Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

eBGP over NAT boundaries

Hi there,

Let’s assume this unrealistic scenario in a totally private network. I have two eBGP peer connections coming into my private network, one for Customer A and one for Customer B.  Both Customer A and Customer B have identical subnet ranges, for example 10.15.100.0/24.  I know I could separate these with VRF's, but lets exclude this for the minute.

If Customer A wishes to exchange data with Customer B then I have a problem due to conflicting subnet ranges. If I were to use NAT, can I establish an eBGP session across a NAT boundary? Furthermore, can Customer A or Customer B have their BGP advertised networks NAT’d to a non conflicting private range of addresses?

If I did use VRF's to separate overlapping networks how could I get these two VRF's to communicate with the knowledge they have the same private networks?

Thanks, Wayne

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Super Blue

Re: eBGP over NAT boundaries

wrgoulden wrote:

Jon,

I guess firstly can you establish a BGP session from a BGP NAT'd peer address? Secondly, would I need a transit network behind the customer BGP router to perform the NAT then advertise the NAT ranges into BGP?

Thanks,


Wayne

Wayne

The first one will be tricky - would the 2 EBGP peers be using WAN IPs from the same subnet ? If so that may take a bit of experimenting with but i though the requirement was simply to NAT an internal network.

As for natting an internal network this should be relatively straighforward and i suspect altho i would need to test the Natting could be done on the same router that runs EBGP.

Don't mind testing but could you just answer whether the WAN IPs would need Natting ?

Jon

4 REPLIES
Hall of Fame Super Blue

Re: eBGP over NAT boundaries

wrgoulden wrote:

Hi there,

Let’s assume this unrealistic scenario in a totally private network. I have two eBGP peer connections coming into my private network, one for Customer A and one for Customer B.  Both Customer A and Customer B have identical subnet ranges, for example 10.15.100.0/24.  I know I could separate these with VRF's, but lets exclude this for the minute.

If Customer A wishes to exchange data with Customer B then I have a problem due to conflicting subnet ranges. If I were to use NAT, can I establish an eBGP session across a NAT boundary? Furthermore, can Customer A or Customer B have their BGP advertised networks NAT’d to a non conflicting private range of addresses?

If I did use VRF's to separate overlapping networks how could I get these two VRF's to communicate with the knowledge they have the same private networks?

Thanks, Wayne

Wayne

Yes you can establish BGP, you would simply advertise out the Natted subnet range rather than the real subnet range. Is this what you are asking or are you asking whether the actual BGP peer address can be Natted ?

Jon

New Member

Re: eBGP over NAT boundaries

Jon,

I guess firstly can you establish a BGP session from a BGP NAT'd peer address? Secondly, would I need a transit network behind the customer BGP router to perform the NAT then advertise the NAT ranges into BGP?

Thanks,


Wayne

Hall of Fame Super Blue

Re: eBGP over NAT boundaries

wrgoulden wrote:

Jon,

I guess firstly can you establish a BGP session from a BGP NAT'd peer address? Secondly, would I need a transit network behind the customer BGP router to perform the NAT then advertise the NAT ranges into BGP?

Thanks,


Wayne

Wayne

The first one will be tricky - would the 2 EBGP peers be using WAN IPs from the same subnet ? If so that may take a bit of experimenting with but i though the requirement was simply to NAT an internal network.

As for natting an internal network this should be relatively straighforward and i suspect altho i would need to test the Natting could be done on the same router that runs EBGP.

Don't mind testing but could you just answer whether the WAN IPs would need Natting ?

Jon

New Member

Re: eBGP over NAT boundaries

Jon,

Just looked over it again and the NAT'ing of the internal ranges is fine.  No need to set peers up over a NAT boundary as I first thought. Thanks for your help.

Wayne

911
Views
0
Helpful
4
Replies