Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Pbs NAT cisco 1812 ISR

Hi,

I have 2 ISP, 2 small d-link router on each ISP (with nat) and 1 cisco 1812. Load-sharing is OK, but i have a pb with NAT to acces from Internet to local server.

Here is my configuration :

--------------------

!

version 12.4

!

ip subnet-zero

no ip source-route

!

!

ip cef

!

!

ip tcp synwait-time 10

no ip bootp server

ip domain name xxxx.xx

ip name-server xxx.xxx.xxx.xxx

ip name-server xxx.xxx.xxx.xxx

ip ips notify SDEE

!

!

!

interface FastEthernet0

description xxxxxxxxxxxxxx

ip address 12.0.0.250 255.255.255.0

no ip redirects

no ip unreachables

no ip proxy-arp

ip nat outside

ip virtual-reassembly

duplex auto

speed auto

!

interface FastEthernet1

description xxxxxxxxxxxxx

ip address 11.0.0.250 255.255.255.0

no ip redirects

no ip unreachables

no ip proxy-arp

ip nat outside

ip virtual-reassembly

duplex auto

speed auto

!

!

interface BVI1

description xxxxxxxxxxxxxxx

ip address 192.168.0.250 255.255.255.0

ip nat inside

ip virtual-reassembly

ip tcp adjust-mss 1412

!

ip classless

ip route 0.0.0.0 0.0.0.0 11.0.0.1

ip route 0.0.0.0 0.0.0.0 12.0.0.1

!

!

ip nat inside source route-map NATMAP1 interface FastEthernet0 overload

ip nat inside source route-map NATMAP2 interface FastEthernet1 overload

ip nat inside source static tcp 192.168.0.xxx 3389 interface FastEthernet0 33333

ip nat inside source static tcp 192.168.0.yyy 3389 interface FastEthernet1 33333

!

no logging trap

no cdp run

!

route-map NATMAP2 permit 10

match interface FastEthernet1

!

route-map NATMAP1 permit 10

match interface FastEthernet0

!

----------------

The access from the internet to 192.168.0.yyy is OK, but 192.168.0.xxx is not OK ???

If i change the FE0 to 10.0.0.250, it's OK on .yyy and not on .xxx !!!

At each time, it's only the FE interface with the lower address that is OK !!!

Have you an idea ?

Thanks, and excuse me for my english !!

3 REPLIES
Gold

Re: Pbs NAT cisco 1812 ISR

I suspect your issue is they way cisco load balances and asymetric routing of your traffic.

Its not this simple but say even addresses alway go out the first path and odd addresses alway go out second.

The nice thing with nat is that it will consitantly pick the same path to a outside machine and therefore always use the same nat address.

You problem is that the outside machine is picking the outside interface to use and the inside machine is using the load balance to pick the path. Just luck if it works. Since you are using 2 differnt NAT addresses to the remote machine you will never get a session open.

If all you have to worry about is 2 machines you can just policy route the traffic back to the proper outside interface to match your nat statements.

I suspect you will also find outbound issues eventually. Many sites use source IP address for security. They get very confused when they think your ip address has changed when they hand off processing to another machine that has a different IP address but is really the same site.

Community Member

Re: Pbs NAT cisco 1812 ISR

OK

Do you think there is a issue ?

OER ?

Thanks

Gold

Re: Pbs NAT cisco 1812 ISR

Yes there are issues with load balancing and NAT.

Policy routing will fix the sample you gave

296
Views
0
Helpful
3
Replies
CreatePlease to create content