<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT based on the Source IP in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314559#M290888</link>
    <description>&lt;P&gt;Howdy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to setup NAT based on the Source IP.. so let's say&lt;BR /&gt;&lt;BR /&gt;when User A from 111.1.1.11 connects to 155.5.5.5 with port 3389 he should be redirected to Server A 192.168.1.2 Port 3389&lt;BR /&gt;&lt;BR /&gt;when User B from 112.2.2.22 connects to 155.5.5.5 with port 3389 he should be redirected to Server B 192.168.1.3 port 3389&lt;BR /&gt;&lt;BR /&gt;and so on..&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I can only use 1 public IP and can't map any ports..&lt;BR /&gt;&lt;BR /&gt;(Currently experimenting on Cisco 2821 with 12.4, but any Cisco IOS Version would do (no ASA though))&lt;BR /&gt;&lt;BR /&gt;I've tried for days now and so far I've only found outdated forum posts without a solution,&lt;BR /&gt;I would appreciate if anyone has a link to a solution or can show me an example.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2019 17:47:59 GMT</pubDate>
    <dc:creator>butterfass</dc:creator>
    <dc:date>2019-03-05T17:47:59Z</dc:date>
    <item>
      <title>NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314559#M290888</link>
      <description>&lt;P&gt;Howdy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to setup NAT based on the Source IP.. so let's say&lt;BR /&gt;&lt;BR /&gt;when User A from 111.1.1.11 connects to 155.5.5.5 with port 3389 he should be redirected to Server A 192.168.1.2 Port 3389&lt;BR /&gt;&lt;BR /&gt;when User B from 112.2.2.22 connects to 155.5.5.5 with port 3389 he should be redirected to Server B 192.168.1.3 port 3389&lt;BR /&gt;&lt;BR /&gt;and so on..&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I can only use 1 public IP and can't map any ports..&lt;BR /&gt;&lt;BR /&gt;(Currently experimenting on Cisco 2821 with 12.4, but any Cisco IOS Version would do (no ASA though))&lt;BR /&gt;&lt;BR /&gt;I've tried for days now and so far I've only found outdated forum posts without a solution,&lt;BR /&gt;I would appreciate if anyone has a link to a solution or can show me an example.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 17:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314559#M290888</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2019-03-05T17:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314646#M290890</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you &amp;nbsp;clarify the location of server A/B in trlstion to the source hosts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;maybe you could provide &amp;nbsp;a small topology&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;res&lt;/P&gt;
&lt;P&gt;paul&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 17:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314646#M290890</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2018-01-19T17:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314668#M290892</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply,&lt;/P&gt;
&lt;P&gt;I've attached an example.jpg with a small topology to the post, can you see it?&lt;/P&gt;
&lt;P&gt;If yes, can you please elaborate on what infos you need?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings&lt;/P&gt;
&lt;P&gt;butterfass&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 17:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314668#M290892</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-19T17:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314689#M290893</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PBR and nat would be applicable - Can you post your configuration&lt;BR /&gt;&lt;BR /&gt;res&lt;BR /&gt;Paul&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 08:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314689#M290893</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2018-01-20T08:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314726#M290895</link>
      <description>&lt;P&gt;I added the NAT rules, but I'm still unable to RDP to the Server, do I need to set anything else? I'm probably missing some kind of ACL i guess?&lt;BR /&gt;&lt;BR /&gt;My config looks like this:&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;description WAN&lt;BR /&gt;ip address 155.5.5.5 255.255.255.0&lt;BR /&gt;ip nat outside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;description LAN&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;ip nat inside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip nat outside source static tcp 111.1.1.11 3389 192.168.1.2 3389 extendable add-route&lt;BR /&gt;ip nat outside source static tcp 112.2.2.22 3389 192.168.1.3 3389 extendable add-route&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 18:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314726#M290895</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-19T18:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314736#M290896</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;Okay understand now apologies -&lt;BR /&gt;The only issue is that PAT and dual static mapping to the interface(gloabl ip) and port isn't allowed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you could use another port or additional global ip for of the mapping then it would be applicable and you then could apply some policy based routing to each server&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;But as you only have one global up You could try the example below using two different ports&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Access-list 100 permit ip 192.168.1.0 0.0.0.0.255 any&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0 x.x.x.x ( isp next hop)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip nat inside source list 100 interface GigabitEthernet0/0&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ip nat inside source static tcp 192.168.1.3 3389 15.1.1.1 3389&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ip nat inside source static tcp 192.168.1.4 3390 15.1.1.1 3390&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly if you did have two global ips to use then you could also incorporate some PBR&lt;/P&gt;
