03-18-2011 05:57 AM - edited 03-04-2019 11:47 AM
Hello,
I faced up with a strange configuration issue at my 2811 router running IOS C2800NM-ADVIPSERVICESK9-M, Version 15.1(3)T. The configured Dynamic and Static NAT do not work (users can't go out to Internet and can't reach internal services via external IPs).
The configuration seems to be very simple (one internal and one external interface, one address for dynamic NAT pool, and only few static translations -- see attached file).
I would appreciate any ideas to understand what is going wrong.
Thanks in advance,
Igor
03-18-2011 07:11 AM
Hi,
Can you add to ACLs applied to DMZ: deny ip any any log
Can you ask the clents to access internet and also access server from outside and take a look at the ACLs hit counts( show access-list) as well as look at the console logging concerning ACLs.
Regards.
Alain.
03-18-2011 08:53 AM
Hello,
It doesn't work -- I already tried to add "deny ip any any" at the end of each ACL for incoming and outgoing filters, but this rule was never triggered. I'll provide the "sh ip nat statistics" output a bit later.
WBR,
Igor
03-18-2011 02:05 PM
Hello Igor,
This is strange... I've had a look on your configuration and I do not see anything immediately wrong. The output of the show ip nat translation would be most helpful here.
Is the routing actually set up correctly? I see a static default route configured on your router but is it actually present in the routing table? Can at least the router itself reach the internet?
As a matter of rule, if ACLs are suspected, you can either add the deny ip any any log on their end, or try removing them temporarily from your interfaces to see if the issue is resolved.
Perhaps it would also be useful to try using the debug ip nat to see if there are any interesting information logged.
Best regards,
Peter
03-22-2011 02:47 PM
Hello Igor,
I have two 1921 with IOS 15.1-3T, with exactly the same problem.
The strangest thing is that my config was working perfectly on a 12.4 on another of my machine, but when switched to 15.1, the ports seem to remain closed.
Until now, no clues in sight.
Kind regards,
Sébastien
03-22-2011 02:54 PM
Hi Sebastien,
Thanks for your comment -- it means I'm not alone and the problem can be reproduced. Welcome to the club!
For the moment, I had no chance to test another configuration (no ACLs on interface, so there's obviously no dropped traffic, + activated ip virtual-reassembly on nat inside/outside interfaces. I don't see how it could help since NAT works using info from packet header, and does not need to re-assemble the source packet, but still want to give it a try).
Let me know if you use ACLs on nat outside interface and if you use ip virtual-reassembly.
I should have my SmartNet contract renewed on this week, so will post a question to Cisco Support then.
WBR,
Igor
05-20-2011 02:29 AM
Hi Sébastien
My friend is facing the same NAT issue. After he complete NAT config and boot system flash:/c2800nm-ipbase-mz.124-15.T.bin it works OK, but once he change to boot system flash:/c2800nm-adventerprisek9-mz.151-4.M.bin the same problem happen.
Is there any solution from lgor? Since he already purchased cisco smartnet and can get support from cisco.
Mike
05-21-2011 12:34 AM
Hi Mike,
No I didn't receive any update from Igor, and Cisco did not gave us a clue either, I have a smartnet contract as well.
So my solution was to insert an hwic card with 4 gigabit ethernet, and then on those ports, everything is working normaly...
I don't understand why on the local gigabit port it's not working.
Sebastien
05-21-2011 01:58 AM
For those with a support contract that are struggling with the TAC:
If it is broken, Cisco ought to acknowledge and fix it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide