03-26-2014 08:13 AM - edited 03-04-2019 10:39 PM
I currently have a primary Internet circuit setup through Comcast. Modem is connected to an ASA5515X and Internet is working fine.
We installed a T1 that terminates in the same CO as a client's Internet service so we can route certain IPs from this office to their datacenter so we're all in the same network with less hops.
2620 router is setup and configured. I have a test route setup to my corporate website that is in a different location. I am able to ping the Internet and this site from the router and the core switch that is handling the routing, but cannot ping or access the site from the local VLAN. Config is faily simple for this site, so I'm not sure what's going on.
To troubleshoot, I attempted to route all traffic from the network to this T1 circuit, but that does not work. I have another site that is setup similarly with no issues.
Any ideas? Configs attached...if you need more, I can upload the full thing.
Solved! Go to Solution.
03-26-2014 01:08 PM
OK...should've seen that.
So does the NAT need to take place on the router or switch?
03-26-2014 01:13 PM
You can do it on the router as i doubt the switch supports.
Jon
03-26-2014 01:14 PM
How would I accomplish this? I'm not that versed on NAT'ing when it comes to router and CLI.
03-26-2014 01:17 PM
int fa0/0
ip nat inside
int s0/0
ip nat outside
access-list 101 permit ip 192.168.16.0 0.0.0.255 host 3.3.3.5
ip nat inside source list 101 interface s0/0 overload
Note instead of specifying the host in the acl you can use "any" if there are more destinations.
Jon
03-26-2014 01:24 PM
Thank you both for your input and working through this with me! :)
03-26-2014 01:12 PM
do below configuration
!
interface vlan 100
ip nat inside
!
!
interface gi 0/48
ip nat outside
!
ip accessl-list standard 1
permit ip 192.168.16.0 0.0.0.0255
!
!
ip nat inside source list 1 interface ge 0/48 overload
!
it should take care of NAT issue.
03-26-2014 01:15 PM
That would work but it depends on the switch ie. most L3 switches don't support NAT.
Jon
03-26-2014 01:16 PM
No, it does not work. ip nat isn't a valid command when editing an interface.
03-26-2014 12:55 PM
So the next hop router at the other end of the T1, what does it's IP routing table show ?
Jon
03-26-2014 12:58 PM
https://supportforums.cisco.com/sites/default/files/attachments/discussion/ar_testing.txt
03-26-2014 01:02 PM
I meant the router at the other end of the T1 link.
Does it have a route back to the 192.168.16.0/24 network ?
Jon
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: