Solved

Wild card setting for NAT

Posted on 2010-08-18
6
794 Views
Last Modified: 2012-05-10
Hi

I put the Ip address for Fast ethernet 0/1

192.168.88.2 and subnet 255.255.255.192

then in NAt, i typed

configure terminal
ip access-list standard NAT_ADDRESS
permit 192.168.88.0 0.0.0.255


but still i is not allowing trafiq to go out side
also i added this line

ip nat inside source list NAT_ADDRESS interface FastEthernet 0/0 overload

and static router has right entry so that trafiq can go out

what i am thinking is bellow line

permit 192.168.88.0 0.0.0.255  -> permit 192.168.88.0 0.0.0.192

can any one please help me
thanks


0
Comment
Question by:fosiul01
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 2

Accepted Solution

by:
xephael earned 250 total points
ID: 33464888
The wildcard subnet mask for 255.255.255.192 is 0.0.0.63.

If you need help with NAT I would need to see the entire configuration.
0
 
LVL 29

Author Comment

by:fosiul01
ID: 33465041
why 63 ??

but i think the problem was different

for some reason, it was unable to use dns server of my isp router

but its working now by using

ip access-list standard NAT_ADDRESS
 permit 192.168.88.0 0.0.0.255
!

but why you said to use 63?
0
 
LVL 2

Assisted Solution

by:Paresh Patel
Paresh Patel earned 250 total points
ID: 33465988
While xephael is correct in his comment, 192.168.88.0 0.0.0.255 will work since it includes your subnet, 192.168.88.0/26 (255.255.255.192).

Since your network is 192.168.88.0 255.255.255.192, wildcard mask for ACL should be 0.0.0.63 so it only covers your network and not entire 192.168.88.0 255.255.255.0.
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 2

Expert Comment

by:jimhoodleeds
ID: 33484963
Can you post your config (hash out any confidential bits) and I'll take a look for you?
0
 
LVL 2

Expert Comment

by:xephael
ID: 33492462
"why 63?"

63+192=255 which is the maximum number for an IPv4 octet.  The wildcard is an inverse of a subnet mask.  For example the wildcard of subnet 255.255.255.0 is 0.0.0.255.  The wildcard of subnet 255.255.255.128 is 0.0.0.128.

Hope that makes sense.

Address:      192.168.88.2      11000000.10101000.01011000.00   000010
Netmask:      255.255.255.192 = 26      11111111.11111111.11111111.11   000000
Wildcard:      0.0.0.63      00000000.00000000.00000000.00   111111
Network:      192.168.88.0      11000000.10101000.01011000.00   000000      (Class C)
Broadcast:      192.168.88.63      11000000.10101000.01011000.00   111111
HostMin:      192.168.88.1      11000000.10101000.01011000.00   000001
HostMax:      192.168.88.62      11000000.10101000.01011000.00   111110
Hosts/Net:      62      ( RFC-1918 Private Internet Address. )

0
 
LVL 2

Expert Comment

by:xephael
ID: 33492473
255.255.255.128 is 0.0.0.127 (messed up ;)
0

Featured Post

Webinar June 1st - Attacking Ransomware  

The global cyberattack that corrupted hundreds of thousands of computer systems on May 12th had a face, name, & price tag that we’ve seen all too often in recent years: Ransomware. With the stakes – and costs – of a ransomware attack higher than ever, is your business prepared ?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question