cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2103
Views
0
Helpful
2
Replies

NAT out and back in on the same interface

kevenpenner
Level 1
Level 1

I have a 1800 router and am trying to get this config going. Currently it cannot open a socket to the other host. I have two mail servers behind the router on the same lan network but translated to different public IP's. traffic from one server to the next fails. See diagram below. MX records point to public IP's so I need to allow traffic to go to the outside interface and back into the network.

http://i1338.photobucket.com/albums/o683/SnakeDoctor45/Cisco_zps157368cc.jpg

2 Replies 2

Dennis Mink
VIP Alumni
VIP Alumni

you are asking about NAT Hairpinnig, yes it can be done:

https://supportforums.cisco.com/thread/1003238



=============================
Please remember to rate useful posts, by clicking on the stars below. 

=============================

Please remember to rate useful posts, by clicking on the stars below.

Marwan ALshawi
VIP Alumni
VIP Alumni

FWs uses DNS doctoring not sure if you can use it with IOS

another option is you can use NAT on stick with a policy that NAT only communication between mail servers from private to public IPs

http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080094430.shtml

you need to use a loopback interface and a policy based routing to get it working with the NAT

hope this help