Solved

Cisco 3620 Sub Interfaces / NAT

Posted on 2004-03-28
3
542 Views
Last Modified: 2008-03-10
I am looking for some assistance in creating some
sub Interfaces and NAT on a CISCO 3620.


Here is what I am looking at doing.


Int 0/0.1  - 219.210.117.1 /25 (NO Nat)
Int 0/0.2  - 172.28.10.1   /23 (NAT Masquerade)
Int 0/0.3  - 172.28.12.1   /24 (NAT Masquerade)
Serial 0/0 - 219.63.168.10 /30

Default Route to 219.63.168.9 (via Serial 0/0)


I want Each Sub-Interface to be able to route to
the other sub interfaces and all to route to a the
internet via Serial 0/0 (T1 CSU/DSU).

I am running Cisco IOS ver 12.1(5)  and will be upgrading
to '12.3(5)' in the next couple of days.


Thanks for any help.

Mark Anderson

0
Comment
Question by:networkfrontier
  • 2
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 10700461
That's pretty easy if you want to nat  everything to the serial 0/0 interface address

interface serial 0/0
 ip nat outside
!
interface ethernet 0/0.1
 ip address 219.210.117.1 255.255.255.192

!
interface ethernet 0/0.2
 ip address 172.28.10.1 255.255.255.0
 ip nat inside
!
interface ethernet 0/0.3
 ip address 172.28.12.1 255.255.255.0
 ip nat inside
!
!
access-list 2 permit 172.28.10.0 0.0.0.255
access-list 2 permit 172.28.12.0 0.0.0.255
!
ip nat inside source list 2 interface serial0/0 overload
!

That's about all you have to do for simple nat

0
 

Author Comment

by:networkfrontier
ID: 10728261
lrmoore,

When I try this  I get :

% Configuring IP routing on a LAN subinterface is only allowed if that
subinterface is already configured as part of an IEEE 802.10, IEEE 802.1Q,
or ISL vLAN.

How do I get around this?

Mark Anderson
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 10728546
Assuming that your switch is using dot1Q vlan tagging:

interface ethernet 0/0.2
 encapsulation dot1Q 2  <-- VLAN #
 ip address 219.210.117.1 255.255.255.192

interface ethernet 0/0.3
 encapsulation dot1Q 3  <-- VLAN #
 ip address 219.210.117.1 255.255.255.192
!

Etc...
I was not sure if you were doing VLAN Ethernet sub-interfaces or serial sub-interfaces like on a frame-relay wan..


0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Classlful vs Classless subneting 18 73
URL question:  WWW versus WWW1 in address line 4 74
Local DNS and Home Routers 4 46
ASA 5505 not passing traffic to Netgear router 22 47
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question