cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
214
Views
0
Helpful
3
Replies
Beginner

cisco ISR4331/K9 NAT UDP/TCP port-range cleanup

-Cisco IOS Software [Fuji], ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.9.2, RELEASE SOFTWARE (fc4)-

 

Hi All,

 

I've tried several suggestions I found on the community but without success unfortunately, and probably it will already be somewhere here on the community  but I cannot seem to find it.

I would like to cleanup the UDP NAT statements, so my config looks better. 

 

This is what I would like to cleanup:

ip nat inside source static udp 10.10.90.201 16000 interface GigabitEthernet0/0/0 16000
ip nat inside source static udp 10.10.90.201 16001 interface GigabitEthernet0/0/0 16001
ip nat inside source static udp 10.10.90.201 16002 interface GigabitEthernet0/0/0 16002
ip nat inside source static udp 10.10.90.201 16003 interface GigabitEthernet0/0/0 16003
ip nat inside source static udp 10.10.90.201 16004 interface GigabitEthernet0/0/0 16004
ip nat inside source static udp 10.10.90.201 16005 interface GigabitEthernet0/0/0 16005
ip nat inside source static udp 10.10.90.201 16006 interface GigabitEthernet0/0/0 16006
ip nat inside source static udp 10.10.90.201 16007 interface GigabitEthernet0/0/0 16007
ip nat inside source static udp 10.10.90.201 16008 interface GigabitEthernet0/0/0 16008
ip nat inside source static udp 10.10.90.201 16009 interface GigabitEthernet0/0/0 16009
ip nat inside source static udp 10.10.90.201 16010 interface GigabitEthernet0/0/0 16010
ip nat inside source static udp 10.10.90.201 16011 interface GigabitEthernet0/0/0 16011
ip nat inside source static udp 10.10.90.201 16012 interface GigabitEthernet0/0/0 16012
ip nat inside source static udp 10.10.90.201 16013 interface GigabitEthernet0/0/0 16013
ip nat inside source static udp 10.10.90.201 16014 interface GigabitEthernet0/0/0 16014
ip nat inside source static udp 10.10.90.201 16015 interface GigabitEthernet0/0/0 16015

 

I've read things about route map but this command my router does not accept.

 

Any ideas?

 

Thanks a lot in advance

 

Everyone's tags (1)
3 REPLIES 3
VIP Advisor

Re: cisco ISR4331/K9 NAT UDP/TCP port-range cleanup

Hello

Below is a possible solution however you mention your ios doesn't support route-maps correct?

access-list 100 permit udp host 10.10.90.201 range 1600 16015 any range 1600 16015
route-map UDP
match ip address 100

ip nat inside source static 10.10.90.201 10.10.90.201 route-map UDP extendable

EDITED

Looks like @pieterh as mentioned it already , i did also find a possible alternative to a nat route-map using NAT portmap which seems positive how ever ive never used it before and at present cannot test it.

access-list 1 permit 10.10.90.201
ip nat portmap UDP
appl udp-rtp startport 16000 size 16064

ip nat inside source list 1 interface x/x overload portmap UDP



kind regards
Paul

Please rate and mark posts accordingly if you have found any of the information provided useful.
It will hopefully assist others with similar issues in the future
Beginner

Re: cisco ISR4331/K9 NAT UDP/TCP port-range cleanup

Hi Paul,

 

it is supposed to be supported from IOS 12.x and I have 16.x:

 

And this is working ip nat inside source static 10.10.90.201 10.10.90.201 route-map UDP extendable

 

But it seems it has a problem with the WAN interface, so this is not working as it needs to come in from WAN to LAN or am I seeying this wrong?

 

ip nat inside source static 10.10.90.201 interface GigabitEthernet0/0/0 route-map UDP extendable

gives:

 

TMROUTER01(config)#ip nat inside source static 10.10.90.201 interface GigabitEthernet0/0/0 route-map UDP extendable
^
% Invalid input detected at '^' marker.

 

Best regards

Glenn Verhoeven

Highlighted
Rising star

Re: cisco ISR4331/K9 NAT UDP/TCP port-range cleanup

look at this post

no route map,  but ip nat portmap

check if your IOS version supports this command.

 

and this post that says:

If you notice on the last command that you are not allowed to use a route-map on an interface so I had to type in the WAN ip address. 

CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards