The need was to reach an host inside a LAN through a VPN connection managed by the LAN gateway (Cisco 1921).
The LAN gateway performs NAT and there was a dedicate nat rule for the host i wanted to reach through VPN.
I couldn't connect to the host.
Same result trying to connect to ports involved in port forwarding.
Everything excluded by static NAT or port-forwarding was reachable instead.
I noticed that the router performed nat on return traffic when I tried to reach hosts involved in static nat through vpn.
This was because i specified a no-nat rule, but it was applied only to the global nat rule, while static nat and port-forwarding had their own rules fixed static in nat table.
This is the configuration I used to fix this situation:
STATIC NAT IP <-> IP ! ip access-list extended NAT deny ip [local-network] [local-wildcard] [vpn-network] [vpn-wildcard] permit ip [local-network] [local-wildcard] any ! route-map NAT permit 10 match ip address NAT ! ip nat inside source static [local-ip] [global-ip] route-map NAT
PORT-FORWARDING IP:PORT <-> IP:PORT ! ip access-list extended nonat-vpn deny tcp host [host-ip] eq [port] [vpn-network] [vpn-wildcard] permit tcp host [host-ip] eq [port] any ! route-map nonat-vpn permit 10 match ip address nonat-vpn ! ip nat inside source static tcp [local-ip] [local-port] [global-ip] [global-port] route-map nonat-vpn extendable
Hello community,I am trying to deploy an easy configuration on a few devices (they are 4k, that's my problem).We hace a Cisco Prime Infraestructure running 3.4I hope we can make it using a customized template. I need to deploy just a command to confi...
Hi colleagues. Could someone describe why Meraki Switch behavior is very odd - when IGMP snooping is enabled and Flood Unknown Traffic disabled, even if IGMP Querier is on - no traffic is passing through switch. But vice versa - when IGMP snoopi...
A 3rd party has asked me to open a range of ports for a new phone system they are installing. However, I can't figure out how to open a range of ports on my Cisco 1921. They are asking me to open ports 10000 to 20000 I have done this for port ...
Hi All,Hope you all are doing well. Please help me in getting the right switch for the below requirements. Our customer is having 6 floor office for that they need wireless connectivity. We have done the survey and conclude that total 42 AP...
hello,i have problem with ios updating in cisco prime.I updated ios for switch 9300 , in switch show correct version but in cisco prime show last version and i recieve error : '' Unexpected error. See the log file inventory.log for details. ''. version of...