VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื—ืœืง ืจืืฉื•ืŸ
ืœืื—ืจ ื”ืคืกืงื” ืงืฆืจื” ืื ื• ื—ื•ื–ืจื™ื ืœ-NSX. ื”ื™ื•ื ืื ื™ ืืจืื” ืœืš ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ NAT ื•ื—ื•ืžืช ืืฉ.
ื‘ื›ืจื˜ื™ืกื™ื™ื” ืื“ืžื™ื ืกื˜ืจืฆื™ื” ืขื‘ื•ืจ ืœืžืจื›ื– ื”ื ืชื•ื ื™ื ื”ื•ื™ืจื˜ื•ืืœื™ ืฉืœืš - ืžืฉืื‘ื™ ืขื ืŸ - ืžืจื›ื–ื™ ื ืชื•ื ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื.

ื‘ื—ืจ ื›ืจื˜ื™ืกื™ื™ื” ืฉืขืจื™ ืื“ื’' ื•ืœื—ืฅ ืœื—ื™ืฆื” ื™ืžื ื™ืช ืขืœ ื”-NSX Edge ื”ืจืฆื•ื™. ื‘ืชืคืจื™ื˜ ืฉืžื•ืคื™ืข ื‘ื—ืจ ื‘ืืคืฉืจื•ืช ืฉื™ืจื•ืชื™ Edge Gateway. ืœื•ื— ื”ื‘ืงืจื” ืฉืœ NSX Edge ื™ื™ืคืชื— ื‘ืœืฉื•ื ื™ืช ื ืคืจื“ืช.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื”ื’ื“ืจืช ื—ื•ืงื™ ื—ื•ืžืช ืืฉ

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืคืจื™ื˜ ื›ืœืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ืชื ื•ืขื” ื ื›ื ืกืช ื”ืืคืฉืจื•ืช ื“ื—ื” ื ื‘ื—ืจื”, ื›ืœื•ืžืจ ื—ื•ืžืช ื”ืืฉ ืชื—ืกื•ื ืืช ื›ืœ ื”ืชืขื‘ื•ืจื”.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื›ื“ื™ ืœื”ื•ืกื™ืฃ ื›ืœืœ ื—ื“ืฉ, ืœื—ืฅ ืขืœ +. ืขืจืš ื—ื“ืฉ ื™ื•ืคื™ืข ืขื ื”ืฉื ื—ื•ืง ื—ื“ืฉ. ืขืจื•ืš ืืช ื”ืฉื“ื•ืช ืฉืœื• ื‘ื”ืชืื ืœื“ืจื™ืฉื•ืช ืฉืœืš.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ืชื—ื•ื ืฉื ืชืŸ ืœื›ืœืœ ืฉื, ืœืžืฉืœ ืื™ื ื˜ืจื ื˜.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ืชื—ื•ื ืžึธืงื•ึนืจ ื”ื–ืŸ ืืช ื›ืชื•ื‘ื•ืช ื”ืžืงื•ืจ ื”ื ื“ืจืฉื•ืช. ื‘ืืžืฆืขื•ืช ื›ืคืชื•ืจ ื”-IP, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื›ืชื•ื‘ืช IP ื‘ื•ื“ื“ืช, ืžื’ื•ื•ืŸ ื›ืชื•ื‘ื•ืช IP, CIDR.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ืืžืฆืขื•ืช ื”ืœื—ืฆืŸ + ืชื•ื›ืœ ืœืฆื™ื™ืŸ ืื•ื‘ื™ื™ืงื˜ื™ื ืื—ืจื™ื:

  • ืžืžืฉืงื™ ืฉืขืจ. ื›ืœ ื”ืจืฉืชื•ืช ื”ืคื ื™ืžื™ื•ืช (ืคื ื™ืžื™), ื›ืœ ื”ืจืฉืชื•ืช ื”ื—ื™ืฆื•ื ื™ื•ืช (ื—ื™ืฆื•ื ื™ื•ืช) ืื• ื›ืœ ืื—ืช.
  • ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช. ืื ื• ืžื—ื™ื™ื‘ื™ื ืืช ื”ื›ืœืœื™ื ืœืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืกืคืฆื™ืคื™ืช.
  • OrgVdcNetworks. ืจืฉืชื•ืช ื‘ืจืžืช ื”ืืจื’ื•ืŸ.
  • ืขืจื›ื•ืช IP. ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื ืฉื ื•ืฆืจื” ืžืจืืฉ ืฉืœ ื›ืชื•ื‘ื•ืช IP (ื ื•ืฆืจื” ื‘ืื•ื‘ื™ื™ืงื˜ Grouping).

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ืชื—ื•ื ื™ึทืขึทื“ ืœืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”ื ืžืขืŸ. ื”ืืคืฉืจื•ื™ื•ืช ื›ืืŸ ื–ื”ื•ืช ืœืืœื• ืฉื‘ืฉื“ื” ื”ืžืงื•ืจ.
ื‘ืชื—ื•ื ืฉืึตืจื•ึผืช ืืชื” ื™ื›ื•ืœ ืœื‘ื—ื•ืจ ืื• ืœืฆื™ื™ืŸ ื‘ืื•ืคืŸ ื™ื“ื ื™ ืืช ื™ืฆื™ืืช ื”ื™ืขื“ (ื™ืฆื™ืืช ื™ืขื“), ืืช ื”ืคืจื•ื˜ื•ืงื•ืœ ื”ื ื“ืจืฉ (ืคืจื•ื˜ื•ืงื•ืœ) ื•ืืช ื™ืฆื™ืืช ื”ืฉื•ืœื— (ื™ืฆื™ืืช ืžืงื•ืจ). ืœื—ืฅ ืขืœ ืฉืžื•ืจ.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ืชื—ื•ื ืคืขื•ืœื” ื‘ื—ืจ ืืช ื”ืคืขื•ืœื” ื”ื ื“ืจืฉืช: ืืคืฉืจ ืื• ื“ื—ื” ืชื ื•ืขื” ื”ืชื•ืืžืช ืืช ื”ื›ืœืœ ื”ื–ื”.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื”ื—ืœ ืืช ื”ืชืฆื•ืจื” ืฉื”ื•ื–ื ื” ืขืœ ื™ื“ื™ ื‘ื—ื™ืจื” ืฉืžื•ืจ ืืช ื”ืฉื™ื ื•ื™ื™ื.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื“ื•ื’ืžืื•ืช ืฉืœ ื›ืœืœื™ื

ื›ืœืœ 1 ืขื‘ื•ืจ ื—ื•ืžืช ืืฉ (ืื™ื ื˜ืจื ื˜) ืžืืคืฉืจ ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช ื›ืœ ืคืจื•ื˜ื•ืงื•ืœ ืœืฉืจืช ืขื IP 192.168.1.10.

ื›ืœืœ 2 ืขื‘ื•ืจ ื—ื•ืžืช ืืฉ (ืฉืจืช ืื™ื ื˜ืจื ื˜) ืžืืคืฉืจ ื’ื™ืฉื” ืžื”ืื™ื ื˜ืจื ื˜ ื“ืจืš (ืคืจื•ื˜ื•ืงื•ืœ TCP, ื™ืฆื™ืื” 80) ื“ืจืš ื”ื›ืชื•ื‘ืช ื”ื—ื™ืฆื•ื ื™ืช ืฉืœืš. ื‘ืžืงืจื” ื–ื” - 185.148.83.16:80.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื”ื’ื“ืจืช NAT

NAT (ืชืจื’ื•ื ื›ืชื•ื‘ืช ืจืฉืช) โ€“ ืชืจื’ื•ื ืฉืœ ื›ืชื•ื‘ื•ืช IP ืคืจื˜ื™ื•ืช (ืืคื•ืจื•ืช) ืœื›ืชื•ื‘ื•ืช ื—ื™ืฆื•ื ื™ื•ืช (ืœื‘ื ื•ืช), ื•ืœื”ื™ืคืš. ื‘ืืžืฆืขื•ืช ืชื”ืœื™ืš ื–ื”, ื”ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช ืžืงื‘ืœืช ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜. ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืžื ื’ื ื•ืŸ ื–ื”, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ื›ืœืœื™ SNAT ื•-DNAT.
ื—ึธืฉืื•ึผื‘! NAT ืคื•ืขืœ ืจืง ื›ืืฉืจ ื—ื•ืžืช ื”ืืฉ ืžื•ืคืขืœืช ื•ื›ืœืœื™ ื”ื”ืจืฉืื” ื”ืžืชืื™ืžื™ื ืžื•ื’ื“ืจื™ื.

ืฆื•ืจ ื›ืœืœ SNAT. SNAT (ืชืจื’ื•ื ื›ืชื•ื‘ื•ืช ืจืฉืช ืžืงื•ืจ) ื”ื•ื ืžื ื’ื ื•ืŸ ืฉืขื™ืงืจื• ื”ื—ืœืคืช ื›ืชื•ื‘ืช ื”ืžืงื•ืจ ื‘ืขืช ืฉืœื™ื—ืช ืžื ื”.

ืจืืฉื™ืช ืขืœื™ื ื• ืœื‘ืจืจ ืืช ื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ืื• ืืช ื˜ื•ื•ื— ื›ืชื•ื‘ื•ืช ื”-IP ื”ืขื•ืžื“ื™ื ืœืจืฉื•ืชื ื•. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ืขื‘ื•ืจ ืืœ ื”ืกืขื™ืฃ ืื“ืžื™ื ืกื˜ืจืฆื™ื” ื•ืœื—ืฅ ืคืขืžื™ื™ื ืขืœ ืžืจื›ื– ื”ื ืชื•ื ื™ื ื”ื•ื•ื™ืจื˜ื•ืืœื™. ื‘ืชืคืจื™ื˜ ื”ื”ื’ื“ืจื•ืช ืฉืžื•ืคื™ืข, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช ืฉืขืจ ืื“ื’'ืก. ื‘ื—ืจ ืืช ื”-NSX Edge ื”ืจืฆื•ื™ ื•ืœื—ืฅ ืขืœื™ื• ื‘ืืžืฆืขื•ืช ืœื—ืฆืŸ ื”ืขื›ื‘ืจ ื”ื™ืžื ื™. ื‘ื—ืจ ืืคืฉืจื•ืช ืžืืคื™ื™ืŸ.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ื—ืœื•ืŸ ืฉืžื•ืคื™ืข, ื‘ืœืฉื•ื ื™ืช ื”ืงืฆืืช ืžืฉื ื” ืžืื’ืจื™ IP ืืชื” ื™ื›ื•ืœ ืœื”ืฆื™ื’ ืืช ื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ืื• ืืช ื˜ื•ื•ื— ื›ืชื•ื‘ื•ืช ื”-IP. ืจืฉื•ื ืืช ื–ื” ืื• ืชื–ื›ื•ืจ ืืช ื–ื”.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ืœืื—ืจ ืžื›ืŸ, ืœื—ืฅ ืœื—ื™ืฆื” ื™ืžื ื™ืช ืขืœ NSX Edge. ื‘ืชืคืจื™ื˜ ืฉืžื•ืคื™ืข ื‘ื—ืจ ื‘ืืคืฉืจื•ืช ืฉื™ืจื•ืชื™ Edge Gateway. ื•ื—ื–ืจื ื• ืœืœื•ื— ื”ื‘ืงืจื” ืฉืœ NSX Edge.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ื—ืœื•ืŸ ืฉืžื•ืคื™ืข, ืคืชื— ืืช ืœืฉื•ื ื™ืช NAT ื•ืœื—ืฅ ืขืœ ื”ื•ืกืฃ SNAT.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ื—ืœื•ืŸ ื”ื—ื“ืฉ ืื ื• ืžืฆื™ื™ื ื™ื:

