The need was to reach an host inside a LAN through a VPN connection managed by the LAN gateway (Cisco 1921).
The LAN gateway performs NAT and there was a dedicate nat rule for the host i wanted to reach through VPN.
I couldn't connect to the host.
Same result trying to connect to ports involved in port forwarding.
Everything excluded by static NAT or port-forwarding was reachable instead.
I noticed that the router performed nat on return traffic when I tried to reach hosts involved in static nat through vpn.
This was because i specified a no-nat rule, but it was applied only to the global nat rule, while static nat and port-forwarding had their own rules fixed static in nat table.
This is the configuration I used to fix this situation:
STATIC NAT IP <-> IP ! ip access-list extended NAT deny ip [local-network] [local-wildcard] [vpn-network] [vpn-wildcard] permit ip [local-network] [local-wildcard] any ! route-map NAT permit 10 match ip address NAT ! ip nat inside source static [local-ip] [global-ip] route-map NAT
PORT-FORWARDING IP:PORT <-> IP:PORT ! ip access-list extended nonat-vpn deny tcp host [host-ip] eq [port] [vpn-network] [vpn-wildcard] permit tcp host [host-ip] eq [port] any ! route-map nonat-vpn permit 10 match ip address nonat-vpn ! ip nat inside source static tcp [local-ip] [local-port] [global-ip] [global-port] route-map nonat-vpn extendable
Hi EveryoneI am facing issue on CISCO 2921 Router since last week. Router keep on rebooting automatically. Find below details of Show commands output. Appreciate if anyone can guide about the root cause of Router rebooting. There are no configuration chan...
Hello Expert,I have two cisco router in HSRP configuration.On each router I have a 4 port card.The vlans configured on the card (both primary and secondary router) are Production Telephone,Security vlan.I am to configure an use HSRP on the production vlan...
Hi Team, Is there cisco recommend RSTP to MSTP migration procedure ? I didn't find any cisco related document for this. Currently network consist of Core (6500 Series) Switches, distribution (4500 series) switches and Access (3850, 2960X an...
Hiat first i want to say that am a newbie in networking and i come from germany so my englisch is not the best.So, here is my Problem: I have a Server at home for general purpose and the home lan i share with my family.My router is a Fritzbox 7490 an...
Hello.I'm having an issue with SSH console slowness once connected into a network device on GNS3. It generally slow on any router/switch regardless of the configuration to ssh/vty lines.If using Telnet it's perfectly fine and very responsive but ssh is sl...