Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Cisco NAT for exchange 2010

Posted on 2011-09-19
7
Medium Priority
?
382 Views
Last Modified: 2012-05-12
All, I have a cisco 1800 series router that I need to have an exchange server behind.  It's running IOS without the firewall enabled, rather, access is more or less turned off or on on a one by one basis.

I have an exchange server with the proper MX and A records at the ISP level.  The current configuration worked previously by doing a NAT translation inside and out like this:

ip nat pool exchange 192.168.1.7 192.168.1.7 netmask 255.255.255.255
ip nat inside source static network 192.168.1.7 66.66.66.123 /32
ip nat outside source static network 66.66.66.123 192.168.1.7 /32

This configuration worked with the Cisco 831 for over a year.  We did get an occasional IP conflict error when we had an outage and came back up, but I was always able to program around it by changing the NAT to another internal IP, then bringing up the server, then changing it back.  I realize this was a redneck solution, but it did work and I figured I'd figure out the issue later.

Later is now.

When we replaced the 831with a cisco 1800, it reports an IP conflict. at both the router, and server.  The NAT translation is using the address and the exchange server shows as 'no internet access' as you would expect from an IP conflict.  It is not resolveable by the workaround I previously mentioned.  The newer router is far less tolerant, it seems, of this kind of NAT/IP conflict.

I have no idea how it worked before given what I now know.  However, I'm not at all sure how to fix this going forward.  what is the correct way to make this work, using the IP information above?  I need to be sure that OWA access is available inside and outside the internal network, and that direct access through outlook is available internally.  Help!
0
Comment
Question by:John W
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 10

Expert Comment

by:SuperTaco
ID: 36564372
You don't need the nat pool for a static NAT.  Just the statement below it
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36565765
The only statement you need is: ip nat inside source static network 192.168.1.7 66.66.66.123 /32

The other two just mess things up ;)
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 1200 total points
ID: 36565782
After re-reading, also remove 'network'. So then you get:
ip nat inside source static 192.168.1.7 66.66.66.123

One other question, is the public ip the address of the outside interface or an extra one?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:John W
ID: 36596839
Sorry for the belated response.

The IP is not the same as the external interface, rather, an extra one as part of several we have.  DNS, MX records, etc are assigned to it to create mail.company.com / webmail.company.com and so forth.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36709808
Ok, then it should be like this.

Remove the three lines:
ip nat pool exchange 192.168.1.7 192.168.1.7 netmask 255.255.255.255
ip nat inside source static network 192.168.1.7 66.66.66.123 /32
ip nat outside source static network 66.66.66.123 192.168.1.7 /32


And replace them with:
p nat inside source static 192.168.1.7 66.66.66.123

Then let's see where that leads you.
0
 

Author Closing Comment

by:John W
ID: 36712052
Thanks so much!
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36712124
You're welcome :)
Thx for the points.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you looking for the options available for exporting EDB files to PST? You may be confused as they are different in different Exchange versions. Here, I will discuss some options available.
This month, Experts Exchange sat down with resident SQL expert, Jim Horn, for an in-depth look into the makings of a successful career in SQL.
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question