cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
979
Views
0
Helpful
8
Replies

My route-map does not send vlan traffic on a appropriate interface

Hello for everyone

Please help me.

I have this problem scenario:

The router Cisco 2851 with c2800nm-advipservicesk9-mz.124-19.bin.

Several VLAN’s have been configured on the router:

Dasha#sh vlan-switch

VLAN Name                             Status    Ports

---- -------------------------------- --------- -------------------------------

1    default                          active    Fa0/1/0, Fa0/1/1, Fa0/1/2

                                                Fa0/1/3

2    VLAN0002                         active

3    VLAN0003                         active

4    VLAN0004                         active

10   VLAN0010                         active    Fa0/0/0

20   VLAN0020                         active    Fa0/0/2

30   VLAN0030                         active

40   VLAN0040                         active    Fa0/0/1

100  VLAN0100                         active

151  VLAN0151                         active

155  fl-guest                         active    Fa0/0/3

200  VLAN0200                         active

207  VLAN0207                         active

1002 fddi-default                     active

1003 token-ring-default               active

1004 fddinet-default                  active

1005 trnet-default                    active

The router is one of the several other routers in my WAN network. It is connected to other router (R1) through VPN Site-to-Site over GRE for access to main Internet service provider (ISP1). All Cisco 2851 VLAN’s is going to the Internet through R1. All except VLAN 155 fl-guest that is intended to go to reserve (back up) ISP2. This ISP2 is directly connected to the Cisco 2851 that I’m talking about.

I think it can be done by route-map. I have configured my Cisco 2851 for the route-map.  I see policy routing matches but users in VLAN 155 cannot access Internet through ISP2. And I cannot ping 8.8.8.8 source vlan 155.

Below I present config parts of the Cisco 2851 and some show outputs. If you need more information, please tell me.

---------------------------------------------------------

VLAN 155

Interface                  IP-Address      OK? Method Status                Protocol

Vlan155                    10.8.0.1        YES manual up                    up

Dasha#sh run | b interface Vlan155

interface Vlan155

ip address 10.8.0.1 255.255.255.0

ip nat inside

ip nat enable

ip virtual-reassembly

ip policy route-map fl-guest

Dasha#sh run | b interface FastEthernet0/0/3

interface FastEthernet0/0/3

description fl-guest

switchport access vlan 155

Dasha#ping 8.8.8.8 source vlan 155

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:

Packet sent with a source address of 10.8.0.1

.....

Success rate is 0 percent (0/5)

----------------------------------------------------------------

VLAN 20

Interface                  IP-Address      OK? Method Status                Protocol

Vlan20                     [global ip addr]   YES NVRAM  up                    up

Dasha#sh run | b interface Vlan20

interface Vlan20

description --=== Internet "Sputnik" ===--

ip address [global ip addr] 255.255.255.252

ip access-group FILTER_TO_INTERNET out

no ip redirects

no ip proxy-arp

ip nat outside

ip nat enable

ip virtual-reassembly

crypto map dynamic-l2tp

Dasha#sh run | b interface FastEthernet0/0/2

interface FastEthernet0/0/2

description --== SPUTNIK ==--

switchport access vlan 20

Dasha#ping 8.8.8.8 source vlan 20

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:

