Solved

Cisco: NAT - OpenDNS

Posted on 2013-01-30
4
520 Views
Last Modified: 2013-01-31
I have 5 external IPs

10.10.10.1 - 10.10.10.5

10.10.10.1 Primary
10.10.10.2 Secondary on Cisco 2800

For OpenDNS to work it must see the WAN side IP of inbound DNS request. To have multiple filtering rules I need to use one WAN side IP per subnet translated.

The issues I have is that I can only get the system to see the WAN side address if I use a local DNS server NAT that to the WAN side IP....

What I want to do is skip the internal DNS server and have the DHCP give out the public DNS server IPs then have the entire subnet look like it's coming from the WAN side IP.

I want 172.16.0.0 / 24 to translate to 10.10.10.1 and 172.16.1.0  / 24 translating to 10.10.10.2


ip nat pool cahs_guest 10.10.10.1 10.10.10.1 netmask 255.255.255.224
ip nat pool cahs 10.10.10.2 10.10.10.2 netmask 255.255.255.224

ip nat inside source list 1 pool cahs  overload
ip nat inside source list 2 pool cahs_guest overload

Then I have the subnets in the pool.

The only way it is working is with:

ip nat inside source static 172.16.0.5 10.10.10.2
0
Comment
Question by:jpcoon
  • 2
4 Comments
 
LVL 15

Assisted Solution

by:Frabble
Frabble earned 125 total points
ID: 38837646
Presumably you also have:
access-list 1 permit ip 172.16.1.0 0.0.0.255
access-list 2 permit ip 172.16.0.0 0.0.0.255

and ip nat inside, ip nat outside on the required interfaces.

This should work. When you're attempting connections, what is the output from:
show ip nat translations
0
 
LVL 20

Accepted Solution

by:
rauenpc earned 125 total points
ID: 38838104
0
 

Author Comment

by:jpcoon
ID: 38841231
There was a typo in my ip nat pool statement
0
 

Author Closing Comment

by:jpcoon
ID: 38841233
Thanks for the direction
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Router DMZ 5 79
Line cards, Supervisor, Control plane 7 37
RV042 site to site vpn can ping but not access server via rdp 6 28
DMVPN Spoke Connectivity Issue 1 25
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question