[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Continue of Cisco 1721 and NAT Failover

Posted on 2004-11-02
5
Medium Priority
?
578 Views
Last Modified: 2008-02-01
I have a cisco 1721 with 2 ETh Wic's
Both WIC's are connected to broadband ISP connections with Static IP's

I use WIC1 (ISP1) for all the main Internet traffic, but I need it to failover to the other one when ISP1 is down.

Here is the ip route i use.  I have checked to see if the gateway of last resort works and it does.  When i pull the plug on ISP1 then the default gateway changes to ISP2 however....Internet connectivity stops completely.  I can still ping from the router itself but all internal pinging/browsing stops.  Any help would be much apprciated.

interface Ethernet0
 description ISP1
 ip address 208.x.x.x 255.255.255.248
 ip nat outside
 half-duplex
 crypto map clientmap
!
interface Ethernet1
 description ISP2
 ip address 24.x.x.x 255.255.252.0
 ip nat outside
 half-duplex
 crypto map clientmap
!
interface FastEthernet0
 description Local LAN
 ip address 192.168.3.1 255.255.252.0
 ip nat inside
 speed auto
!
ip local pool ippool 192.168.123.200 192.168.123.250
ip nat inside source route-map ROUTE-NAT interface Ethernet0 overload
ip nat inside source static tcp 192.168.0.231 25 24.x.x.x 25 extendable
ip nat inside source static tcp 192.168.3.250 80 24.x.x.x 80 extendable
ip nat inside source static tcp 192.168.0.231 25 208.x.x.x 25 extendable
ip classless
ip route 0.0.0.0 0.0.0.0 208.x.x.x 50
ip route 0.0.0.0 0.0.0.0 24.x.x.x 55

I can provide whatever else is needed.

0
Comment
Question by:dgratton1085
5 Comments
 
LVL 13

Expert Comment

by:td_miles
ID: 12480480
You don't have a NAT statement for the traffic to be NAt'ed to your second outside interface.
0
 

Author Comment

by:dgratton1085
ID: 12484186
Actually upon looking...my startup-config has boht entries in it (see below) but my running config only picks up the last one specified.  I tried entering it manually and it complianed that there was already a %Dynamic mapping in use, cannot change.

Here is the stratup-config

interface Ethernet0
 description ISP1
 ip address 208.x.x.x255.255.255.248
 ip nat outside
 half-duplex
 crypto map clientmap
!
interface Ethernet1
 description ISP2
 ip address 24.x.x.x 255.255.252.0
 ip nat outside
 half-duplex
 crypto map clientmap
!
interface FastEthernet0
 description Local LAN
 ip address 192.168.3.1 255.255.252.0
 ip nat inside
 speed auto
!
ip local pool ippool 192.168.123.200 192.168.123.250
ip nat inside source route-map ROUTE-NAT interface Ethernet0 overload
ip nat inside source route-map ROUTE-NAT interface Ethernet1 overload
ip nat inside source static tcp 192.168.0.231 25 24.x.x.x 25 extendable
ip nat inside source static tcp 192.168.3.250 80 24.x.x.x 80 extendable
ip nat inside source static tcp 192.168.0.231 25 208.x.x.x 25 extendable
ip classless
ip route 0.0.0.0 0.0.0.0 208.x.x.x 50
ip route 0.0.0.0 0.0.0.0 24.x.x.x 55

Any thoughts
0
 
LVL 11

Expert Comment

by:PennGwyn
ID: 12485043
Your ISP connections probably don't need to be half duplex....

The fact that only one dynamic NAT statement appears in the running config indicates that only one can be active at any given time.  I don't think you can do what you want -- failover AND NAT -- with a single router like this.  You could do it with BGP and your own public address space (requires the cooperation of both ISPs...), or I believe there are some SOHO routers with two Internet ports that are designed to do what you want (but aren't Cisco...).

0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12487449
Since this is a continuation of your previous post:

http://www.experts-exchange.com/Hardware/Routers/Q_21189366.html

We can try changing the nat statements like this:

ip nat inside source route-map ROUTE-NAT interface Ethernet0 overload
ip nat inside source list 2 interface Ethernet1 overload

access-list 2 permit 192.168.3.0 0.0.3.255

0
 
LVL 79

Accepted Solution

by:
lrmoore earned 1500 total points
ID: 13688775
Do you need more information?
Have you resolved this problem?
Can you close this question?
Thanks!
0

Featured Post

The new generation of project management tools

With monday.com’s project management tool, you can see what everyone on your team is working in a single glance. Its intuitive dashboards are customizable, so you can create systems that work for you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

612 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question