Cisco Router NAT setup

Posted on 2009-02-11
Last Modified: 2012-05-06
HI guys,
I have a network that is connected via site to site VPN's using BDSL internet connections and Cisco 1812 Routers.

I have set up static NAT entries on each router so users can access their terminal servers from home, however with this entry in place, users on other subnets cannot connect to the terminal server on other subnnets.

IE  one subnet is connected via VPN to subnet
On the router for the subnet, i have a static NAT entry, linking the terminal server ( to the outside interface.  
Users outside our network can connect through nat, however users on the subnet cannot connect with this NAT entry in place. If i take the entry out, all users on all subnets can connect again (obviously external users cannot)

I am thinking i need to set up an access list for the NAST setup, but am not really sure.

Thanks in advance!
Question by:digitalts
    1 Comment
    LVL 5

    Accepted Solution

    I think I understand the problem.

    With the static NAT in place external users can connect, to be expected, but VPN users cannot.  This indicates the NAT statement is being used in preference to the site to site VPN config.

    If you configure route map based NAT'ing I think it should sort you out.  Have a look at the following to get an idea what you may need:

    Basically, you want to match when a user from is accessing the server and not NAT so the traffic traverses the VPN, but do NAT when anyone else accesses the server.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Join & Write a Comment

    Suggested Solutions

    Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
    I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

    733 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    23 Experts available now in Live!

    Get 1:1 Help Now