  • ื‘ืฉื“ื” Applied on โ€“ ืจืฉืช ื—ื™ืฆื•ื ื™ืช (ืœื ืจืฉืช ื‘ืจืžืช ื”ืืจื’ื•ืŸ!);
  • ืžืงื•ืจ IP/ื˜ื•ื•ื— ืžืงื•ืจื™ - ื˜ื•ื•ื— ื›ืชื•ื‘ื•ืช ืคื ื™ืžื™, ืœื“ื•ื’ืžื”, 192.168.1.0/24;
  • ืžืงื•ืจ IP/ื˜ื•ื•ื— ืžืชื•ืจื’ื - ื”ื›ืชื•ื‘ืช ื”ื—ื™ืฆื•ื ื™ืช ืฉื“ืจื›ื” ืชื”ื™ื” ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ื•ืฉืื•ืชื” ื”ืกืชื›ืœืช ื‘ืœืฉื•ื ื™ืช Sub-alocate IP Pools.

ืœื—ืฅ ืขืœ ืฉืžื•ืจ.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ืฆื•ืจ ื›ืœืœ DNAT. DNAT ื”ื•ื ืžื ื’ื ื•ืŸ ืฉืžืฉื ื” ืืช ื›ืชื•ื‘ืช ื”ื™ืขื“ ืฉืœ ืžื ื” ื•ื›ืŸ ืืช ื™ืฆื™ืืช ื”ื™ืขื“. ืžืฉืžืฉ ืœื ื™ืชื•ื‘ ืžื—ื“ืฉ ืฉืœ ืžื ื•ืช ื ื›ื ืกื•ืช ืžื›ืชื•ื‘ืช/ื™ืฆื™ืื” ื—ื™ืฆื•ื ื™ืช ืœื›ืชื•ื‘ืช/ื™ืฆื™ืืช IP ืคืจื˜ื™ืช ื‘ืชื•ืš ืจืฉืช ืคืจื˜ื™ืช.

ื‘ื—ืจ ื‘ื›ืจื˜ื™ืกื™ื™ื” NAT ื•ืœื—ืฅ ืขืœ ื”ื•ืกืฃ DNAT.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื‘ื—ืœื•ืŸ ืฉืžื•ืคื™ืข, ืฆื™ื™ืŸ:

- ื‘ืฉื“ื” Applied on - ืจืฉืช ื—ื™ืฆื•ื ื™ืช (ืœื ืจืฉืช ื‘ืจืžืช ื”ืืจื’ื•ืŸ!);
- IP/ื˜ื•ื•ื— ืžืงื•ืจื™ - ื›ืชื•ื‘ืช ื—ื™ืฆื•ื ื™ืช (ื›ืชื•ื‘ืช ืžื”ื›ืจื˜ื™ืกื™ื™ื” Sub-Alocate IP Pools);
- ืคืจื•ื˜ื•ืงื•ืœ - ืคืจื•ื˜ื•ืงื•ืœ;
- ื™ืฆื™ืื” ืžืงื•ืจื™ืช - ื™ืฆื™ืื” ืœื›ืชื•ื‘ืช ื—ื™ืฆื•ื ื™ืช;
- IP/ื˜ื•ื•ื— ืžืชื•ืจื’ื - ื›ืชื•ื‘ืช IP ืคื ื™ืžื™ืช, ืœื“ื•ื’ืžื”, 192.168.1.10
โ€” Translated Port โ€“ ื™ืฆื™ืื” ืœื›ืชื•ื‘ืช ื”ืคื ื™ืžื™ืช ืฉืืœื™ื” ืชืชื•ืจื’ื ื”ื™ืฆื™ืื” ืฉืœ ื”ื›ืชื•ื‘ืช ื”ื—ื™ืฆื•ื ื™ืช.

ืœื—ืฅ ืขืœ ืฉืžื•ืจ.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื”ื—ืœ ืืช ื”ืชืฆื•ืจื” ืฉื”ื•ื–ื ื” ืขืœ ื™ื“ื™ ื‘ื—ื™ืจื” ืฉืžื•ืจ ืืช ื”ืฉื™ื ื•ื™ื™ื.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ืกื™ื™ืžืชื™.

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 2. ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื•-NAT

ื”ื‘ื ื‘ืชื•ืจ ื”ื•ื ื”ื•ืจืื•ืช ืขืœ DHCP, ื›ื•ืœืœ ื”ื’ื“ืจืช DHCP Bindings and Relay.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”