Solved

Cisco: NAT - OpenDNS

Posted on 2013-01-30
4
525 Views
Last Modified: 2013-01-31
I have 5 external IPs

10.10.10.1 - 10.10.10.5

10.10.10.1 Primary
10.10.10.2 Secondary on Cisco 2800

For OpenDNS to work it must see the WAN side IP of inbound DNS request. To have multiple filtering rules I need to use one WAN side IP per subnet translated.

The issues I have is that I can only get the system to see the WAN side address if I use a local DNS server NAT that to the WAN side IP....

What I want to do is skip the internal DNS server and have the DHCP give out the public DNS server IPs then have the entire subnet look like it's coming from the WAN side IP.

I want 172.16.0.0 / 24 to translate to 10.10.10.1 and 172.16.1.0  / 24 translating to 10.10.10.2


ip nat pool cahs_guest 10.10.10.1 10.10.10.1 netmask 255.255.255.224
ip nat pool cahs 10.10.10.2 10.10.10.2 netmask 255.255.255.224

ip nat inside source list 1 pool cahs  overload
ip nat inside source list 2 pool cahs_guest overload

Then I have the subnets in the pool.

The only way it is working is with:

ip nat inside source static 172.16.0.5 10.10.10.2
0
Comment
Question by:jpcoon
  • 2
4 Comments
 
LVL 15

Assisted Solution

by:Frabble
Frabble earned 125 total points
ID: 38837646
Presumably you also have:
access-list 1 permit ip 172.16.1.0 0.0.0.255
access-list 2 permit ip 172.16.0.0 0.0.0.255

and ip nat inside, ip nat outside on the required interfaces.

This should work. When you're attempting connections, what is the output from:
show ip nat translations
0
 
LVL 20

Accepted Solution

by:
rauenpc earned 125 total points
ID: 38838104
0
 

Author Comment

by:jpcoon
ID: 38841231
There was a typo in my ip nat pool statement
0
 

Author Closing Comment

by:jpcoon
ID: 38841233
Thanks for the direction
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question