прописал на внешнем интерфейсе еще один адрес.
привязал трансляцию порта к определенному адресу.!
interface GigabitEthernet0/0
ip address aaa.bbb.ccc.202 255.255.255.248 secondary
ip address aaa.bbb.ссс.203 255.255.255.248
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
ip nat inside source static tcp 10.0.0.100 443 aaa.bbb.ccc.202 443 extendable
пробую запустить телнет прямо с маршрутизатора, вижу следующее:
telnet aaa.bbb.ccc.202 443
Trying aaa.bbb.ccc.202, 443 ...
*Nov 22 10:45:45.241: NAT: [0] Allocated Port for SYSTEM prot 6: aaa.bbb.ccc.203, 38938
*Nov 22 10:45:45.241: NAT - SYSTEM PORT for aaa.bbb.ccc.203: allocated port 38938, refcount 1, localport 4294967295, localaddr 0.0.0.0, flags 1, syscount 1, proto 6
*Nov 22 10:45:45.245: tcp0: O CLOSED aaa.bbb.ccc.202:443 aaa.bbb.ccc.203:38938 seq 2644901721
OPTS 4 SYN WIN 4128
*Nov 22 10:45:45.245: NAT: o: tcp (aaa.bbb.ccc.203, 38938) -> (aaa.bbb.ccc.202, 443) [15741]
*Nov 22 10:45:45.245: NAT: s=aaa.bbb.ccc.203, d=aaa.bbb.ccc.202->10.0.0.100 [15741]
*Nov 22 10:45:45.245: NAT - SYSTEM PORT for aaa.bbb.ccc.203: allocated port 0, refcount 49, localport 4294967295, localaddr 0.0.0.0, flags 1, syscount 49, proto 6
*Nov 22 10:45:45.245: tcp0: I LISTEN 10.0.0.100:443 aaa.bbb.ccc.203:38938 seq 4265545176
OPTS 4 ACK 2644901722 SYN WIN 8192
*Nov 22 10:45:45.245: TCP: sent RST to 10.0.0.100:443 from aaa.bbb.ccc.203:38938
*Nov 22 10:45:47.245: tcp0: R SYNSENT aaa.bbb.ccc.202:443 aaa.bbb.ccc.203:38938 seq 2644901721
OPTS 4 SYN WIN 4128
*Nov 22 10:45:47.245: NAT: o: tcp (aaa.bbb.ccc.203, 38938) -> (aaa.bbb.ccc.202, 443) [15741]
*Nov 22 10:45:47.245: NAT: s=aaa.bbb.ccc.203, d=aaa.bbb.ccc.202->10.0.0.100 [15741]
*Nov 22 10:45:47.245: NAT - SYSTEM PORT for aaa.bbb.ccc.203: allocated port 0, refcount 50, localport 4294967295, localaddr 0.0.0.0, flags 1, syscount 50, proto 6
*Nov 22 10:45:47.245: tcp0: I LISTEN 10.0.0.100:443 aaa.bbb.ccc.203:38938 seq 4266043774
OPTS 4 ACK 2644901722 SYN WIN 8192
*Nov 22 10:45:47.245: TCP: sent RST to 10.0.0.100:443 from aaa.bbb.ccc.203:38938
*Nov 22 10:45:51.245: tcp0: R SYNSENT aaa.bbb.ccc.202:443 aaa.bbb.ccc.203:38938 seq 2644901721
OPTS 4 SYN WIN 4128
*Nov 22 10:45:51.245: NAT: o: tcp (aaa.bbb.ccc.203, 38938) -> (aaa.bbb.ccc.202, 443) [15741]
*Nov 22 10:45:51.245: NAT: s=aaa.bbb.ccc.203, d=aaa.bbb.ccc.202->10.0.0.100 [15741]
*Nov 22 10:45:51.245: NAT - SYSTEM PORT for aaa.bbb.ccc.203: allocated port 0, refcount 51, localport 4294967295, localaddr 0.0.0.0, flags 1, syscount 51, proto 6
*Nov 22 10:45:51.245: tcp0: I LISTEN 10.0.0.100:443 aaa.bbb.ccc.203:38938 seq 4267078070
OPTS 4 ACK 2644901722 SYN WIN 8192
*Nov 22 10:45:51.245: TCP: sent RST to 10.0.0.100:443 from aaa.bbb.ccc.203:38938
*Nov 22 10:45:59.245: tcp0: R SYNSENT aaa.bbb.ccc.202:443 aaa.bbb.ccc.203:38938 seq 2644901721
OPTS 4 SYN WIN 4128
*Nov 22 10:45:59.245: NAT: o: tcp (aaa.bbb.ccc.203, 38938) -> (aaa.bbb.ccc.202, 443) [15741]
*Nov 22 10:45:59.245: NAT: s=aaa.bbb.ccc.203, d=aaa.bbb.ccc.202->10.0.0.100 [15741]
*Nov 22 10:45:59.245: NAT - SYSTEM PORT for aaa.bbb.ccc.203: allocated port 0, refcount 52, localport 4294967295, localaddr 0.0.0.0, flags 1, syscount 52, proto 6
*Nov 22 10:45:59.245: tcp0: I LISTEN 10.0.0.100:443 aaa.bbb.ccc.203:38938 seq 4269136271
OPTS 4 ACK 2644901722 SYN WIN 8192
*Nov 22 10:45:59.245: TCP: sent RST to 10.0.0.100:443 from aaa.bbb.ccc.203:38938
% Connection timed out; remote host not responding