Packet sent with a source address of 80.122.174.90

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 312/314/316 ms

---------------------------------------------------------------------

NAT and ACL

ip nat inside source list NAT_TO_SPUTNIK interface Vlan20 overload

ip access-list extended FILTER_TO_INTERNET

permit tcp 10.2.0.0 0.0.3.255 any eq www

permit ip 10.8.0.0 0.0.0.255 any log

permit tcp 10.2.0.0 0.0.3.255 any eq 443

permit tcp 10.2.0.0 0.0.3.255 any eq ftp

permit tcp 10.2.0.0 0.0.3.255 any eq ftp-data

permit udp 10.2.0.0 0.0.3.255 any eq ntp

permit tcp 10.2.0.0 0.0.3.255 any eq 8080

permit tcp 10.4.0.0 0.0.3.255 any eq www

permit tcp 10.4.0.0 0.0.3.255 any eq 443

permit tcp 10.4.0.0 0.0.3.255 any eq ftp

permit tcp 10.4.0.0 0.0.3.255 any eq ftp-data

permit udp 10.4.0.0 0.0.3.255 any eq ntp

permit tcp 10.4.0.0 0.0.3.255 any eq 8080

permit tcp 10.2.4.0 0.0.3.255 any eq 443

permit tcp 10.2.4.0 0.0.3.255 any eq ftp

permit tcp 10.2.4.0 0.0.3.255 any eq ftp-data

permit udp 10.2.4.0 0.0.3.255 any eq ntp

permit tcp 10.2.4.0 0.0.3.255 any eq 8080

ip access-list extended NAT_TO_SPUTNIK

deny   ip 10.2.0.0 0.0.3.255 10.4.0.0 0.0.0.255

deny   ip 10.4.0.0 0.0.3.255 10.2.0.0 0.0.0.255

deny   ip 10.2.0.0 0.0.3.255 10.2.4.0 0.0.0.255

deny   ip 10.2.4.0 0.0.0.255 10.2.0.0 0.0.3.255

deny   ip 10.2.4.0 0.0.0.255 10.4.0.0 0.0.0.255

permit ip 10.2.0.0 0.0.3.255 any

permit ip 10.4.0.0 0.0.3.255 any

permit ip 10.2.4.0 0.0.0.255 any

permit ip 10.8.0.0 0.0.0.255 any log

--------------------------------------------------------------------------------------

PBR

access-list 101 permit ip 10.8.0.0 0.0.0.255 any

route-map fl-guest permit 10

match ip address 101

set ip default next-hop 80.122.174.89 80.122.174.90

set default interface Vlan20 FastEthernet0/0/2

Also I tried different other variations with set command.

--------------------------------------------------------------------------

Dasha#sh route-map

route-map fl-guest, permit, sequence 10

  Match clauses:

    ip address (access-lists): 101

  Set clauses:

    default interface Vlan20 FastEthernet0/0/2

  Policy routing matches: 1447 packets, 121185 bytes

With kind regards

Sergey Bondarenko

skype: sergio.bondarenko

ICQ: 435 129 759

sergey.bondarenko.grey@gmail.com

1 Accepted Solution

Accepted Solutions

Hi,

I think there is a single ICMP entry for 80.122.174.90 in your nat table which is bind to 10.8.0.1.

Can you try either to clear it and then ping from your laptop or try something else from your laptop like http or telnet

HTH

Laurent.


View solution in original post

8 Replies 8

Laurent Aubert
Cisco Employee
Cisco Employee

Hi,

By default, a policy-map doesn't apply to packets locally generated by the router. You need to add the following command:

ip local policy route-map fl-guest

Also here is the config you should use:

route-map fl-guest permit 10

match ip address 101

set ip next-hop 80.122.174.89

!

This way VLAN 155 will use ISP2 until the VLAN interface get down.

HTH

Laurent.

Thank you for your answer Laurent.

I have implemented your proposed commands. And now I can ping through ISP2 with source of 10.8.0.1 (VLAN 155 address).

But when I connect my notebook to the router Ethernet port to which VLAN 155 is assigned (switchport access vlan155) I receive ip addr from dhcp server and gateway 10.8.0.1. And I cannot ping even 10.8.0.1.

From the router I cannot ping ip addr of my notebook (10.8.0.2).

What do you think about it?

The route-map you applied on VLAN155 allow you to bypass the routing table for routing decision. So each packet received on VLAN155 will be send to ISP2 regardless the destination so what you see is expected.

Can you browse the Internet ? It should work.

If you want to be able locally ping between your device and router, you need to be more granular in your route-map ACL by denying any traffic which destination is 10.8.0.0/24 subnet so the routing table will be used instead.

HTH

Laurent.

Hello Laurent


Thanks for your hint about ACL.


I have edited my ACL so now it looks:

Dasha#sh access-lists 101

Extended IP access list 101

    5 deny ip any 10.8.0.0 0.0.0.255 (1382 matches)

    10 permit ip 10.8.0.0 0.0.0.255 any (39364 matches)

And now I can ping my notebook (10.8.0.2) from the router and backwards.

But unfortunately I cannot ping 8.8.8.8 from my notebook (10.8.0.2) that is in VLAN 155.

Here I present the debug ip policy output:

Dasha#, len 100, policy rejected -- normal forwarding
Jul 10 08:39:20.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, FIB policy match
Jul 10 08:39:20.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, g=80.122.174.89, len 62, FIB policy routed
Jul 10 08:39:20.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, policy match
Jul 10 08:39:20.421: IP: route map fl-guest, item 10, permit
Jul 10 08:39:20.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8 (Vlan20), len 62, policy routed
Jul 10 08:39:20.421: IP: Vlan155 to Vlan20 80.122.174.89

Jul 10 08:39:20.837: IP: s=192.168.1.2 (local), d=192.168.1.220, len 52, policy rejected -- normal forwarding
Dasha#terminal monitor
Jul 10 08:39:20.869: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:20.869: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:21.309: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:21.309: IP: s=192.168.1.2 (local), d=192.168.1.1, len 156, policy rejected -- normal forwarding
Jul 10 08:39:21.309: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:21.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, FIB policy match
Jul 10 08:39:21.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, g=80.122.174.89, len 62, FIB policy routed
Jul 10 08:39:21.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, policy match
Jul 10 08:39:21.421: IP: route map fl-guest, item 10, permit
Jul 10 08:39:21.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8 (Vlan20), len 62, policy routed
Jul 10 08:39:21.421: IP: Vlan155 to Vlan20 80.122.174.89

Jul 10 08:39:21.513: IP: s=80.122.174.90 (local), d=66.223.219.48, len 40, policy rejected -- normal forwarding
Jul 10 08:39:21.541: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:21.661: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:22.037: IP: s=10.8.0.2 (Vlan155), d=10.1.0.1, len 48, FIB policy match
Jul 10 08:39:22.037: IP: s=10.8.0.2 (Vlan155), d=10.1.0.1, g=80.122.174.89, len 48, FIB policy routed
Jul 10 08:39:22.037: IP: s=10.8.0.2 (Vlan155), d=10.1.0.1, len 48, policy match
Jul 10 08:39:22.037: IP: route map fl-guest, item 10, permit
Jul 10 08:39:22.037: IP: s=10.8.0.2 (Vlan155), d=10.1.0.1 (Vlan20), len 48, policy routed
Jul 10 08:39:22.037: IP: Vlan155 to Vlan20 80.122.174.89

Jul 10 08:39:22.309: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:22.309: IP: s=192.168.1.2 (local), d=192.168.1.1
Dasha#terminal mon, len 444, policy rejected -- normal forwarding
Jul 10 08:39:22.313: IP: s=192.168.1.2 (local), d=192.168.1.220, len 100, policy rejected -- normal forwarding
Jul 10 08:39:22.337: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:22.337: IP: s=192.168.1.2 (local), d=192.168.1.1, len 204, policy rejected -- normal forwarding
Jul 10 08:39:22.341: IP: s=192.168.1.2 (local), d=192.168.1.1, len 236, policy rejected -- normal forwarding
Jul 10 08:39:22.341: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:22.341: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:22.345: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:22.345: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:22.349: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:22.349: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:22.357: IP: s=192.168.1.2 (local), d=192.168.1.39, len 100, policy rejected -- normal forwarding
Jul 10 08:39:22.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 156, policy rejected -- normal forwarding
Jul 10 08:39:22.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:22.373: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:22.437: IP: s=192.168.1.2 (local), d=192.168.1.4, len 52, policy rejected -- normal forwarding
Jul 10 08:39:22.577: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:22.585: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:22.725: IP: s=80.122.174.90 (local), d=80.122.174.89, len 64, policy rejected -- normal forwarding
Jul 10 08:39:22.725: IP: s=172.17.0.10 (local), d=172.17.0.9, len 64, policy rejected -- normal forwarding
Jul 10 08:39:22.725: IP: s=172.16.0.6 (local), d=172.16.0.5, len 64, policy rejected -- normal forwarding
Jul 10 08:39:22.817: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.061: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.173: IP: s=192.168.1.2 (local), d=192.168.1.30, len 52, policy rejected -- normal forwarding
Jul 10 08:39:23.261: IP: s=192.168.1.2 (local), d=192.168.1.162, len 100, policy rejected -- normal forwarding
Jul 10 08:39:23.309: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.345: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:23.345: IP: s=192.168.1.2 (local), d=192.168.1.1, len 460, policy rejected -- normal forwarding
Jul 10 08:39:23.349: IP: s=192.168.1.2 (local), d=192.168.1.1, len 188, policy rejected -- normal forwarding
Jul 10 08:39:23.353: IP: s=192.168.1.2 (local), d=192.168.1.1, len 252, policy rejected -- normal forwarding
Jul 10 08:39:23.353: IP: s=192.168.1.2 (local), d=192.168.1.1
Dasha#terminal m, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.353: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.353: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.353: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.357: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.357: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.361: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.361: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.361: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:23.361: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.365: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.365: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:23.373: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.373: IP: s=192.168.1.2 (local), d=192.168.1.1, len 140, policy rejected -- normal forwarding
Jul 10 08:39:23.373: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:23.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, FIB policy match
Jul 10 08:39:23.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, g=80.122.174.89, len 62, FIB policy routed
Jul 10 08:39:23.449: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, policy match
Jul 10 08:39:23.449: IP: route map fl-guest, item 10, permit
Jul 10 08:39:23.449: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8 (Vlan20), len 62, policy routed
Jul 10 08:39:23.449: IP: Vlan155 to Vlan20 80.122.174.89

Jul 10 08:39:23.541: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.849: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:23.993: IP: s=192.168.1.2 (local), d=192.168.1.7, len 100, policy rejected -- normal forwarding
Jul 10 08:39:24.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:24.369: IP: s=192.168.1.2 (local), d=192.168.1.1, len 476, policy rejected -- normal forwarding
Jul 10 08:39:24.385: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:24.385: IP: s=192.168.1.2 (local), d=192.168.1.1, len 156, policy rejected -- normal forwarding
Jul 10 08:39:24.385: IP: s=192.168.1.2 (local), d=192.168.1.1, len 268, policy rejected -- normal forwarding
Jul 10 08:39:24.389: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.389: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.389: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.389: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.389: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.393: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.393: IP: s=192.168.1.2 (local), d=192.168.1.1
Dasha#terminal n, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.393: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.397: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.397: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.397: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.397: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.421: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.421: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.421: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.421: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.429: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.429: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.429: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:24.433: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.433: IP: s=192.168.1.2 (local), d=192.168.1.1, len 300, policy rejected -- normal forwarding
Jul 10 08:39:24.433: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:24.433: IP: s=192.168.1.2 (local), d=192.168.1.1, len 124, policy rejected -- normal forwarding
Jul 10 08:39:24.581: IP: s=192.168.1.2 (local), d=192.168.1.7, len 52, policy rejected -- normal forwarding
Jul 10 08:39:24.633: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:24.645: IP: s=192.168.1.2 (local), d=192.168.1.30, len 100, policy rejected -- normal forwarding
Jul 10 08:39:24.917: IP: s=192.168.1.2 (local), d=192.168.1.4, len 100, policy rejected -- normal forwarding
Jul 10 08:39:25.029: IP: s=192.168.1.2 (local), d=192.168.1.39, len 52, policy rejected -- normal forwarding
Jul 10 08:39:25.161: IP: s=192.168.1.2 (local), d=192.168.1.8, len 100, policy rejected -- normal forwarding
Jul 10 08:39:25.317: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:25.353: IP: s=192.168.1.2 (local), d=10.1.0.237
Dasha#terminal no , len 118, policy rejected -- normal forwarding
Jul 10 08:39:25.369: IP: s=192.168.1.2 (local), d=10.1.0.237, len 119, policy rejected -- normal forwarding
Jul 10 08:39:25.397: IP: s=192.168.1.2 (local), d=10.1.0.237, len 118, policy rejected -- normal forwarding
Jul 10 08:39:25.413: IP: s=192.168.1.2 (local), d=10.1.0.237, len 121, policy rejected -- normal forwarding
Jul 10 08:39:25.421: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:25.421: IP: s=192.168.1.2 (local), d=192.168.1.1, len 300, policy rejected -- normal forwarding
Jul 10 08:39:25.441: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:25.441: IP: s=192.168.1.2 (local), d=192.168.1.1, len 400, policy rejected -- normal forwarding
Jul 10 08:39:25.445: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:25.445: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:25.449: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:25.449: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:25.449: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:25.449: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:25.449: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:25.453: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:25.457: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:25.457: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:25.457: IP: s=192.168.1.2 (local), d=192.168.1.1, len 156, policy rejected -- normal forwarding
Jul 10 08:39:25.457: IP: s=192.168.1.2 (local), d=192.168.1.1, len 124, policy rejected -- normal forwarding
Jul 10 08:39:25.461: IP: s=192.168.1.2 (local), d=10.1.0.237, len 118, policy rejected -- normal forwarding
Jul 10 08:39:25.541: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:25.765: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:25.957: IP: s=192.168.1.2 (local), d=192.168.1.162, len 52, policy rejected -- normal forwarding
Jul 10 08:39:26.245: IP: s=192.168.1.2 (local), d=10.1.0.237, len 122, policy rejected -- normal forwarding
Jul 10 08:39:26.261: IP: s=192.168.1.2 (local), d=10.1.0.237, len 122, policy rejected -- normal forwarding
Jul 10 08:39:26.273: IP: s=192.168.1.2 (local), d=10.1.0.237, len 122, policy rejected -- normal forwarding
Jul 10 08:39:26.289: IP: s=192.168.1.2 (local), d=10.1.0.237, len 122, policy rejected -- normal forwarding
Jul 10 08:39:26.305: IP: s=192.168.1.2 (local), d=10.1.0.237, len 121, policy rejected -- normal forwarding
Jul 10 08:39:26.321: IP: s=192.168.1.2 (local), d=10.1.0.237, len 119, policy rejected -- normal forwarding
Jul 10 08:39:26.349: IP: s=192.168.1.2 (local), d=10.1.0.237, len 115, policy rejected -- normal forwarding
Jul 10 08:39:26.453: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:26.453: IP: s=192.168.1.2 (local), d=192.168.1.1, len 428, policy rejected -- normal forwarding
Jul 10 08:39:26.505: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:26.509: IP: s=192.168.1.2 (local), d=192.168.1.1, len 220, policy rejected -- normal forwarding
Jul 10 08:39:26.509: IP: s=192.168.1.2 (local), d=192.168.1.1, len 220, policy rejected -- normal forwarding
Jul 10 08:39:26.509: IP: s=192.168.1.2 (local), d=192.168.1.1
Dasha#terminal no , len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.509: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.513: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.513: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.513: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.513: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.517: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.517: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.521: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:26.525: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.525: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.525: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.529: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.529: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.533: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.533: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.541: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.541: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.553: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:26.553: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:26.573: IP: s=192.168.1.2 (local), d=192.168.1.1, len 300, policy rejected -- normal forwarding
Jul 10 08:39:26.577: IP: s=192.168.1.2 (local), d=192.168.1.1, len 124, policy rejected -- normal forwarding
Jul 10 08:39:26.777: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:26.989: IP: s=192.168.1.2 (local), d=192.168.1.39, len 100, policy rejected -- normal forwarding
Jul 10 08:39:27.001: IP: s=192.168.1.2 (local), d=192.168.1.8, len 88, policy rejected -- normal forwarding
Jul 10 08:39:27.249: IP: s=192.168.1.2 (local), d=192.168.1.220, len 100, policy rejected -- normal forwarding
Jul 10 08:39:27.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, FIB policy match
Jul 10 08:39:27.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, g=80.122.174.89, len 62, FIB policy routed
Jul 10 08:39:27.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8, len 62, policy match
Jul 10 08:39:27.421: IP: route map fl-guest, item 10, permit
Jul 10 08:39:27.421: IP: s=10.8.0.2 (Vlan155), d=8.8.8.8 (Vlan20), len 62, policy routed
Jul 10 08:39:27.421: IP: Vlan155 to Vlan20 80.122.174.89

Jul 10 08:39:27.513: IP: s=80.122.174.90 (local), d=66.223.219.48, len 40, policy rejected -- normal forwarding
Jul 10 08:39:27.577: IP: s=192.168.1.2 (local), d=192.168.1.1, len 600, policy rejected -- normal forwarding
Jul 10 08:39:27.577: IP: s=192.168.1.2 (local), d=192.168.1.1, len 300, policy rejected -- normal forwarding
Jul 10 08:39:27.593: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.597: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.597: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.597: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.597: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.597: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.601: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.601: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.601: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.605: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.605: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.605: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.605: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.609: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.609: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.609: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.613: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.613: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.617: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.617: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.617: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.617: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.621: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.621: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.625: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.625: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.629: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.629: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.629: IP: s=192.168.1.2 (local), d=192.168.1.1, len 40, policy rejected -- normal forwarding
Jul 10 08:39:27.629: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.629: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.629: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.633: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.641: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.645: IP: s=192.168.1.2 (local), d=192.168.1.1, len 108, policy rejected -- normal forwarding
Jul 10 08:39:27.645: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.645: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.645: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.645: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.649: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.649: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.661: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.661: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.661: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.661: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.665: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.665: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.665: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.665: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.669: IP: s=192.168.1.2 (local), d=192.168.1.1, len 332, policy rejected -- normal forwarding
Jul 10 08:39:27.669: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Dasha#terminal no monitor
Jul 10 08:39:27.669: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.669: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.673: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.673: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.681: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.681: IP: s=192.168.1.2 (local), d=192.168.1.1, len 384, policy rejected -- normal forwarding
Jul 10 08:39:27.681: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.681: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding
Jul 10 08:39:27.681: IP: s=192.168.1.2 (local), d=192.168.1.1, len 92, policy rejected -- normal forwarding
Jul 10 08:39:27.685: IP: s=192.168.1.2 (local), d=192.168.1.1, len 348, policy rejected -- normal forwarding

I can traceroute 8.8.8.8 from the router VLAN 155 (10.8.0.1 addr).

And the packets go directly from  80.122.174.89.

Dasha#traceroute 8.8.8.8 source 10.8.0.1

Type escape sequence to abort.

Tracing the route to 8.8.8.8

  1 80.122.174.89 4 msec 0 msec 0 msec

  2 10.0.2.123 620 msec 552 msec 560 msec

  3 10.0.2.1 580 msec 576 msec 552 msec

  4 10.255.0.25 588 msec 572 msec 568 msec

  5 172.17.66.85 596 msec 560 msec 548 msec

  6 195.3.118.185 572 msec 556 msec 560 msec

  7 195.3.68.14 588 msec 604 msec

    195.3.68.18 608 msec

  8 72.14.218.172 568 msec 620 msec 568 msec

  9 72.14.238.44 576 msec

    72.14.238.46 596 msec 616 msec

10 209.85.250.140 [MPLS: Label 595403 Exp 4] 576 msec

    209.85.248.182 [MPLS: Label 557649 Exp 4] 592 msec

    209.85.250.140 [MPLS: Label 595403 Exp 4] 572 msec

11 72.14.233.114 644 msec

    64.233.175.246 608 msec 584 msec

12 72.14.239.197 580 msec

    72.14.239.199 572 msec

    209.85.255.143 584 msec

13  *  *  *

14 8.8.8.8 608 msec 620 msec 616 msec

Route-map is matched also

Dasha#sh route-map

route-map fl-guest, permit, sequence 10

  Match clauses:

    ip address (access-lists): 101

  Set clauses:

    ip next-hop 80.122.174.89

  Policy routing matches: 14681 packets, 1079100 bytes

Dasha#ping 8.8.8.8 source 10.8.0.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:

Packet sent with a source address of 10.8.0.1

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 612/622/644 ms

Dasha#sh route-map

route-map fl-guest, permit, sequence 10

  Match clauses:

    ip address (access-lists): 101

  Set clauses:

    ip next-hop 80.122.174.89

  Policy routing matches: 14686 packets, 1079600 bytes

If you need more information please let me know.

