Cisco 2621xm Router Question

Is there a config that I can program into my router so it knows that when someone trys to pcanywhere a machine on my lan they can hit it with a wan address.

For example my router is and I give a client and address of which should automatically hit on a pcanywhere session, or is that only done on the firewall?
Chris StauntonCommented:
You can set up your router with Rmon to monitor this activity through snmp.  I'm not big on setting up anything like this however, check out the webpage for settings.


sragusa66Author Commented:
It's not that I want to monitor it but its the fact that I'm having an issue with this. I also have a shorewall firewall which I think I made the proper changes to but I'm starting to doubt this. This is the scenario; I need to have a machine on my internal lan be accessible by pcanywhere with an external ip so that the programmers can get into this machine without having to vpn into the internal network. Sometimes this works and sometimes it doesn't. Another problem that I'm running into is that clients on a verizon dsl connection cannot access my vpn or website and webmail. They can ping and trac route my router and I can do the same; so whats the problem? Both Verizon and Telcove who is my isp says they're not doing anything that would prohibit this. Is it my router or my firewall?
It sounds like you're looking for network address translation, so that someone on the outside would PCAnywhere to which would then be translated to an inside machine on
As mike said, NAT or PAT is the way to go. The url below should give you a basic understanding of the topic. Suggest you read through it and then post further questions.

Hope this helps.
The thing is, if you already have 192.168 on your LAN, something in your network is already performing NAT. If you'll post your current router configuration, leaving out passwords, we can tell you if the router is doing it and modify the config appropriately. If it's not the router it might be the firewall.

ip nat inside source list <acl_number> interface <outside_nat_interface> overload
ip inside source static tcp 3389 3389

acl_number = acl number detailing which IPs get nat'd

access-list 1 permit                     ----for example

Then from interface config mode add inside and outside NAT interfaces:

router(int-conf)#ip nat inside   - on inside interface
router(int-conf)#ip nat outside - on outside interface

one to one NAT is also a possibility

harbor235 ;}
>ip inside source static tcp 3389 3389
It's backwards, should be
>ip inside source static tcp 3389 3389

But all of it is moot if his current NAT isn't on the firewall.

