cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
4
Replies

if i remove this ip nat outside commnd from we can able to access internet ..please help..

contactamit21
Level 1
Level 1

Hi, this is the configuration where I am using two different links one as backup and other as main, same configuration is working on my...

interface GigabitEthernet0/0
description **BROADBAND**
ip address 192.168.1.2 255.255.255.0
ip nat outside
ip virtual-reassembly in
load-interval 30
duplex auto
speed auto
!
interface GigabitEthernet0/1
description **LAN**
ip address 10.20.0.1 255.255.255.0 secondary
ip address 10.66.69.17 255.255.255.240
ip nat inside
ip virtual-reassembly in
load-interval 30
duplex auto
speed auto
!
interface Serial0/0/0
bandwidth 2048
ip address 10.66.64.109 255.255.255.252
ip nat outside
ip virtual-reassembly in
encapsulation ppp
load-interval 30
!
interface Serial0/0/1
no ip address
encapsulation ppp
clock rate 2000000
!
ip forward-protocol nd
!
ip http server
ip http secure-server
!
ip nat pool gramin 10.66.69.16 10.66.69.31 netmask 255.255.255.240
ip nat inside source route-map isp-b interface GigabitEthernet0/0 overload
ip nat inside source route-map isp-s interface Serial0/0/0 overload
ip route 0.0.0.0 0.0.0.0 10.66.64.108 10
ip route 0.0.0.0 0.0.0.0 192.168.1.1 251
!
access-list 101 permit ip 10.20.0.0 0.0.0.255 any
!
route-map isp-b permit 10
match interface GigabitEthernet0/0
!
route-map isp-s permit 10
match interface Serial0/0/0
!

4 Replies 4

Philip D'Ath
VIP Alumni
VIP Alumni

I don't understand your question.  Can you phrase it differently.

I agree that the question is not clear. But it is obvious that the issue involves something about NAT using two outside interfaces and I do have a comment about that. There is a challenge when using NAT for two outside interfaces. The solution to that challenge is frequently to use a route map to control the address translation. This config does have route maps to control the address translation. But the route map has a match only for the interface. I would also expect the route map to have a match statement for an access list which identifies what traffic should be translated but this config does not have a match for an access list.

HTH

Rick

HTH

Rick

Hello,

The OP means "The IP NAT outside" under the interface serial0/0/0 (I checked the OP other post)

You have two IP addresses on the LAN interface. Which one are you using as a source to test?

Please share the output of these commands also.

Show IP route

Ping 8.8.8.8 source 10.66.64.109 (or /source)

Masoud

Hello

I can see some misconfiguration with your post.

1) the addressing relating to ser0/0/0 has a subnet of /30 with ip address of 10.66.64.109  but your static route next hop is in a different subnet 10.66.64.108 - So either your serial interface ip is incorrect or you have specified an incorrect nexthop or subnet mask.

2) Your NAT route maps are not relating to any acl so are not matching their outgoing interface

3) Is there a need to double NAT on the backup interface as this interface is using a RFC1918 private addressing, So I guess the attached router is already performing NAT, however this shouldn’t stop you performing double natting if you wish too.

4) The nat pool is incorporating the subnet/broadcast address(s) also isn’t being referenced either by NAT translation statement


Can you amend your configuration to the following:

1) Apply some tracking for the primary default route and also going with a /30 subnet mask  you posted for serial 0/0/0 and keeping the same interface ip

ip sla 1
icmp-echo 10.66.64.110 source-ip 10.66.64.109
ip sla schedule 1 life forever start-time now

track 1 rtr 1 reachability


no ip route 0.0.0.0 0.0.0.0 10.66.64.108 10
ip route 0.0.0.0 0.0.0.0 10.66.64.110 10 name Primary track 1

2)
no ip nat pool gramin 10.66.69.16 10.66.69.31 netmask 255.255.255.240
no ip nat inside source route-map isp-b interface GigabitEthernet0/0 overload
ip nat pool gramin 10.66.69.18 10.66.69.30 netmask 255.255.255.240
ip nat inside source route-map isp-b pool gramin

3)
no access-list 101 permit ip 10.20.0.0 0.0.0.255 an
access-list 100 permit ip 10.20.0.0 0.0.0.255 any
access-list 100 permit ip 10.66.69.16 0.0.0.15 any

4)
route-map isp-b permit 10
match ip address 100
match interface GigabitEthernet0/0

route-map isp-s permit 10
match ip address 100
match interface Serial0/0/0




Let me know how you get on?

res
Paul




Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul