Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

Double NAT


I'm struck with a situation where in our management wants to extend a WAN Link to one of our customer sites, and since there is a conflicting IP Addressing Scheme (we both have 10.120.X.X).

Hence, a solution has been suggested by using NAT on the Router with a Proxy Address (or NATted IP Address of

Could anyone please point out a URL which describes my situation with a solution.

Kind Regards,

Wilson Samuel

  • WAN Routing and Switching

Re: Double NAT

and what about the subnetmask... it is also identical or what?

and will you please give me the more detail for the same issue?



Re: Double NAT

Hi Devang,

Thanks for the response.

Infact the situation is something like this:

1. Our Subnet is 10.120.x.x and our client's subnet is also of the same range.

2. There is one server at our end which is of and there is a Server at the other end which is of

3. Both the Servers should be able to talk to each other in order to make the things work.

4. Now we want to translate their Server = and Our Server to be translated as so that there is no confusion in our exisiting Routing infrastructure.

Now the issue is that on our Border Router this translation should take place:

1. The Server at our end neednt know the actual IP Address of the SErver at our client side i.e. but would be configured to use the Destination IP as

Similarly the Server at the client side needn't to know our Server's actual address ie. but should be configured to use as the destination address.

Any help would be great.


Wilson Samuel


Re: Double NAT

Try this document to start.

It has some examples of how to do this this.

Now if there was not a exact duplication you might get by putting /32 static routes in. The router since it has a /32 will respond to a arp (proxy arp) and then send the traffic to the other interface. This is not the best thing to do but is useful as you migrate address ranges.

This widget could not be displayed.