cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
830
Views
10
Helpful
7
Replies

Static NAT issue (outside to inside)

Patts
Level 1
Level 1

Hi, need help on my CME-PABX that's connect to the external SIP server for external calls. The external SIP server is pointing to public ip (202.x.x.1) as per diagram below. I need to map this to our CME (10.10.130.1) in order to reach the external SIP server. I believed my issue is more on the NAT translation. Let me know the correct NAT setup considering the ISR4321 and ASA Firewall as per diagram.

Thanks much.

Pat

Patts_0-1666923338233.png

 

1 Accepted Solution

Accepted Solutions

 

ASA-Router Subnet
use one IP from this Subnet and config static NAT in ASA 
use this IP in router also to static NAT to WAN interface IP

View solution in original post

7 Replies 7

Patts
Level 1
Level 1

Just to summarize my issue above, I just need to configure ISR4321 to translate public IP 202.x.x.1 to the private IP in the inside which is CME 1010.130.1. Meaning public IP 202.x.x.1 should be able to translate to 10.10.130.1 which will use for SIP connectivity from the external SIP server to the CME. 

Let me know if I can add "ip nat outside source static 202.x.x.1 10.10.130.1" without affecting my current configuration. Or let me know other way to do.

NAT (voice,outside) real IP-ASA mapped IP-ASA

ip nat inside static source mapped IP-ASA mapped IP-Router 

this make server access from Internet 

Thanks for your inputs @MHM Cisco World 

Can you just confirm that I can still retain this below NAT overload for my internet access? 

ip nat inside source list 10 interface GigabitEthernet0/0/0 overload

I forgot to ask both NAT setup above I'll need to do in Firewall and Router right? Thanks

 

ASA-Router Subnet
use one IP from this Subnet and config static NAT in ASA 
use this IP in router also to static NAT to WAN interface IP

Hi, can you confirm the NAT in the ASA is Manual or Auto NAT? Thanks

manual NAT why? because we have dynamic NAT (auto) and we need FW to check static NAT before dynamic NAT so we need to config new static NAT as manual this put new NAT above dynamic and make FW check static NAT before dynamic NAT.
images.png

Review Cisco Networking products for a $25 gift card