content. |
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Check Your Understanding
5
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module 6: Activities
What activities are associated with this module?
Page # | Activity Type | Activity Name | Optional? |
6.1.5 | Check Your Understanding | NAT Characteristics | Recommended |
6.2.7 | Packet Tracer | Investigate NAT Operations | Recommended |
6.3.3 | Check Your Understanding | NAT Advantages and Disadvantages | Recommended |
6.4.5 | Packet Tracer | Configure Static NAT | Recommended |
6.5.6 | Packet Tracer | Configure Dynamic NAT | Recommended |
6.6.7 | Packet Tracer | Configure PAT | Recommended |
6.8.1 | Packet Tracer | Configure NAT for IPv4 | Recommended |
6.8.2 | Lab | Configure NAT for IPv4 | Recommended |
6
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module 6: Best Practices
Prior to teaching Module 6, the instructor should:
Topic 6.1
Topic 6.2
7
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module 6: Best Practices (Cont.)
Topic 6.3
Topic 6.4
Topic 6.5
8
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module 6: Best Practices (Cont.)
Topic 6.6
Topic 6.7
9
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module 6: NAT for IPv4
Enterprise Networking, Security, and Automation v7.0 (ENSA)
10
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module Objectives
Module Title: NAT for IPv4
Module Objective: Configure NAT services on the edge router to provide IPv4 address scalability.
Topic Title | Topic Objective |
NAT Characteristics | Explain the purpose and function of NAT. |
Types of NAT | Explain the operation of different types of NAT. |
NAT Advantages and Disadvantages | Describe the advantages and disadvantages of NAT. |
Static NAT | Configure static NAT using the CLI. |
Dynamic NAT | Configure dynamic NAT using the CLI. |
PAT | Configure PAT using the CLI. |
NAT64 | Describe NAT for IPv6. |
11
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.1 NAT Characteristics
12
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
12
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Characteristics�IPv4 Address Space
Class | Activity Type | Activity Name |
A | 10.0.0.0 – 10.255.255.255 | 10.0.0.0/8 |
B | 172.16.0.0 – 172.31.255.255 | 172.16.0.0/12 |
C | 192.168.0.0 – 192.168.255.255 | 192.168.0.0/16 |
13
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Characteristics�What is NAT
14
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Characteristics�How NAT Works
PC1 wants to communicate with an outside web server with public address 209.165.201.1.
15
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Characteristics�NAT Terminology
NAT includes four types of addresses:
NAT terminology is always applied from the perspective of the device with the translated address:
16
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Characteristics�NAT Terminology (Cont.)
Inside local address
The address of the source as seen from inside the network. This is typically a private IPv4 address. The inside local address of PC1 is 192.168.10.10.
Inside global addresses
The address of source as seen from the outside network. The inside global address of PC1 is 209.165.200.226
Outside global address
The address of the destination as seen from the outside network. The outside global address of the web server is 209.165.201.1
Outside local address
The address of the destination as seen from the inside network. PC1 sends traffic to the web server at the IPv4 address 209.165.201.1. While uncommon, this address could be different than the globally routable address of the destination.
17
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.2 Types of NAT
18
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
18
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�Static NAT
Static NAT uses a one-to-one mapping of local and global addresses configured by the network administrator that remain constant.
Note: Static NAT requires that enough public addresses are available to satisfy the total number of simultaneous user sessions.
19
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�Dynamic NAT
Dynamic NAT uses a pool of public addresses and assigns them on a first-come, first-served basis.
Note: Dynamic NAT requires that enough public addresses are available to satisfy the total number of simultaneous user sessions.
20
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�Port Address Translation
Port Address Translation (PAT), also known as NAT overload, maps multiple private IPv4 addresses to a single public IPv4 address or a few addresses.
21
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�Next Available Port
PAT attempts to preserve the original source port. If the original source port is already used, PAT assigns the first available port number starting from the beginning of the appropriate port group 0-511, 512-1,023, or 1,024-65,535.
22
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�NAT and PAT Comparison
Summary of the differences between NAT and PAT.
NAT - Only modifies the IPv4 addresses
PAT - PAT modifies both the IPv4 address and the port number.
Inside Global Address | Inside Local Address |
209.165.200.226 | 192.168.10.10 |
Inside Global Address | Inside Local Address |
209.165.200.226:2031 | 192.168.10.10:2031 |
NAT | PAT |
One-to-one mapping between Inside Local and Inside Global addresses. | One Inside Global address can be mapped to many Inside Local addresses. |
Uses only IPv4 addresses in translation process. | Uses IPv4 addresses and TCP or UDP source port numbers in translation process. |
A unique Inside Global address is required for each inside host accessing the outside network. | A single unique Inside Global address can be shared by many inside hosts accessing the outside network. |
23
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�Packets without a Layer 4 Segment
Some packets do not contain a Layer 4 port number, such as ICMPv4 messages. Each of these types of protocols is handled differently by PAT.
For example, ICMPv4 query messages, echo requests, and echo replies include a Query ID. ICMPv4 uses the Query ID to identify an echo request with its corresponding echo reply.
Note: Other ICMPv4 messages do not use the Query ID. These messages and other protocols that do not use TCP or UDP port numbers vary and are beyond the scope of this curriculum.
24
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Types of NAT�Packet Tracer – Investigate NAT Operations
In this Packet Tracer, you will complete the following objectives:
25
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.3 NAT Advantages and Disadvantages
26
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
26
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Advantages and Disadvantages�Advantages of NAT
NAT provides many benefits:
27
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Advantages and Disadvantages�Disadvantages of NAT
NAT does have drawbacks:
28
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.4 Static NAT
29
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
29
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Static NAT Scenario
30
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Configure Static NAT
There are two basic tasks when configuring static NAT translations:
R2(config)# ip nat inside source static 192.168.10.254 209.165.201.5
R2(config)#
R2(config)# interface serial 0/1/0
R2(config-if)# ip address 192.168.1.2 255.255.255.252
R2(config-if)# ip nat inside
R2(config-if)# exit
R2(config)# interface serial 0/1/1
R2(config-if)# ip address 209.165.200.1 255.255.255.252
R2(config-if)# ip nat outside
31
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Analyze Static NAT
The static NAT translation process between the client and the web server:
32
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Static NAT
To verify NAT operation, issue the show ip nat translations command.
R2# show ip nat translations
Pro Inside global Inside local Outside local Outside global
--- 209.165.201.5 192.168.10.254 --- ---
Total number of translations: 1
R2# show ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 209.165.201.5 192.168.10.254 209.165.200.254 209.165.200.254
--- 209.165.201.5 192.168.10.254 --- ---
Total number of translations: 2
33
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Static NAT (Cont.)
Another useful command is show ip nat statistics.
R2# show ip nat statistics
Total active translations: 1 (1 static, 0 dynamic; 0 extended)
Outside interfaces:
Serial0/1/1
Inside interfaces:
Serial0/1/0
Hits: 4 Misses: 1
(output omitted)
34
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Packet Tracer – Configure Static NAT
In this Packet Tracer, you will complete the following objectives:
35
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.5 Dynamic NAT
36
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
36
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Dynamic NAT Scenario
37
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Configure Dynamic NAT
There are five tasks when configuring dynamic NAT translations:
R2(config)# ip nat pool NAT-POOL1 209.165.200.226 209.165.200.240 netmask 255.255.255.224
R2(config)# access-list 1 permit 192.168.0.0 0.0.255.255
R2(config)# ip nat inside source list 1 pool NAT-POOL1
38
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Configure Dynamic NAT (Cont.)
There are five tasks when configuring dynamic NAT translations:
R2(config)# ip nat pool NAT-POOL1 209.165.200.226 209.165.200.240 netmask 255.255.255.224
R2(config)# access-list 1 permit 192.168.0.0 0.0.255.255
R2(config)# ip nat inside source list 1 pool NAT-POOL1
R2(config)# interface serial 0/1/0
R2(config-if)# ip nat inside
R2(config-if)# interface serial 0/1/1
R2(config-if)# ip nat outside
39
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Analyze Dynamic NAT – Inside to Outside
Dynamic NAT translation process:
40
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Analyze Dynamic NAT – Outside to Inside
Dynamic NAT translation process:
41
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Analyze Dynamic NAT – Outside to Inside (Cont.)
Dynamic NAT translation process:
42
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Dynamic NAT
The output of the show ip nat translations command displays all static translations that have been configured and any dynamic translations that have been created by traffic.
R2# show ip nat translations
Pro Inside global Inside local Outside local Outside global
--- 209.165.200.228 192.168.10.10 --- ---
--- 209.165.200.229 192.168.11.10 --- ---
R2#
43
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Dynamic NAT (Cont.)
Adding the verbose keyword displays additional information about each translation, including how long ago the entry was created and used.
R2# show ip nat translation verbose
Pro Inside global Inside local Outside local Outside global
tcp 209.165.200.228 192.168.10.10 --- ---
create 00:02:11, use 00:02:11 timeout:86400000, left 23:57:48, Map-Id(In): 1,
flags:
none, use_count: 0, entry-id: 10, lc_entries: 0
tcp 209.165.200.229 192.168.11.10 --- ---
create 00:02:10, use 00:02:10 timeout:86400000, left 23:57:49, Map-Id(In): 1,
flags:
none, use_count: 0, entry-id: 12, lc_entries: 0
R2#
44
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Dynamic NAT (Cont.)
By default, translation entries time out after 24 hours, unless the timers have been reconfigured with the ip nat translation timeout timeout-seconds command in global configuration mode. To clear dynamic entries before the timeout has expired, use the clear ip nat translation privileged EXEC mode command.
R2# clear ip nat translation *
R2# show ip nat translation
Command | Description |
clear ip nat translation * | Clears all dynamic address translation entries from the NAT translation table. |
clear ip nat translation inside global-ip local-ip [outside local-ip global-ip] | Clears a simple dynamic translation entry containing an inside translation or both inside and outside translation. |
clear ip nat translation protocol inside global-ip global-port local-ip local-port [ outside local-ip local-port global-ip global-port] | Clears an extended dynamic translation entry. |
45
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Dynamic NAT (Cont.)
The show ip nat statistics command displays information about the total number of active translations, NAT configuration parameters, the number of addresses in the pool, and how many of the addresses have been allocated.
R2# show ip nat statistics
Total active translations: 4 (0 static, 4 dynamic; 0 extended)
Peak translations: 4, occurred 00:31:43 ago
Outside interfaces:
Serial0/1/1
Inside interfaces:
Serial0/1/0
Hits: 47 Misses: 0
CEF Translated packets: 47, CEF Punted packets: 0
Expired translations: 5
Dynamic mappings:
-- Inside Source
[Id: 1] access-list 1 pool NAT-POOL1 refcount 4
pool NAT-POOL1: netmask 255.255.255.224
start 209.165.200.226 end 209.165.200.240
type generic, total addresses 15, allocated 2 (13%), misses 0
(output omitted)
R2#
46
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Static NAT�Verify Dynamic NAT (Cont.)
The show running-config command and show s the NAT, ACL, interface, or pool commands with the required values.
R2# show running-config | include NAT
ip nat pool NAT-POOL1 209.165.200.226 209.165.200.240 netmask 255.255.255.224
ip nat inside source list 1 pool NAT-POOL1
47
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Dynamic NAT�Packet Tracer – Configure Dynamic NAT
In this Packet Tracer, you will complete the following objectives:
48
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.6 PAT
49
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
49
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Configure PAT to Use a Single IPv4 Address
To configure PAT to use a single IPv4 address, add the keyword overload to the ip nat inside source command.
In the example, all hosts from network 192.168.0.0/16 (matching ACL 1) that send traffic through router R2 to the internet will be translated to IPv4 address 209.165.200.225 (IPv4 address of interface S0/1/1). The traffic flows will be identified by port numbers in the NAT table because the overload keyword is configured.
R2(config)# ip nat inside source list 1 interface serial 0/1/0 overload
R2(config)# access-list 1 permit 192.168.0.0 0.0.255.255
R2(config)# interface serial0/1/0
R2(config-if)# ip nat inside
R2(config-if)# exit
R2(config)# interface Serial0/1/1
R2(config-if)# ip nat outside
50
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Configure PAT to Use an Address Pool
An ISP may allocate more than one public IPv4 address to an organization. In this scenario the organization can configure PAT to use a pool of IPv4 public addresses for translation.
To configure PAT for a dynamic NAT address pool, simply add the keyword overload to the ip nat inside source command.
In the example, NAT-POOL2 is bound to an ACL to permit 192.168.0.0/16 to be translated. These hosts can share an IPv4 address from the pool because PAT is enabled with the keyword overload.
R2(config)# ip nat pool NAT-POOL2 209.165.200.226 209.165.200.240 netmask 255.255.255.224
R2(config)# access-list 1 permit 192.168.0.0 0.0.255.255
R2(config)# ip nat inside source list 1 pool NAT-POOL2 overload
R2(config)# interface serial0/1/0
R2(config-if)# ip nat inside
R2(config-if)# interface serial0/1/0
R2(config-if)# ip nat outside
51
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Analyze PAT – Server to PC
52
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Analyze PAT – PC to Server
53
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Analyze PAT – Server to PC
54
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Verify PAT
The same commands used to verify static and dynamic NAT are used to verify PAT. The show ip nat translations command displays the translations from two different hosts to different web servers. Notice that two different inside hosts are allocated the same IPv4 address of 209.165.200.226 (inside global address). The source port numbers in the NAT table differentiate the two transactions.
R2# show ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 209.165.200.225:1444 192.168.10.10:1444 209.165.201.1:80 209.165.201.1:80
tcp 209.165.200.225:1445 192.168.11.10:1444 209.165.202.129:80 209.165.202.129:80
R2#
55
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
PAT�Verify PAT (Cont.)
The show ip nat statistics command verifies that NAT-POOL2 has allocated a single address for both translations. Also shown are the number and type of active translations, NAT configuration parameters, the number of addresses in the pool, and how many have been allocated.
R2# show ip nat statistics
Total active translations: 4 (0 static, 2 dynamic; 2 extended)
Peak translations: 2, occurred 00:31:43 ago
Outside interfaces:
Serial0/1/1
Inside interfaces:
Serial0/1/0
Hits: 4 Misses: 0
CEF Translated packets: 47, CEF Punted packets: 0
Expired translations: 0
Dynamic mappings:
-- Inside Source
[Id: 3] access-list 1 pool NAT-POOL2 refcount 2
pool NAT-POOL2: netmask 255.255.255.224
start 209.165.200.225 end 209.165.200.240
type generic, total addresses 15, allocated 1 (6%), misses 0
(output omitted)
R2#
56
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Dynamic NAT�Packet Tracer – Configure PAT
In this Packet Tracer, you will complete the following objectives:
57
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.7 NAT64
58
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
58
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT64�NAT for IPv6?
IPv6 was developed with the intention of making NAT for IPv4 with translation between public and private IPv4 addresses unnecessary.
59
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT64�NAT64
60
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
6.8 Module Practice and Quiz
61
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
61
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Dynamic NAT�Packet Tracer – Configure NAT for IPv4
In this Packet Tracer, you will complete the following objectives:
62
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Dynamic NAT�Packet Tracer – Configure NAT for IPv4
In this Lab, you will complete the following objectives:
63
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module Practice and Quiz�What did I learn in this module?
64
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module Practice and Quiz�What did I learn in this module? (Cont.)
65
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Module 6: NAT for IPv4�New Terms and Commands
|
66
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
67
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential