Solved

NAT to resolve IP address conflict issue

Posted on 2010-11-28
3
808 Views
Last Modified: 2012-05-10
I have a task to help Company A for a join venture project, the network diagram as attached. The task requirements as following:

1.) Both company IP address cannot be modified

2.) Company A 10.1.99.0/24 segment can access Company B server SRV5 and SRV6, and also their own Company A server SRV1, SRV2 and SRV3.

3.) Company A Firewall NAT setting cannot be modified

4.) Company B 10.1.0.0/16 segment can access Company A server SRV1

Base on the above requirements, actually only R1 router under my control and the diagram can show you that both company IP address are conflicted, seems the NAT setting is required to achieve the goal. I have try to use the following NAT and routing setting on R1 as following but it totally doesn't work :(

int f0/0
ip nat inside

int S0/0
ip nat outside

ip nat inside source static 10.1.99.100 10.99.1.100
ip nat outside source static 10.1.1.100 10.10.10.100
ip nat outside source static 10.1.1.200 10.10.10.200

R1 routing table as following:

0.0.0.0 0.0.0.0 10.1.99.1
10.10.10.0 255.255.255.0 172.16.1.2

On R2 they have add a routing entry as following:

10.99.1.0 255.255.255.0 172.16.1.1

Any experts can help me please?????????????????? Many Thanks Diagram
0
Comment
Question by:gcl_hk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 10

Expert Comment

by:ujitnos
ID: 34228381
I feel that as both the server SRV1 and SRV4 have the same IP, it wont be possible to configure a NAT too. Either change one of the servver's IP or configure rules to a specific port.

Suppose the SRV4 is listening on port 1521 then confiure ruels in Company A to route traffic for SRV4:1521 to R2
0
 
LVL 6

Author Comment

by:gcl_hk
ID: 34229014
Thanks for your comment ujitnos.

Do you mean NAT on only R1 is impossible to solve this issue? Also, what do you mean of rules for specific port? But actually all SRV server is running http service, is this method can work as well.
0
 
LVL 10

Accepted Solution

by:
ujitnos earned 500 total points
ID: 34231320
Ok.. Lets say we configure (NAT, actual ip will remain 10.1.99.100) the SRV 4 with IP address 192.168.1.2/24.

so, Users in company A will access the server SVR4 with 192.168.1.2. You will need to configure routes in company A firewall to forward traffic for srv4 to R1, now in R1 configure routes to forward traffic to R2 of company B. Now either in R2 or firewall of company B do a NAT resolution to the actual IP 10.1.99.100.
Users in Company B will access SRV4 with IP 10.1.99.100, but they wont be able access SRV1 from Company B as traffic will always go to SRV4.

Try and let me know.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question