Cisco 887 NAT Issue

techmiss
techmiss used Ask the Experts™
on
Hi All,

I can't seem to get NAT working on my Cisco 887 Router, I have internet access on the device but when I NAT port 443 through to a web server it just times out.

I am trying to NAT through port 443 on the interface IP address to 10.7.100.44, I have attached the config.

Cheers

K
887clean.log
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Senior infrastructure engineer
Top Expert 2012
Commented:
Could it be a routing issue? I see that 10.7.100.44 is directly on the routers inside subnet but is accessed through another device (10.249.249.2) can you reach the 10.7.100.44 from the router?

Oh, I took the liberty of hiding the public IP from the config.

Author

Commented:
Hi Erniebeek, thanks for that, thought I sanitized it but didn't do a very good job!

I can ping 10.7.100.44 from the router...
Top Expert 2012

Commented:
Your routers internal ip is 10.249.249.3 yes?

What is this device - 10.249.249.2?

From your config you are passing traffic through that 249.3 device to get to 10.7.100.44, so there's another device in the loop which needs to be taken into consideration...

Author

Commented:
Hi, yes the 887 has an IP of 10.249.249.3, the .2 is a core switch, from that the web server is directly connected.

I'm pretty sure it's a NAT rule as the URL I have pointing to the public IP in question was giving me a login prompt for the 887 web page but since I added a rule for the web server that has stopped...!

Cheers

K

Author

Commented:
Was a routing issue to do with my internal network and the use of two internet breakouts from my core.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial