Solved

Cisco Router 1700 Seies NAT configuration issues

Posted on 2004-04-20
11
1,181 Views
Last Modified: 2008-02-01
Ok I have a Cisco 1700 series hooked to a t-1. It's currently set up with nat polling.  What I would like to do is reconfigure the router to setup a firewall behind the router with external ips, but I don't know how to do it..  here is the current configuration:

User Access Verification

Password:
router>enable
Password:
% Password:  timeout expired!
Password:
% Password:  timeout expired!
Password:
remacc#show config
Using 1069 out of 29688 bytes
!
version 12.2
service config
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname router!
enable secret
enable password XXXXX
!
memory-size iomem 25
ip subnet-zero
!
!
!
!
interface FastEthernet0
 ip address 192.168.x.x 255.255.255.0
 ip nat inside
 speed auto
 full-duplex
!
interface Serial0
 no ip address
 ip nat outside
 encapsulation frame-relay IETF
 service-module t1 timeslots 1-24
 frame-relay lmi-type ansi
!
interface Serial0.540 point-to-point
 ip address 68.72.x.x 255.255.255.x
 ip nat outside
 frame-relay interface-dlci 540
!
ip nat pool net-1 68.78.x.x 68.78.x.x netmask 255.255.255.x
ip nat inside source list 1 pool net-1 overload
ip nat inside source static 192.168.x.x 68.78.x.x
ip classless
ip route 0.0.0.0 0.0.0.0 68.72.x.x
no ip http server
!
access-list 1 permit 192.168.x.x 0.0.0.255
access-list 104 permit tcp any any eq telnet
!
line con 0
line aux 0
line vty 0 4
 password xxxxxx
 login
!
no scheduler allocate
end

router#



Thanks In Advance

Nathan
0
Comment
Question by:nlockwood
11 Comments
 
LVL 13

Expert Comment

by:td_miles
Comment Utility
What size real IP address range do you have allocated to you ?
0
 
LVL 27

Expert Comment

by:Asta Cu
Comment Utility
0
 
LVL 1

Author Comment

by:nlockwood
Comment Utility
I have a block of 5 ips
0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
What about setting it up like this:

68.72.x.x(Router)192.168.0.1 ------ 192.168.0.2(Firewall)192.168.1.1 ------Network 192.168.1.0/24

Continue to NAT on the router for the inside network beyond the firewall.  You will need to setup the proper routes.

On the firewall:

0.0.0.0 0.0.0.0 192.168.0.1

On the router:

192.168.1.0 255.255.255.0 192.168.0.2
Same default gateway to your ISP.
0
 
LVL 1

Accepted Solution

by:
ekahan earned 500 total points
Comment Utility
Nathan,

If you are putting in a REAL firewall behind the router it makes the most sense to disable NAT on the router. So you would take one of the 68.68.x.x addresses and assign it to the Ethernet port of the router. You would take another 68.78.x.x address and assign it to the external interface of your firewall. You then would do all your NAT’ing on the firewall.
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 1

Author Comment

by:nlockwood
Comment Utility
Thanks ekahan.  

That's what I would like to do..    how do I go about removing nat on the router? I know how to add the stuff but not remove it....

0
 
LVL 1

Expert Comment

by:ekahan
Comment Utility
To remove the nat operation you would use these two commands to take NAT of the interfaces.

int fas 0
no ip nat inside

int s 0
no ip nat outside


If you want to remove the other NAT lines you would just type each nat line in with the word NO at the begining.


Eli
0
 
LVL 1

Expert Comment

by:ekahan
Comment Utility
For clarity:
This is what the commands are if you want to remove all the NAT lines in the configuration you posted.

Once you are in config mode type the following lines.

int fast  0
no ip nat inside
!
int s 0
no ip nat outside

!
no ip nat pool net-1 68.78.x.x 68.78.x.x netmask 255.255.255.x
no ip nat inside source list 1 pool net-1 overload
no ip nat inside source static 192.168.x.x 68.78.x.x

0
 
LVL 1

Author Comment

by:nlockwood
Comment Utility
oops silly me I got the commands..

Thanks Ekahan
0
 
LVL 1

Expert Comment

by:ekahan
Comment Utility
Great! Happy I could help. Please remember to accept the answer.

Eli
0
 
LVL 1

Author Comment

by:nlockwood
Comment Utility
Thanks for the help Eli...  I appericate it
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
VTP LOG RUNTTIME ERROR 31 125
What is SDWAN? 9 377
Switch Speed 2 57
iPad Won't Connect 16 27
It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now