Solved

HELP! Can't access webpage from behind router. Need help with cisco ios (maybe).

Posted on 2006-11-12
4
479 Views
Last Modified: 2012-06-27
Hi,

I've got a webserver set up behind a cisco 877 router. Everything works fine in that I can access the webpages from external networks (i.e. the internet). I can't however access the webpages from inside my network. Here's a little example to make things clearer:

[Webserver 10.5.5.20] ------------------ [Router 150.x.x.82] --------------- [Internet]
[Home Computer 10.5.6.x] --------/

So say someone tries to connect to my webpage foo.bar.com from the internet, the router will translate that domain's external IP address of 150.x.x.82 to 10.5.5.20 and they will be able to see the webpage.

But, say I want to access that webpage from my home computer, the domain will still resolve to 150.x.x.82, and my router will get confused. The reasons why are beyond me.

So far I have fixed the problem by having an internal DNS server which forwards all requests but the ones specific to my domain, *.bar.com. All requests to that domain will instead resolve to the internal webserver address of 10.5.5.20. This solution is however no longer feasible -- I no longer want to host my own DNS server.

A MORE IDEAL SOLUTION would be to have all packets destined for 150.x.x.82, but originating from my internal network (or address range 10.5.6.x), to be translated to 10.5.5.20. This would enable my home computers to access my webpage without disrupting access from the internet.

Now for the money question:

Is it possible with my cisco 877 (IOS 12.4) to use nat or routing or whatever, to have it translate requests for 150.x.x.82, from both the internet AND my internal IP address range, to 10.5.5.20??? i.e.

[internet] -------> 150.x.x.82 -----> [ router 150.x.x.82 ] ----> 10.5.5.20 ------> [Webserver 10.5.5.20]
                                                                             \<-------- 150.x.x.82 <-------[Home Computer 10.5.6.x]

And/or would this even work?

If you read this far, thank you very very much. I'd give you points just for that if I could....
0
Comment
Question by:nulldaemon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 7

Accepted Solution

by:
dlangr earned 80 total points
ID: 17926943
see "Inside to Inside NAT - NAT Virtual Interface Support" at http://www.cisco.com/en/US/products/sw/iosswrel/ps5413/prod_release_note09186a0080457818.html . Probably works for the 877 as well.
0
 
LVL 9

Assisted Solution

by:PeterMac
PeterMac earned 45 total points
ID: 17932097
Without going into too much detail suspect using your router would not be possible - you would need multiple external IP addresses at minimum.

There is much easier way of replacing your internal DNS server if only Name you are interested in is your Webserver, and number of other PC's is limited.

Use Hosts File - In hosts file on each PC specify internal address of your Webserver against Domain Name - this will take precedence over externally resolved DNS for this address.
0
 

Author Comment

by:nulldaemon
ID: 18184405
Sorry, I have found myself too busy to pursue this further. While inside to inside nat looks like the answer, it confuses me too much how to apply it to my situation. In regards to PeterMac's post, I already have multile external IP addresses (though I fail to see how this relevant) and already use the hosts file solution, though this is hardly suffificient.

Thank you both for your help, but I have no time to pursue this issue any further at this moment.
0

Featured Post

Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Backup DNS routing 3 45
DNS and Promoting Server 2012R2 to DC Issues 10 49
patch status tool - free 9 61
Network VLAN 3 18
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question