Unfortunately there is no command syntax in NAT to configure a translation for range of ports in one go, so if you only have one public ip address which is assiged to the outside interface of the edge router, and that same ip address has to be used for hosting udp ports 10000 to 20000, then you really do not have a good solution
But if you have ANOTHER public ip which can be used for NATing then, you can simply configure the command:
ip nat inside source static 192.168.1.61 188.8.131.52
With the above command, you are mapping the public ip to a private ip including all udp & tcp ports. And if you want more security then you can even have ACL (which ofcourse have a "range" keyword) applied (using route-map) on this NAT statement so that only the ports which you want will be NATed
Would like to check if I NAT my private IP with public IP by using the command you mentioned, will it open all the ports?
I tried it before and after that I use online port checker to check the port and seem like it only open for port 80 the rest are still closed. Furthermore, my device still not able to communicate with my PABX from external network.
yes, using the command I mentioned will map all the ports of Public ip with your private ip but an online port checker tool will only look for a response on these ports and that response will only come if you have some service hosted on that port. that too will be done for TCP ports as udp will not create a session using 3 way handshake
so I am assuming that you are only using an Http service on the inside when it comes to TCP and that's why the online port checker sees that but if you host other services on that server then they will also become accessible/visible from internet
For security purpose, if you want to block unused ports from internet then you'd have to make use of ACL on the outside interface allowing only port 80 or 443 or whichever service you want to host.
Now regarding communication with PABX, you'd have to check the NAT table on the router using "sh ip nat translation" command to see if the translations are happening for the traffic coming from internet towards the PABX box
This is actually a pretty cool feature, i didn't even know it existed until I was looking for a solution to advertise a subnet (prefix in BGP talk), only if a certain condition existed. This is exactly what conditional advertisements does
j ai une question j ai achete un routeur cisco 887VA-k9 , je le configuré avec la configuration ci- dessous
si je le lier avec mon pc portable sur l un de ses ports directement ça marche toute est bien ( la connexion internet + m...
Attached policy provides CLI access to the Cisco 4G router over text messaging. Two files are in the attached .tar file:
2. PDF with instructions on how to load and use the .tcl file.