multiple static nat with one public ip (one customer ip to one internal host)
Hi all together!
I need a 1:1 NAT between a remote Host and a internal host for a IPSec Site-to-Site Tunnel for each of our customers. I need this configuration for a dial-in remote maintenance concept shown in the Picture.
My Problem is, that i have only one public ip address for disposal. At this moment the connection with only one site to site works perfect, but now, how could i implemet my next customers? I read some pages about policy based nat or nat with route-maps, but i can't get one of the examples to work.
Re: multiple static nat with one public ip (one customer ip to o
at first, sorry for my late answer but i was looking a few days for an other solution with my cisco router. i get always the same result, it doesnt work with my router.
Now i tryd my luck with iptables and it works fine. I write a small shellscript for easy use. It set a "static nat" based on the source customer peer ip. The script is not perfect and is not the fastest, but it works good ;-)
Thank you for your help!
d-fw-nat-01:~# cat iptables.sh
# 1 Set Variables:
EXTERNAL_INT="eth0" # External Internet interface
EXTERNAL_IP="220.127.116.11" # Internet Interface IP address
# Customer 0
# Customer 1
# 2 Iptables
# 3 delete existing Rules
$FW -t nat -F
# 4 Standardrules
$FW -P INPUT ACCEPT
$FW -P FORWARD ACCEPT
$FW -P OUTPUT ACCEPT
# close the external interface for local services
$FW -A INPUT -i $EXTERNAL_INT -j REJECT
$FW -A OUTPUT -o $EXTERNAL_INT -j REJECT
# the loop for setting one rule per customer
typeset -i I
typeset -i ANZ
while (( $I < $ANZ ));
# in prerouting the destination ip must be rewritten
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...