&lt;P&gt;Like below&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;access-list 103 permit tcp host 111.1.1.11 host 192.168.1.3 eq 3389&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-list 104 permit tcp host 112.2.2.22 host 192.168.1.4 eq 3389&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;route-map PBR permit 10&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;match ip address 103&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;set ip next hop 192.168.1.3&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;route-map PBR permit 20&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;match ip address 104&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;set ip next hop 192.168.1.4&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;int gig0/0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Description WAN&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip policy route-map PBR&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;res&lt;BR /&gt;Paul&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2018 10:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314736#M290896</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2018-01-21T10:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314752#M290899</link>
      <description>&lt;P&gt;Thanks for bearing with me..&lt;/P&gt;
&lt;P&gt;Sorry I guess the info I provided were misleading,&lt;/P&gt;
&lt;P&gt;for simplification all WAN addresses are on the same subnet (new topology in attachement).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My config looks like this now:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;description WAN&lt;BR /&gt;ip address 111.1.1.1 255.255.255.0&lt;BR /&gt;ip nat outside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;description LAN&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;ip nat inside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip nat inside source list 100 interface GigabitEthernet0/0 overload&lt;BR /&gt;ip nat outside source static tcp 111.1.1.2 3389 192.168.1.2 3389 extendable add-route&lt;BR /&gt;ip nat outside source static tcp 111.1.1.3 3389 192.168.1.3 3389 extendable add-route&lt;BR /&gt;!&lt;BR /&gt;access-list 100 permit ip 192.168.1.0 0.0.0.255 any&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(nat inside added the "overload" option automatically)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 19:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314752#M290899</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-19T19:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314758#M290900</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;when you initiate the connection from the outside hosts can you access the internal servers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you post the output from&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;sh ip nat translations&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;res&lt;BR /&gt;Paul&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 19:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314758#M290900</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2018-01-19T19:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314768#M290901</link>
      <description>&lt;P&gt;No I can't estabish a connection at all, the output is this:&lt;/P&gt;
&lt;P&gt;Pro Inside global&amp;nbsp;&amp;nbsp; &amp;nbsp;Inside local&amp;nbsp;&amp;nbsp; &amp;nbsp;Outside local&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Outside global&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;tcp ---&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.2:3389&amp;nbsp;&amp;nbsp;&amp;nbsp; 111.1.1.2:3389&lt;BR /&gt;tcp ---&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.3:3389&amp;nbsp;&amp;nbsp; &amp;nbsp;111.1.1.3:3389&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 20:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314768#M290901</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-19T20:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314776#M290902</link>
      <description>&lt;P&gt;Also I just noticed that I'm now getting a "Duplicate address 192.168.1.2 on GigabitEthernet0/1"&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 20:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314776#M290902</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-19T20:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314790#M290903</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;For now and testing proposes remove&amp;nbsp; the static nat entries and confirm&amp;nbsp; you are initiating the&amp;nbsp; connection from OUTSIDE your network and not inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have reachability to 155.5.5.5 and can you ping 155.5.5.5 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please review the previous configuration i posted -&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;res&lt;BR /&gt;Paul&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 20:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314790#M290903</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2018-01-20T20:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314797#M290905</link>
      <description>&lt;P&gt;Ok, i deleted the static entry for 111.1.1.3.&lt;/P&gt;
&lt;P&gt;My test setup consists of 2x windows clients, of which I change the IPs accordingly to test the NAT configuration:&lt;/P&gt;
&lt;P&gt;Currently it is setup as:&lt;/P&gt;
&lt;P&gt;Client A on OUTSIDE interface with IP: 111.1.1.2/24 can ping OUTSIDE interface 111.1.1.1&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;Server A on INSIDE interface with IP: 192.168.1.2/24 can ping INSIDE interface 192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however when i try to establish a RDP session from Client A to 111.1.1.1 nothing happens. (RDP is functional on the machine/no Firewall or sth like that..)&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 22:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3314797#M290905</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-19T22:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT based on the Source IP</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3315486#M290946</link>
      <description>&lt;P&gt;Oh, I did not see that you answered already, I always just checked the bottom of the page...&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I was afraid you'd say that, unfortunately I need multiple static mappings for the same IP.&lt;BR /&gt;The initial idea was that due to a large number of users, not everyone had to be provided with their own IP.&lt;BR /&gt;&lt;BR /&gt;Thank you very much for your help and the tip with PAT/PBR!&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2018 19:23:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/nat-based-on-the-source-ip/m-p/3315486#M290946</guid>
      <dc:creator>butterfass</dc:creator>
      <dc:date>2018-01-21T19:23:39Z</dc:date>
    </item>
  </channel>
</rss>

