Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
You may experience some slow load times, errors, and slight inconsistencies. We ask for your patience as we finalize the launch. Thank you.

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAT problem

Hi, I have inherited a system which I am trying to make work. It consists of two routers each with an ethernet and a bri. For some reason this very straightforward network has some NAT. I guess the NAT was configured as a workaround for some old legacy application and migration to a new network or something.

My problem is that the routers dial and ping each other OK without the NAT (removing 'ip nat outside' from dialer 2) but when this is put back on the traffic doesn't pass. Does the NAT pool address range need to match that of the bri at the receiving end? Am I missing some static routes for the pool address?

Help appreciated.

Router configs summerised with the interesting bits only!

Router1. (Dialing end)

eth 0

ip address

ip nat inside

dialer 2

ip address

ip nat outside

ip nat pool NATPOOL netmask

ip nat inside source list 101 pool NATPOOL overload

ip classless

ip route dialer 2

access-list 101 permit ip any any

Router 2 (Receiving end)

eth 0

ip address /24


ip address

ip route bri0

ip route bri0 - not sure why this route is here.

  • Other Network Infrastructure Subjects
New Member

Re: NAT problem


I think you should put a static route on router1 that points to the ip address of bri interface of router two for the internal address of router two.


ip route

put this on router1

and try find out what is. and where it is located.

put your access-list to cover just the internal network of router1


access-list 101 permit ip any

please mail me and tell me how it went.


New Member

Re: NAT problem

In order for communcation to exist between two end nodes two conditions must exist:

1) There must be a route and a communication path between them.

2) they must be within the same segment.

As per your example, by applying the

ip nat outside

on BRI0 of R1 you are translating to

by using the static route, the traffic leaves interface Dialer2 however the traffic will not know how to get back!

When R2 examins the frame it will see the source address of in its header.

And it will not know how to respond.

New Member

Re: NAT problem

Q. Does the NAT pool address rantge need to match the of the VRI at the receiving end?

A. Yes, There must exist on the same network between two end points. You can use private address between both BRI's and use static routes, and Dialer lists to specificy interesting traffic.

Please correct me if i am wrong. Thank you

Orlando Piedrahita.