• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 4151
  • Last Modified:

Cisco 3750 routing question

I have a Cisco 3750 with IP routing turned on.
I have three VLANs configured 1,2,3.
VLAN 1 IP Address:
VLAN 2 IP Address:
VLAN 3 IP Address:

VLAN 3 is a network not in my control and will not route traffic from VLANs 1 and 2.  
Clients on VLANs 1 and 2 have each other's respective VLAN IP addresses configured as default gateways.

Is there a way to configure NAT on this Cisco that will allow me to communicate to the internet only through VLAN 3 (which has a proxy sever setting)?  Or a better way?
4 Solutions
Yes you could do that;

int <internet facing interface>
ip nat outside

int <vlan1>
ip nat inside

int <vlan2>
ip nat inside

ip nat inside source list 1 int <internet facing interface> overload

access-list 1 permit
access-list 1 permit

That should do it.

If you only want VLAN3 to communicate to the internet, then replace vlan1 & vlan2 above with vlan3 and only permit that subnet.
int <vlan3>
ip nat inside

access-list 1 permit

I don't think the 3750 switch supports NAT...

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

Under "Layer 2 Features" section


Q. Is Network Address Translation (NAT) supported?
A. No, there are no plans to support NAT.

You'll need a router to do NAT on a stick:

int fa0/24
description to router
switchport trunk encap dot1q
switchport trunk allowed vlan 1,2,3
switchport mode trunk

int fa0/0
description to switch
int fa0/0.1
description VLAN1
encap dot1q 1
ip nat inside
int fa0/0.2
description VLAN2
encap dot1q 2
ip nat inside
int fa0/0.3
description to Internet VLAN
encap dot1q 3
ip nat outside
ip nat inside source list 1 int fa0/0.3 overload
access-list 1 permit
access-list 1 permit

All Cisco switches support NAT, in order to get it though you have to have the enhanced image IOS version. Other than that rsivanandan is exactly right on how to acheive the result.
romatloAuthor Commented:
Jim Coyne,

Since there is a list of unsupported NAT commands for the 3750, does that mean that it should work just not supported?  Therefore rsivanandan's suggestion may work?


Do you know what version of IOS is considered enhanced?

Thanks, to everyone for your responses.  Allow me to try some of these suggestions before accepting answers.
Switch#config t
Switch(config)#ip nat ?
% Unrecognized command
Switch(config)#int fa0/1
Switch(config-if)#ip nat ?
% Unrecognized command

It's not available at all, you MUST do NAT on a stick if you want this to work. Anyone who tells you that you can NAT on a 3550, 3560 or 3750 is wrong, you can route but not NAT.
Standard multilayer image (SMI), which provides Layer 2+ features
(enterprise-class intelligent services). These features include access
control lists (ACLs), quality of service (QoS), static routing, and the
Hot Standby Router Protocol (HSRP) and the Routing Information Protocol
(RIP). Switches with the SMI installed can be upgraded to the EMI.

· Enhanced multilayer image (EMI), which provides a richer set of
enterprise-class intelligent services. It includes all SMI features
plus full Layer 3 routing (IP unicast routing, IP multicast routing,
and fallback bridging). To distinguish it from the Layer 2+ static
routing and RIP, the EMI includes protocols such as the Enhanced
Interior Gateway Routing Protocol (EIGRP) and the Open Shortest Path
First (OSPF) Protocol.
romatloAuthor Commented:
Thanks Jim.
I do not have a separate router...other than a linksys NAT router.  I wonder if I can make that work some how?
You need to find out if that model supports 802.1q (dot1q) trunking. If it does, you can use it. Although I would be careful not to overload it, since it's meant to be a 'home" router and not an enterprise solution.

I personally have a Linksys WRT54G loaded with DD-WRT firmware and I can dot1q trunk with it.

romatloAuthor Commented:
So I finally got it to work.
I hung the linksys off of VLAN 2 and gave it an internal static IP of and gateway of  I gave it a static external IP address, gateway, and DNS setting.  I then set a static route at the core to point any destination of 16.x.x.x to and put forwarder on my internal DNS to a 16.x.x.x address.  
So now clients on VLANs 1 and 2 try to resolve internet DNS requests to internal DNS first and then it forwards to a 16.x.x.x address which is taken care of with the static route to the linksys...and back.
Seems to work fine for now...  Thanks again for all the help.
Robert Sutton JrSenior Network ManagerCommented:
That was going to be my suggestion, static your route to your gateway in this case your Linksys and DNS resolution should occur.  
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Amazon Web Services - Basic

Are you thinking about creating an Amazon Web Services account for your business? Not sure where to start? In this course you’ll get an overview of the history of AWS and take a tour of their user interface.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now