01-10-2016 10:54 PM - edited 03-05-2019 03:05 AM
Hi, this is the configuration where I am using two different links one as backup and other as main, same configuration is working on my...
interface GigabitEthernet0/0
description **BROADBAND**
ip address 192.168.1.2 255.255.255.0
ip nat outside
ip virtual-reassembly in
load-interval 30
duplex auto
speed auto
!
interface GigabitEthernet0/1
description **LAN**
ip address 10.20.0.1 255.255.255.0 secondary
ip address 10.66.69.17 255.255.255.240
ip nat inside
ip virtual-reassembly in
load-interval 30
duplex auto
speed auto
!
interface Serial0/0/0
bandwidth 2048
ip address 10.66.64.109 255.255.255.252
ip nat outside
ip virtual-reassembly in
encapsulation ppp
load-interval 30
!
interface Serial0/0/1
no ip address
encapsulation ppp
clock rate 2000000
!
ip forward-protocol nd
!
ip http server
ip http secure-server
!
ip nat pool gramin 10.66.69.16 10.66.69.31 netmask 255.255.255.240
ip nat inside source route-map isp-b interface GigabitEthernet0/0 overload
ip nat inside source route-map isp-s interface Serial0/0/0 overload
ip route 0.0.0.0 0.0.0.0 10.66.64.108 10
ip route 0.0.0.0 0.0.0.0 192.168.1.1 251
!
access-list 101 permit ip 10.20.0.0 0.0.0.255 any
!
route-map isp-b permit 10
match interface GigabitEthernet0/0
!
route-map isp-s permit 10
match interface Serial0/0/0
!
01-11-2016 12:55 AM
I don't understand your question. Can you phrase it differently.
01-11-2016 07:23 AM
I agree that the question is not clear. But it is obvious that the issue involves something about NAT using two outside interfaces and I do have a comment about that. There is a challenge when using NAT for two outside interfaces. The solution to that challenge is frequently to use a route map to control the address translation. This config does have route maps to control the address translation. But the route map has a match only for the interface. I would also expect the route map to have a match statement for an access list which identifies what traffic should be translated but this config does not have a match for an access list.
HTH
Rick
01-11-2016 02:59 PM
Hello,
The OP means "The IP NAT outside" under the interface serial0/0/0 (I checked the OP other post)
You have two IP addresses on the LAN interface. Which one are you using as a source to test?
Please share the output of these commands also.
Show IP route
Ping 8.8.8.8 source 10.66.64.109 (or /source)
Masoud
01-12-2016 03:29 AM
Hello
I can see some misconfiguration with your post.
1) the addressing relating to ser0/0/0 has a subnet of /30 with ip address of 10.66.64.109 but your static route next hop is in a different subnet 10.66.64.108 - So either your serial interface ip is incorrect or you have specified an incorrect nexthop or subnet mask.
2) Your NAT route maps are not relating to any acl so are not matching their outgoing interface
3) Is there a need to double NAT on the backup interface as this interface is using a RFC1918 private addressing, So I guess the attached router is already performing NAT, however this shouldn’t stop you performing double natting if you wish too.
4) The nat pool is incorporating the subnet/broadcast address(s) also isn’t being referenced either by NAT translation statement
Can you amend your configuration to the following:
1) Apply some tracking for the primary default route and also going with a /30 subnet mask you posted for serial 0/0/0 and keeping the same interface ip
ip sla 1
icmp-echo 10.66.64.110 source-ip 10.66.64.109
ip sla schedule 1 life forever start-time now
track 1 rtr 1 reachability
no ip route 0.0.0.0 0.0.0.0 10.66.64.108 10
ip route 0.0.0.0 0.0.0.0 10.66.64.110 10 name Primary track 1
2)
no ip nat pool gramin 10.66.69.16 10.66.69.31 netmask 255.255.255.240
no ip nat inside source route-map isp-b interface GigabitEthernet0/0 overload
ip nat pool gramin 10.66.69.18 10.66.69.30 netmask 255.255.255.240
ip nat inside source route-map isp-b pool gramin
3)
no access-list 101 permit ip 10.20.0.0 0.0.0.255 an
access-list 100 permit ip 10.20.0.0 0.0.0.255 any
access-list 100 permit ip 10.66.69.16 0.0.0.15 any
4)
route-map isp-b permit 10
match ip address 100
match interface GigabitEthernet0/0
route-map isp-s permit 10
match ip address 100
match interface Serial0/0/0
Let me know how you get on?
res
Paul
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide