you have 10.84.54.0 as your " ip nat inside interface " meaning a segment in your inside network where your local servers reside for 10.84.54.0 network (not 10.84.68.0 ), and 192.168.156.0 as " ip nat outside " meaning outside interface where custumer will be comming through for inbound connections to get to web servers on 10.84.81.68 and 69, will not work, what interface is routing 10.84.81.0 network where your servers 10.84.81.68 & 69 are? if you have an interface routing 10.84.81.0 place " ip nat inside " statement in that interface and your current static nat will work along with an access list to permit inbound traffic.
access-list 101 permit ip host Custumer_IP 192.168.156.248 0.0.0.255 log
access-list 101 permit ip host Custumer_IP 192.168.156.249 0.0.0.255 log
Sorry Beno, I should have read your initial question carefully an/or asked about your topology thinking you were dealing with a single device.. thats what happens when reading fast.
ON your initial question your configuration is conisder a source NAT.
I quote from a link
"Destination-based NATing uses route maps to determine which IP address each IP session is translated to based on routing reachability of the destination IP host. The dynamic translation command can now specify a route map to be processed instead of an access list. A route map allows the user to match any combination of access list, next-hop IP address, and output interface to determine which pool to use "
Also, even though my previous post is useless because I was thinking that was a single device I am abligated to correct something in the statement " ip access-group 101 in " should be applied on interface with "ip nat oustide".
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...