[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

cisco router configuration of nat routing for computers inside the router

Posted on 2004-10-21
2
Medium Priority
?
369 Views
Last Modified: 2010-04-17
I have a router that i am connecting to my corperate network(172.16.7.xxx) to set up a private network(10.10.10.xxx). The router is assigned an external static address of 172.16.7.50 and internally it has an address of 10.10.10.1.  It uses DHCP and gives out addresses of 10.10.10.2 - 10.10.10.254 to internal computers using DHCP on the private network:  

    interface Ethernet0
       ip address 10.10.10.1 255.255.255.0
       ip nat inside
       no ip mroute-cache
       no cdp enable
       hold-queue 32 in
    !
    interface Ethernet1
       ip address 172.16.7.50 255.255.255.0
       ip nat outside
       no ip mroute-cache
       duplex auto
       no cdp enable

I also have some NAT entries defined in the router for example:

   ip nat inside source static tcp 10.10.10.2 8888 interface Ethernet1 8888

This allows a program on the corperate network to open 172.16.7.50:8888 and that port is translated to 10.10.10.2:8888 on my private network.  If i have a program on 10.10.10.2 that listens on port 8888 for connections everything works great.

Additonally from a computer in my private network say 10.10.10.3 I want to connect to  172.16.7.50:8888 (that is i would like the router to translate the address even if it is comming from an internal address).  

When i used a linksys router (RV042 or BEFVP41) this worked fine.  Now i am attempting this on a Cisco SOHO 91 (this router supports telnet and i want to change the configuration of the router programatically) i can open 172.16.7.50:8888 from a computer on the outside of the router (corperate network) but i cannot open 172.16.7.50:8888 from a computer on my private network (I can open 10.10.10.2:8888 from the private but i need it to be 172.16.7.50:8888 from the private network, so it goes through the router and the translation is provided).  

What configuration settings do i need for my Cisco router to provide the same functionality the the linksys router provided (I am sure it can be done judging by the configuration settings from the cisco router under telnet).
0
Comment
Question by:keith_gard
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 750 total points
ID: 12379443
You can with Linksys but not with Cisco.  On a Cisco router, static NAT translation only occurs when the packet enters the "nat outside" interface and exits the "nat inside" interface.  Even if it did work, would you really want all traffic to traverse the router when the server is on the same physical network?  You'd have greater performance accessing the server via the switched network versus the router providing translation.  
0
 
LVL 1

Author Comment

by:keith_gard
ID: 12381776
Here is what i would like to do:   On my private network i am setting up a load balancing solution (home brew).  I was using the router to locate the main server for registration of other computers (they would register 1 every minute, this is not a performance sensitive communication and is only used by my internal server application).  With the linksys router i would set up a nat entry that would specify one computer "main server" and the port to communicate on.  For example if i set up the nat to route 172.16.7.50 port 8888 to my internal address 10.10.10.2.  Then on each computer on the private network i would open port 172.16.7.50 and with the linksys router configured with the proper nat settings it would it would really open 10.10.10.2:8888.  Each private server could then send socket based xml packets to the "main server" and register with the main server.  

Again this works fine for the linksys routers.  

Additionally I would like to change the main server by just changing the router nat settings. I would do this if  "main server" fails by reconfiguring the router programatically (telnet).  This forces me to look at cisco routers since they support telnet and i can change the nat via  one of my functional servers (when they notice the main server is down). (BTW: for anyone who cares linksys RV042 says it supports telnet but really does not).  However i cannot get the cisco router to apply the nat translation even if i use what i think is an external address 172.16.7.50.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question