Solved

Cisco 831 NAT issue

Posted on 2007-11-26
9
935 Views
Last Modified: 2008-02-01
Here is the problem. We have Cisco router 831 (12.3(7)T) with some static translations. Problem is that NAT translations has stopped working couple of days ago with no changes from our or ISP side. After reviewing config i saw that on external interface is missing 'ip nat outside' so i went to add it. how many times we add it it is never written in config. Here is copy&paste.

cisco01#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
cisco01(config)#int eth1
cisco01(config-if)#ip nat outside
cisco01(config-if)#end
cisco01#

But however if we check config it will show it witout it and ofc routes will not work. Everything else will work, internet access and also VPN that is configured on those interfaces.  Does any1 has problem like this or a solution.

interface Ethernet0

 description Internal network

 ip address 192.168.0.1 255.255.255.0

 no ip redirects

 no ip proxy-arp

 ip nat inside

 ip route-cache flow

 ip tcp adjust-mss 1452

 no cdp enable

 crypto ipsec client ezvpn VPNacc inside

 hold-queue 32 in

!

interface Ethernet1

 description Outside

 ip address 192.168.2.2 255.255.255.0

 no ip redirects

 no ip proxy-arp

 duplex auto

 no cdp enable

 crypto ipsec client ezvpn VPNacc

Open in new window

0
Comment
Question by:RodeRidder
9 Comments
 
LVL 50

Expert Comment

by:Don Johnston
ID: 20351207
Do you get any type of notification or message that the command is rejected?
0
 

Author Comment

by:RodeRidder
ID: 20356533
Nope, as i showed in copy&paste:

cisco01#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
cisco01(config)#int eth1
cisco01(config-if)#ip nat outside
cisco01(config-if)#end
cisco01#

So everything looks ok, lika command is accepted, but when i do sh run, it is not there and also translations are not working.
0
 
LVL 7

Expert Comment

by:naughton
ID: 20362274
have you tried to tftp the runing config to a PC, putting in the "ip nat outside" command in the file in the area of the eth1 interface,  then tftp the file to the start up config and restart the router.
0
 

Author Comment

by:RodeRidder
ID: 20364738
No, did not try that, i will give a shot and report back here of result.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:RodeRidder
ID: 20365105
Ok tryed that. Downloaded config, added 'ip nat outside' line, puted back config but now i got an error:

cisco01#copy tftp: running-config
Address or name of remote host []? 192.168.0.3
Source filename []? cisco01-confg
Destination filename [running-config]?
Accessing tftp://192.168.0.3/cisco01-confg...
Loading cisco01-confg from 192.168.0.3 (via Ethernet0): !!
[OK - 8016 bytes]

%NAT: Error activating CNBAR on the interface Ethernet1
Error:Only one outside interface is allowed per ezvpn configuration
8016 bytes copied in 3.104 secs (2582 bytes/sec)
cisco01#sh run

and in sh run i got that lines.

Did wr mem and reload.

After reload BOTH lines are gone, both ip nat inside on one int and ip nat outside on other.

Any suggestions?
0
 
LVL 15

Expert Comment

by:wingatesl
ID: 20370996
You should definitely upgrade the IOS version
0
 

Author Comment

by:RodeRidder
ID: 20372024
Yes, i reded som of problems here that people had with CNBAR, and they said to go to 12.3.8. BUT, what puzzels me is that this worked for over of 3 years, on same router with no config changes. So one day just stopped working.
0
 
LVL 7

Accepted Solution

by:
naughton earned 500 total points
ID: 20377216
no no -
copy tftp start
reload

0
 

Author Comment

by:RodeRidder
ID: 20380357
Tryed that, same thing:

cisco01#copy tftp: start
Address or name of remote host []? 192.168.0.3
Source filename []? cisco01-confg
Destination filename [startup-config]?
Accessing tftp://192.168.0.3/cisco01-confg...
Loading cisco01-confg from 192.168.0.3 (via Ethernet0): !!
[OK - 8016 bytes]
[OK]
8016 bytes copied in 2.352 secs (3408 bytes/sec)
cisco01# reload

But after reload both lines with ip nat inside and outside are gone.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now