配置acl ip access-list extended outacl 10 permit icmp any any 20 permit tcp host 101.1.1.1 host 90.1.1.10 eq 10022 #隐含一条默认拒绝
在outside接口调用acl,方向是in interface GigabitEthernet 0/1 ip access-group outacl in ip address 99.1.1.1 255.255.255.0 ip nat outside
查看NAT会话
Router#sh ip nat translations Pro Inside global Inside local Outside local Outside global tcp 101.1.1.1:50102 101.1.1.1:50102 90.1.1.10:10022 10.1.1.1:22