<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi JodyThanks i think you may in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528453#M236407</link>
    <description>&lt;P&gt;Hi Jody&lt;/P&gt;&lt;P&gt;Thanks i think you may of hit the nail on the head, I'll need to have someone at site check. Thanks for your help and I'll update what the problem was Monday.&lt;/P&gt;&lt;P&gt;Russ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 19 Jul 2014 17:04:17 GMT</pubDate>
    <dc:creator>Russell Dawson</dc:creator>
    <dc:date>2014-07-19T17:04:17Z</dc:date>
    <item>
      <title>Static nat not working</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528449#M236397</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Please find below my customers running config. Everything ok apart from static nat. I cant connect to servers using rdp on port 389, 390 or a device using port internal 443 external 8443 for secure HTTP. From the router i can ping the devices. It was working can some please check my config as i'm at a loss. can anyone help!&lt;/P&gt;&lt;P&gt;????????_DATA#sh run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 5372 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 11:37:50 UTC Sat Jul 19 2014 by admin&lt;BR /&gt;version 15.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname ??????????_DATA&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;memory-size iomem 10&lt;BR /&gt;crypto pki token default removal timeout 0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;license udi pid CISCO887VA-K9 sn FCZ1608C11J&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;username admin privilege 15 password 7 0963401A101112445D5B507278&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;controller VDSL 0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface ATM0&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;ip nat outside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;no atm ilmi-keepalive&lt;BR /&gt;&amp;nbsp;pvc 0/38&lt;BR /&gt;&amp;nbsp; encapsulation aal5mux ppp dialer&lt;BR /&gt;&amp;nbsp; dialer pool-member 1&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt;&amp;nbsp;switchport access vlan 1&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt;&amp;nbsp;switchport access vlan 14&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt;&amp;nbsp;switchport access vlan 14&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;description VLAN1 LinkVOICEMANAGMENTInterface&lt;BR /&gt;&amp;nbsp;ip address 192.168.2.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan10&lt;BR /&gt;&amp;nbsp;description VLAN10 Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.10.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan11&lt;BR /&gt;&amp;nbsp;description BMS_LAN Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.11.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt;&amp;nbsp;description CCTV_LAN Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.12.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan13&lt;BR /&gt;&amp;nbsp;description Access Control_LAN Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.13.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan14&lt;BR /&gt;&amp;nbsp;description MANAGMENT_LAN Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.14.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan15&lt;BR /&gt;&amp;nbsp;description TELEPHONY_LAN Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.15.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan16&lt;BR /&gt;&amp;nbsp;description SPARE2_DATA_LAN Interface&lt;BR /&gt;&amp;nbsp;ip address 172.17.16.254 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Dialer0&lt;BR /&gt;&amp;nbsp;ip address negotiated&lt;BR /&gt;&amp;nbsp;no ip redirects&lt;BR /&gt;&amp;nbsp;no ip unreachables&lt;BR /&gt;&amp;nbsp;no ip proxy-arp&lt;BR /&gt;&amp;nbsp;ip flow ingress&lt;BR /&gt;&amp;nbsp;ip nat outside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly in&lt;BR /&gt;&amp;nbsp;encapsulation ppp&lt;BR /&gt;&amp;nbsp;dialer pool 1&lt;BR /&gt;&amp;nbsp;dialer-group 1&lt;BR /&gt;&amp;nbsp;ppp authentication chap pap callin&lt;BR /&gt;&amp;nbsp;ppp chap hostname ??????????&lt;BR /&gt;&amp;nbsp;ppp chap password 7 00544156530D595E5B761F1F&lt;BR /&gt;&amp;nbsp;ppp pap sent-username ??????????? password 7 06565D711B185B415140415A&lt;BR /&gt;&amp;nbsp;no cdp enable&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;no ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip nat translation timeout 1800&lt;BR /&gt;ip nat translation tcp-timeout 1800&lt;BR /&gt;no ip nat service skinny tcp port 2000&lt;BR /&gt;no ip nat service sip udp port 5060&lt;BR /&gt;ip nat inside source list 1 interface Dialer0 overload&lt;BR /&gt;ip nat inside source static tcp 172.17.14.11 3390 interface Dialer0 3390&lt;BR /&gt;ip nat inside source static tcp 172.17.14.10 3389 interface Dialer0 3389&lt;BR /&gt;ip nat inside source static tcp 192.168.2.1 443 interface Dialer0 8443&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;access-list 1 permit 172.17.10.