Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

SNAT with HSRP having same statefull SNAT ID's

When you have two routers at a client location and they are using HSRP is it ever okay to use the same Stateful Nat id?

I am not at work right now so I can’t grab any parts of a config, however to my understanding when you are using SNAT you always must make sure the two routers are using different stateful nat id’s. In a case I’ve found we have two routers at a client location taking back to our host routers over two different ISP’s. They are using HSRP in the event one client router loses the tunnels over the ISP but have the same Stateful Nat id.  They see each other as SNAT peers, but I’m not so sure they will be able to share the snat tables properly with the same Id. Does anyone know if it is ever okay to use the same SNAT id when using HSRP to control failover?


----- Updated
Here is a link where they used the same ID. http://jr-computerlabs.blogspot.com/2009/10/stateful-nat-with-hsrp-snat.html 

Here is a link where cisco says they need to be unique.

 

"Note: id-number is a unique number given to each router in the stateful translation group. Each SNAT router should have a unique ID number. "
 

http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-software-releases-12-2-t/prod_white_paper0900aecd8052870b.html

 

Looking here http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-software-releases-12-2-t/prod_white_paper0900aecd8052870b.html

It looks like you can use the same stateful ID if using HSRPis that correct?

Everyone's tags (4)
1 REPLY

Hi Benjamin, "ip nat stateful

Hi Benjamin,

 

"ip nat stateful id" must be unique locally in each router. therefore, it's not a problem to use same stateful IDs in 2 routers. 

The other ID is mapping-id, which must be the same in group members.

 

HTH

Houtan

 

 

73
Views
5
Helpful
1
Replies