08-14-2007 08:37 AM - edited 03-03-2019 06:19 PM
i have two routers sitting on the same LAN. the first router provides the interface with ISP and PAT for outgoing traffic - router two has the static NAT entries for our www servers. Since both routers have routes to the www servers (10.10.10.x)how does the first (ISP) router know to send the traffic from the ISP to the dedicated NAT router.
if we have a www server that needs a static NAT we set the default gateway to the static NAT router rather than the ISP facing router.
i cant figure out why the ISP router doesnt send the packet directly to the www server and by passing the NAT router.
thanks in advance.
Solved! Go to Solution.
08-14-2007 08:43 AM
Hi Jerry
Just to confirm - the static NAT entries are done on router two.
So router 1 & router 2 both have an interface into your LAN 10.10.10.x. But when the traffic is coming from outside to your www server it is a natted address. Router 1 receives the packet but the destination is not a 10.10.10.x address because it hasn't been natted back by router 2 yet.
So router 1 arps out for the NAT address and router 2 responds, the packet gets sent to router 2 and then router 2 NATs to back to 10.10.10.x and sends it to the www server.
Hope this makes sense
Jon
08-14-2007 08:43 AM
Hi Jerry
Just to confirm - the static NAT entries are done on router two.
So router 1 & router 2 both have an interface into your LAN 10.10.10.x. But when the traffic is coming from outside to your www server it is a natted address. Router 1 receives the packet but the destination is not a 10.10.10.x address because it hasn't been natted back by router 2 yet.
So router 1 arps out for the NAT address and router 2 responds, the packet gets sent to router 2 and then router 2 NATs to back to 10.10.10.x and sends it to the www server.
Hope this makes sense
Jon
08-14-2007 08:58 AM
"So router 1 arps out for the NAT address"
router 1 arps looking for the private ip of the unNATted public ip?
thanks.
08-14-2007 09:07 AM
i got it!
(ARP) is the standard method for finding a host's hardware address when only its network layer address is known.
thanks.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: