Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Natting on router to firewall

Hi , If a have a static address on my router interface, would it be possible to nat from the ip of the interface to an internal address so it forwards all traffic destined from that interface to an internal ip ?


Re: Natting on router to firewall

lets say ur public ip on interface fa0/0

and u have internal ip u want this IP to to be used from internet if u have only this IP and u want it for internal users to use the internetr and to access the internal private IP from internat useing the same IP u need to dop what is known as port forwarding static PAT

lets say u wann access the internal ip mentioned above thorugh the public ip on the fa0/0 to use http

use the following config

lets say ur internal interface is fa0/1

internal subnet

u will access through the IP in the fa0/0 which is static public:

access-list 1 permit

ip nat inside source static tcp 80 interface fa0/0 80

ip nat inside source list 1 interface fa0/0 overload

interface fa0/0

ip nat outside

interface f0/1

ip nat inside

the above config will let internal users to get PATed to the internet and allow http access to the internal device with ip u can add what ever port u want and if u have ACLs on the outside interface u nedd to permit the traffic coming the outisde IP

good luck

if helpful Rate

New Member

Re: Natting on router to firewall

Hi there, I did not want to use PAT, I wanted to use NAT if poss, I guess I will have to see if there is a spare public ip I can use...