Solved

Cisco router 87x - Combining NAT & VPNs

Posted on 2009-05-15
10
488 Views
Last Modified: 2013-11-16
Hi,

We have Cisco 87x routers and 2 sites lets call them siteA and siteB.  There is a Cisco VPN tunnel between siteA and siteB setup using the SDM Wizard.

The problem we have is if we create any incoming NAT rules like the following -
At SiteA incoming NAT rule for SMTP to 192.168.0.1
Then from SiteB no-one can connect to SMTP at 192.168.0.1

This is the same for any NAT rule I create coming into SiteA then becomes unavailable for SiteB users.  Why is this?  What can I do about it?

Thankyou


0
Comment
Question by:nmxsupport
  • 5
  • 5
10 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
Comment Utility
You can exclude the servers from NAT when talking to the SiteB subnet.

For example:

conf t
ip access-list ext static-no-nat
deny ip any 192.168.x.0 0.0.0.255   <--site B subnet
permit ip any any

route-map static-no-nat permit 10
 match ip address static-no-nat

no ip nat inside source static tcp 192.168.0.1 25 x.x.x.x 25
ip nat inside source static tcp 192.168.0.1 25 x.x.x.x 25 route-map static-no-nat
0
 

Author Comment

by:nmxsupport
Comment Utility
Unfortunately it looks like the 800 series routers may not support the "route-map" command
I tried but it said % invalid input at the "route-map" command
0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
The route-map on the static NAT statement or just adding the route-map?
0
 

Author Comment

by:nmxsupport
Comment Utility
It was the route-map on the static NAT statement
0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
Yeah, figured, you'll need to upgrade for it to work.  Can you post a "show version"?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:nmxsupport
Comment Utility
I found out the route-map command is not valid with my static IP addresses with the following line
ip nat inside source statip tcp 192.168.1.1 25 interface Dialer0 25
but will work with the following
ip nat inside source static tcp 192.168.1.1 25 81.201.22.11 25  
0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
Yeah, sorry, should have mentioned.  I assumed you were specifying an IP address.  Does it take care of the issue using that config?
0
 

Author Comment

by:nmxsupport
Comment Utility
I have overlooked this issue I will have another go if JFrederick29 is still available to assist?
0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
Yep, I am available.  Let me know if that config works.
0
 

Author Comment

by:nmxsupport
Comment Utility
Yes worked fine thankyou.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now