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 172.17.11.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 172.17.12.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 172.17.13.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 172.17.14.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 172.17.15.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 172.17.16.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 192.168.2.0 0.0.0.255&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;&amp;nbsp;login local&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;session-timeout 30&lt;BR /&gt;&amp;nbsp;login local&lt;BR /&gt;&amp;nbsp;transport input telnet ssh&lt;BR /&gt;!&lt;BR /&gt;scheduler max-task-time 5000&lt;BR /&gt;ntp server ???????&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528449#M236397</guid>
      <dc:creator>Russell Dawson</dc:creator>
      <dc:date>2019-03-12T04:30:04Z</dc:date>
    </item>
    <item>
      <title>The NAT configuration looks</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528450#M236400</link>
      <description>&lt;P&gt;The NAT configuration looks good. What happens if you try the following from the router?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: rgba(255, 255, 255, 0);"&gt;telnet&amp;nbsp;&lt;A href="tel:172.17.14.11"&gt;172.17.14.1&lt;/A&gt;0 3390 /source-interface Dialer0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: rgba(255, 255, 255, 0);"&gt;telnet&amp;nbsp;&lt;A href="tel:172.17.14.11"&gt;172.17.14.11&lt;/A&gt;&amp;nbsp;3390 /source-interface Dialer0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: rgba(255, 255, 255, 0);"&gt;telnet 192.168.2.1 443&amp;nbsp;/source-interface Dialer0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2014 13:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528450#M236400</guid>
      <dc:creator>ghostinthenet</dc:creator>
      <dc:date>2014-07-19T13:12:14Z</dc:date>
    </item>
    <item>
      <title>Thanks for the reply, and see</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528451#M236402</link>
      <description>&lt;P&gt;Thanks for the reply, and see below. The 192.168.2.1 device is connected directly to the router on interface 0 to rule out the switches.&lt;/P&gt;&lt;P&gt;hostname#telnet 192.168.2.1 443 /source-interface dialer0&lt;BR /&gt;Trying 192.168.2.1, 443 ...&lt;BR /&gt;% Connection timed out; remote host not responding&lt;/P&gt;&lt;P&gt;hostname#ping 192.168.2.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;hostname#telnet 172.17.14.11 3390 /source-interface Dialer0&lt;BR /&gt;Trying 172.17.14.11, 3390 ...&lt;BR /&gt;% Connection timed out; remote host not responding&lt;/P&gt;&lt;P&gt;hostname#ping 172.17.14.11&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 172.17.14.11, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2014 13:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528451#M236402</guid>
      <dc:creator>Russell Dawson</dc:creator>
      <dc:date>2014-07-19T13:31:05Z</dc:date>
    </item>
    <item>
      <title>Looks like the default</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528452#M236404</link>
      <description>&lt;P&gt;Looks like the default gateway isn't set correctly on the machines you're trying to reach. Either that or there's a host-based firewall blocking the connection.&lt;/P&gt;&lt;P&gt;Try running those telnet commands again on the router without the "/source-interface Dialer0" part and see the ports open. If they do, you've got a default gateway problem. If they don't, it's likely a host-based firewall.&lt;/P&gt;&lt;P&gt;The default gateways for those machines should be 172.17.14.254 and 192.168.2.254. You might want to make sure someone hasn't set them up for&amp;nbsp;&lt;SPAN style="background-color: rgba(255, 255, 255, 0);"&gt;172.17.14.1 and 192.168.2.1.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2014 13:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528452#M236404</guid>
      <dc:creator>ghostinthenet</dc:creator>
      <dc:date>2014-07-19T13:40:44Z</dc:date>
    </item>
    <item>
      <title>Hi JodyThanks i think you may</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528453#M236407</link>
      <description>&lt;P&gt;Hi Jody&lt;/P&gt;&lt;P&gt;Thanks i think you may of hit the nail on the head, I'll need to have someone at site check. Thanks for your help and I'll update what the problem was Monday.&lt;/P&gt;&lt;P&gt;Russ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2014 17:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-not-working/m-p/2528453#M236407</guid>
      <dc:creator>Russell Dawson</dc:creator>
      <dc:date>2014-07-19T17:04:17Z</dc:date>
    </item>
  </channel>
</rss>

