I am in need of some router configuration help. I have 3030 concentrator that we use to connect to our customer sites via VPN. We have equipment at our customer locations that we support. We assign them an IP in the 172.20.x.x subnet to which we ask that they NAT on their end since the 3030 cannot perform this on our end. Some customer do this without any problems. Some are saying they will not perform the NAT. So, I need to add a router behind my 3030 and perform outside NAT. This is where I need help. My 3030 is something like this.
Public IP address
DMZ 10.10.10.0 This interface is where our servers are. this subnet is our customers remote network.
10.1.1.1 inside address.
I understand the concept. I'm just not sure of how to configure the router. Two ethernet interfaces? Which will be NAT inside? Which will be NAT outside. Also, I want to keep the customers who are willing to perform NAT on their end seperate from this. How will this effect the configuration? Any help MUCH appreciated.
I think that NAT Inside should be the interface from your side in this case, outside interface - interface from customers side.
Because you need to create access list to do NAT translation you can easy separate addresses which customers equipment translate itself from those which you have to translate yourself - just deny those IP addresses which customer translates itself and permit those which you have to translate in the access list.
Check these documents (as well as other about NAT on Cisco site) - there are a lot of examples there.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...