Solved

NAT problems on Cisco 890

Posted on 2010-11-15
10
1,186 Views
Last Modified: 2012-05-10
Hey everyone

Ok, here is the problem.

I have a CISCO 890 router and I can setup port forwarding and the people from the outside can get to the servers with no issues, but the people inside the network cannot get to the local server using the public IP address.  Now, here is where it gets tricky.

The server in question is an IP camera server, and so its not on the domain nor does it get its DNS from a local DNS server.  Of course, now that I mention all of that, I will have to ask the camera guy if the PC could join the domain and use the local DNS server.  But, if that cannot be done, is there a way to setup NAT loopback (if thats the proper term) on a CISCO 890?

Now, here is the crutch of it all.  Right now they have a RVO42 and it works fine.  They are trying to upgrade their router and the 890 was the one that they picked out.

Thanks for any help!!
0
Comment
Question by:jonmenefee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
10 Comments
 
LVL 5

Expert Comment

by:mittermueller
ID: 34136935
Why not use a network name for the camera and configure your DNS to point to it?
0
 

Author Comment

by:jonmenefee
ID: 34136991
that would be a reverse setting right?  or a forwarding setting in the DNS?
0
 
LVL 5

Expert Comment

by:mittermueller
ID: 34137222
Forward - as your clients query camera_name.domain.local
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:jonmenefee
ID: 34167994
Naw, didnt work.  What I dont understand is this.  How can a Linksys RV042 router do this without making anything special, but a Cisco 892 cant do this?

Can anyone out there tell me this?
0
 
LVL 5

Expert Comment

by:mittermueller
ID: 34168204
What I do not understand: Why are you acessing it from internal with a public ip?
0
 

Author Comment

by:jonmenefee
ID: 34168295
The camera system requires it. I asked the camera guy and he said that the software is setup that way. Is it dumb?  Yes
0
 
LVL 1

Expert Comment

by:danielc25
ID: 34168504
What is the local subnet and route information on the 890? Do you have seperate VLANs configured on the 890 for the inside networks?
0
 

Author Comment

by:jonmenefee
ID: 34168583
No. Same subnet. Should I put them on separate VLANS?  Damn. Didn't think of that. Local subnet is 192.168.1.0 - 255. The DHCP is from the router and is 50 - 255. Left the lower ones for the servers and printers.  I am on my cell now so I don't have the rest of the route configuration. I can post it here later
0
 

Accepted Solution

by:
jonmenefee earned 0 total points
ID: 34306954
Ok.  The customer came up with a solution.  They went ahead and purchased another Internet connection from Comcast.  They will put all of their security cameras and DVR one one network and their PC's, servers and printers on a separate one.  Made my life much easier :-)
0
 

Author Closing Comment

by:jonmenefee
ID: 34424548
Unfortunately I could not get an answer from here that would solve the problem
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ACL Logging Optimization 7 47
configure ASA Vlan Interface 14 90
DMVPN Spoke Connectivity Issue 1 60
ospf neighbors not coming up 6 71
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question