07-17-2003 12:40 AM - edited 03-09-2019 04:05 AM
I have a client wanting to allow inbound PPTP to theie internal network. They are running NAT on a 1751 with IOS 12.2 and have a single public IP. They are using static NAT entries to allow inbound SMTP and terminal services. Static NAT entries do not support protocol 47 (GRE) so we can't do it that way. What options do they have to do it another way? I think they will have to get another public IP and translate all inbound traffic to that Ip to the internal IP where PPTP terminates. Will that work and can they have multiple external VPN users connecting to the single internal network IP via NAT? Thanks in advance.
Solved! Go to Solution.
07-17-2003 10:43 PM
The only way to do this is to get a second IP address, then set up a one-to-one static translation for it, and have all your users connect to that static IP address. Yes, multiple users will be able to connect to that one IP address, no problem there.
The issue here is, as you've said, that you can't map GRE through with just the one IP addess, so they need the second one and map all protocols through to it with just a standard static NAT translation.
07-17-2003 10:43 PM
The only way to do this is to get a second IP address, then set up a one-to-one static translation for it, and have all your users connect to that static IP address. Yes, multiple users will be able to connect to that one IP address, no problem there.
The issue here is, as you've said, that you can't map GRE through with just the one IP addess, so they need the second one and map all protocols through to it with just a standard static NAT translation.
07-18-2003 02:00 PM
Thanks for confirming that. Is this something that will be supported in later IOS releases or is there some fundamental reason why it cannot work?
07-20-2003 06:38 PM
I guess it could work, we actually support static PAT translations for ESP/IPSec now, so I presume we could support it for GRE. It's probably that no-one's really asked for it. Feel free to contact your Account Manager and get them to put in a feature request for it, the more people that ask for it the faster it gets included.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide