Where apply static nat

Answered Question
Jul 11th, 2012

Dear boss

My server ip nating IP and i will access from

WAN IP     and it is crypto with IPsec.

MY conf :

Interface fe 0/0

switch port access vlan 10

interface vlan 10

ip add

ip route

ip nat inside source static route-map NAT_30

access-list 2002 permit ip

route-map NAT_30 permit 10

match ip address 2002

Generally I bind nat with tunnel , but here no tunnel. where i apply nat  and how to configure ????

Please suggest me.


I have this problem too.
0 votes
Correct Answer by soroushm about 2 years 9 months ago

remove the route-map from ur static NAT command, make it simple n make it work, complications... later.

did you set your router's LAN interface as NAT outside?  ip nat outside



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Sandeep Choudhary Wed, 07/11/2012 - 23:11

can you please provide your topology layout ???

then I can tell you .


shahid_duet Thu, 07/12/2012 - 01:38

Generally i create a tunnel and bind NAT lie this:

tunnel 100

ip add

tunnel source

tunnel desti

ip nat outside

Here no tunnel so where i bind in avobe configuration ??


cadet alain Thu, 07/12/2012 - 01:47


you're doing a site-to-site IPSec VPN between these 2 subnets? if so then you don't have to NAT traffic between the 2 subnets( do a deny in an extended access-list used for NAT) an apply nat on inside and outside interfaces for internet traffic.



Don't forget to rate helpful posts.

shahid_duet Thu, 07/12/2012 - 02:14

Dear Alain

Branch have permission on not at  and it virtual IP. so i need NAT to get Rranch router is configured  for forwarding and it is ok.

How i get by using NAT from branch ???

soroushm Thu, 07/12/2012 - 05:13


if I got it right, u want ur hosts to send traffic to and ur Server ( at the other end receives it, and your switch does routing as well, and u need to convert the ip's on ur branch router...?

So your config on the switch would need a static route to pointing to the branch router.

ip route x.x.x.x [router, gateway ip] .... so that traffic with original ip for server is sent to the router.

then on the router you do the NAT with the serial interface as OUTSIDE interface.

int s0/0

ip nat outside

ip nat inside source static

let me know if i got the whole idea wrong, then you may need to shift the config to the other router.

Hope it Helps,


shahid_duet Sat, 07/14/2012 - 23:14

Dear Soroushm

The NAT is applicable in Head office router. Take it very simple. Branch IP( will ping  to and will respond. I did NAT to my head office router and bind to vlan 10 described in avobe configuration. It dose not work.  My crypto and routing is ok. but when i create nat and bind it to vlan 10  dose not work.

Is there another way to work. ?????


Correct Answer
soroushm Sun, 07/15/2012 - 07:45

remove the route-map from ur static NAT command, make it simple n make it work, complications... later.

did you set your router's LAN interface as NAT outside?  ip nat outside



shahid_duet Sun, 07/15/2012 - 21:46

Dear Soroushm

U r Right. Its working now.

now i need to delete some static nat. but can not do ?

I tried to deletet  as follows:

router# no ip nat translation *

router(conf)#no ip nat inside source static



But can not remove or edit

How to remove single or all nat.

Pls suggest me


soroushm Mon, 07/16/2012 - 09:55

try removing the ip nat outside / ip nat inside commands from the interfaces, then go through the steps u did before. and then reconfig.

Hope it Helps,



Login or Register to take actions

This Discussion

Posted July 11, 2012 at 9:50 PM
Replies:9 Overall Rating:5
Views:483 Votes:0
Tags: No tags.
Categories: Routers

Discussions Leaderboard

Rank Username Points
Giuseppe Larosa
Paolo Bevilacqua
Richard Burts
Jon Marshall
Peter Paluch
Rank Username Points
Jon Marshall
Joseph W. Doherty
Leo Laohoo
Peter Paluch
Vasilii Mikhail...