With kind regards

Sergey Bondarenko    

skype: sergio.bondarenko

e-mail and jabber: sergey.bondarenko.grey@gmail.com


With kind regards

Sergey Bondarenko   

skype:  sergio.bondarenko

e-mail and jabber: sergey.bondarenko.grey@gmail.com

Hi,

Hmm everything looks fine... Could you remove your outbound ACL and crypto-map and check again. Also verify NAT is working properly.

HTH

Laurent.

Hello Laurent

I think my nat behaves abnormally.

Please look on the debug.

I have connected my notebook (ip addr 10.8.0.2) to VLAN 155 and ping 8.8.8.8. I cannot rich the network.

I ping 8.8.8.8 source Vlan 155 (ip addr 10.8.0.1) directly from the router CLI. Ping success rate is 100%.

Jul 14 10:37:05.717: NAT: s=10.8.0.2->80.122.174.90, d=8.8.8.8 [1985]

.Jul 14 10:37:05.717: NAT: s=10.8.0.1, d=80.122.174.90->10.8.0.2 [54538]!

.Jul 14 10:37:06.717: NAT: s=10.8.0.2->80.122.174.90, d=8.8.8.8 [1986]

.Jul 14 10:37:06.717: NAT: s=10.8.0.1, d=80.122.174.90->10.8.0.2 [54578]

.Jul 14 10:37:07.625: NAT: s=10.8.0.1->80.122.174.90, d=8.8.8.8 [61018]!!

.Jul 14 10:37:07.721: NAT: s=10.8.0.2->80.122.174.90, d=8.8.8.8 [1987]

.Jul 14 10:37:07.721: NAT: s=10.8.0.1, d=80.122.174.90->10.8.0.2 [54642]

.Jul 14 10:37:08.213: NAT*: s=8.8.8.8, d=80.122.174.90->10.8.0.1 [20543]

.Jul 14 10:37:08.213: NAT: s=10.8.0.1->80.122.174.90, d=8.8.8.8 [61019]!

.Jul 14 10:37:08.721: NAT: s=10.8.0.2->80.122.174.90, d=8.8.8.8 [1988]

.Jul 14 10:37:08.721: NAT: s=10.8.0.1, d=80.122.174.90->10.8.0.2 [54687]

.Jul 14 10:37:08.809: NAT*: s=8.8.8.8, d=80.122.174.90->10.8.0.1 [20544]

.Jul 14 10:37:08.809: NAT: s=10.8.0.1->80.122.174.90, d=8.8.8.8 [61020]

.Jul 14 10:37:09.433: NAT*: s=8.8.8.8, d=80.122.174.90->10.8.0.1 [20545]

.Jul 14 10:37:09.433: NAT: s=10.8.0.1->80.122.174.90, d=8.8.8.8 [61021]!

Success rate is 100 percent (5/5), round-trip min/avg/max = 588/622/668 ms

If I ping 8.8.8.8 from my notebook.

As you can see by yourself the router translates packets sent to destination 8.8.8.8 with source address 10.8.0.2 to 80.122.174.90. But the router does not receive the backward icmp reply with source 8.8.8.8. Instead of it the router translates the packet with the source ip addr 10.8.0.1. 

Jul 14 10:37:05.717: NAT: s=10.8.0.2->80.122.174.90, d=8.8.8.8 [1985]

.Jul 14 10:37:05.717: NAT: s=10.8.0.1, d=80.122.174.90->10.8.0.2 [54538]!

If I ping 8.8.8.8 source Vlan 155 (ip addr 10.8.0.1) directly from the router CLI everything is looking ok.

.Jul 14 10:37:07.625: NAT: s=10.8.0.1->80.122.174.90, d=8.8.8.8 [61018]!!

.Jul 14 10:37:08.213: NAT*: s=8.8.8.8, d=80.122.174.90->10.8.0.1 [20543]

What do you think about it?

Hi,

I think there is a single ICMP entry for 80.122.174.90 in your nat table which is bind to 10.8.0.1.

Can you try either to clear it and then ping from your laptop or try something else from your laptop like http or telnet

HTH

Laurent.


Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card