要显示 NAT 池使用情况的统计信息,请使用 show nat pool 命令。
show nat pool [ interface if-name [ ip address ] | ip address | detail ]
show nat pool cluster [ summary | interface if-name [ ip address ] | ip address ]
Syntax Description
cluster
|
(可选)启用群集技术后,将显示当前分配到所有者设备和备用设备的 PAT 地址。
(6.7+) 包括 summary 关键字,以查看集群中设备之间的端口块分布情况。
|
interface if_name
|
将显示限制为指定接口的池。您可以选择包含 ip 关键字以进一步限制视图。
|
ip 地址
|
将显示限制为 PAT 池中的指定 IP 地址。
|
detail
|
显示与集群内端口块的使用和分布相关的信息。仅当设备是集群成员时,才会显示此关键字。不能将其与集群关键字一起使用。
|
Command History
版本
|
修改
|
6.1
|
引入了此命令。
|
6.7
|
添加了以下关键字: interface 、 ip 、 detail 、 summary 。
|
Usage Guidelines
(Pre-6.7) 为每个映射的协议/IP 地址/端口范围创建 NAT 池,其中端口范围默认为 1-511、512-1023 和 1024-65535。如果将 PAT 池配置为使用平面范围的端口,则会看到更少、更大的范围。
(6.7+) 从 6.7 开始,端口范围默认为平面,您可以选择在池中包含保留的端口 1-1023。对于集群系统,PAT 池以 512 个端口为一组分布在集群成员之间。
每个 NAT 池在上次使用后存在至少 10 分钟。如果您使用 clear xlate 清除转换,则 10 分钟抑制计时器将被取消。
Examples
以下是 show running-config object network 命令显示的动态 PAT 规则创建的 NAT 池的输出示例。
> show running-config object network
object network myhost
host 10.10.10.10
nat (pppoe2,inside) dynamic 10.76.11.25
> show nat pool
TCP inside, address 10.76.11.25, range 1-511, allocated 0
TCP inside, address 10.76.11.25, range 512-1023, allocated 0
TCP inside, address 10.76.11.25, range 1024-65535, allocated 1
以下是 show nat pool 命令展示如何使用 PAT 池 flat 选项的输出示例。如果没有 include-reserve 关键字,则显示两个范围;低于 1024 的源端口映射到同一端口时使用较低的范围。
> show nat pool
ICMP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 2
TCP PAT pool dynamic-pat, address 172.16.2.200, range 1-1024, allocated 0
TCP PAT pool dynamic-pat, address 172.16.2.200, range 1024-65535, allocated 2
UDP PAT pool dynamic-pat, address 172.16.2.200, range 1-1024, allocated 0
UDP PAT pool dynamic-pat, address 172.16.2.200, range 1024-65535, allocated 2
以下是 show nat pool 命令的输出示例,显示了 PAT 池 flat include-reserve 选项的使用。
> show nat pool
ICMP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 2
TCP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 2
UDP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 2
(Pre-6.7) 以下是 show nat pool 命令的输出示例,其中显示了 PAT 池 extended flat include-reserve 选项的使用。重要的项目是括号内的地址。这些是用于扩展 PAT 的目标地址。
ICMP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 0
ICMP PAT pool dynamic-pat, address 172.16.2.200(172.16.2.99), range 1-65535,
allocated 2
TCP PAT pool dynamic-pat, address 172.16.2.200(172.16.2.100), range 1-65535,
allocated 1
UDP PAT pool dynamic-pat, address 172.16.2.200(172.16.2.100), range 1-65535,
allocated 1
TCP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 0
ICMP PAT pool dynamic-pat, address 172.16.2.200(172.16.2.100), range 1-65535,
allocated 1
TCP PAT pool dynamic-pat, address 172.16.2.200(172.16.2.99), range 1-65535,
allocated 2
UDP PAT pool dynamic-pat, address 172.16.2.200, range 1-65535, allocated 0
Examples
(6.7+) 以下示例显示了端口块的分布情况(显示端口范围)及其在集群中的使用情况,包括拥有该块的设备和该块的备用设备。
> show nat pool cluster
IP outside_a:src_map_a 174.0.1.20
[1536 – 2047], owner A, backup B
[8192 – 8703], owner A, backup B
[4089 – 4600], owner B, backup A
[11243 – 11754], owner B, backup A
IP outside_a:src_map_a 174.0.1.21
[1536 – 2047], owner A, backup B
[8192 – 8703], owner A, backup B
[4089 – 4600], owner B, backup A
[11243 – 11754], owner B, backup A
IP outside_b:src_map_b 174.0.1.22
[6656 - 7167], owner A, backup B
[13312 - 13823], owner A, backup B
[20480 - 20991], owner B, backup A
[58368 - 58879], owner B, backup A
IP outside_b:src_map_b 174.0.1.23
[46592 - 47103], owner A, backup B
[52224 - 52735], owner A, backup B
[62976 - 63487], owner B, backup A
(6.7+) 以下示例显示集群中的池分配摘要。
> show nat pool cluster summary
port-blocks count display order: total, unit-A, unit-B, unit-C, unit-D
IP outside_a:src_map_a, 174.0.1.20 (128 - 32/32/32/32)
IP outside_a:src_map_a, 174.0.1.21 (128 - 36/32/32/28)
IP outside_b:src_map_b, 174.0.1.22 (128 - 31/32/32/33)
(6.7+) 以下示例显示了集群中池的 PAT 池的详细使用情况。查看详细输出时,备份端口范围用星号表示。例如:范围 63464-62975,已分配 27 *
> show nat pool detail
TCP PAT pool outside_a, address 174.0.1.1
range 1536-2047, allocated 56
range 8192-8703, allocated 16
UDP PAT pool outside_a, address 174.0.1.1
range 1536-2047, allocated 12
range 8192-8703, allocated 25
TCP PAT pool outside_b, address 174.0.2.1
range 47104-47615, allocated 39
range 62464-62975, allocated 9
UDP PAT pool outside_b, address 174.0.2.1
range 47104-47615, allocated 35
range 62464-62975, allocated 27
(6.7+) 以下示例显示如何将视图限制为特定设备上的特定接口。
> show nat pool interface outside_b ip 174.0.2.1
TCP PAT pool outside_b, address 174.0.2.1, range 1-511, allocated 0
TCP PAT pool outside_b, address 174.0.2.1, range 512-1023, allocated 12
TCP PAT pool outside_b, address 174.0.2.1, range 1024-65535, allocated 48
UDP PAT pool outside_b, address 174.0.2.1, range 1-511, allocated 6
UDP PAT pool outside_b, address 174.0.2.1, range 512-1023, allocated 8
UDP PAT pool outside_b, address 174.0.2.1, range 1024-65535, allocated 62