Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Cisco 2821 Port Forwarding

Posted on 2007-08-07
6
Medium Priority
?
1,388 Views
Last Modified: 2008-08-20
I wanted to make sure my config for port forwarding will work.  The ISP router is in bridge mode and I will have a Cisco 2821 sitting behind it handling the Internet and port forwarding.  I fairly comfortable forwarding ports on a PIX, but I have come to realize that I haven't had to forward too many ports on an actual router.  The objective is pretty simple,  Internet access for everyone and open up a few ports for Terminal Server, etc.

Here's what I have:

interface fastethernet 0/0
description Public IP address
ip address xxx.x.xx.106 255.255.255.248
ip nat outside
duplex auto
speed auto
no shut

interface fastethernet0/1
speed 100
full-duplex
no shut

interface fastethernet0/1.100
description DATA VLAN
encapsulation dot1q 100 native
ip address 192.168.0.1 255.255.255.0
ip nat inside
no shut

ip route 0.0.0.0 0.0.0.0 xxx.x.xx.105

ip nat pool poolone xxx.x.xx.106 xxx.x.xx.106 netmask 255.255.255.248
ip nat inside source list 20 pool poolone overload
ip nat inside source static tcp 192.168.0.11 3389 xxx.x.xx.106 3389 extendable

access-list 20 permit 192.168.0.0 0.255.255.255

Thanks for your time and help!
0
Comment
Question by:jplagens
6 Comments
 
LVL 9

Accepted Solution

by:
trinak96 earned 400 total points
ID: 19652298
Hi,
 
I would remove "p nat pool poolone xxx.x.xx.106 xxx.x.xx.106 netmask 255.255.255.248"
Change "ip nat inside source list 20 pool poolone overload" to : ip nat inside source list 20 interface fa0/0 overload
access-list 20 permit 192.168.0.0 0.0.0.255

Port forward looks good.
0
 
LVL 32

Assisted Solution

by:rsivanandan
rsivanandan earned 100 total points
ID: 19654422
Agree with the above, just copy paste these;

no ip nat nat pool poolone xxx.x.xx.106 xxx.x.xx.106 netmask 255.255.255.248
ip nat inside source list 20 int fa0/0 overload

ip nat inside source static tcp 192.168.0.11 3389 xxx.x.xx.106 3389 extendable

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 19654445
Also don't forget to do this immediately to clear the existing translations;

clear ip nat translations *

Cheers,
Rajesh
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 4

Author Comment

by:jplagens
ID: 19689027
Thanks for the help.  I set this up today and everything worked perfectly.

One more quick question.  What if I need to use a second public IP address such as xxx.x.xx.107 for another port?  Do I just add it such as:

ip nat inside source static tcp 192.168.0.100 443 xxx.x.xx.107 443 extendable

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 19689137
Yes Sir.

Cheers,
Rajesh
0
 

Expert Comment

by:tbrower
ID: 22271495
Hi I found this thread and I have a question, I have created a host A record to my Firewall but when I attempt the URL I am prompted for login credentials to the router through SDM .. Any idea on how to resolve this ?

Your help is appreciated

0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question