Showing results for 
Search instead for 
Did you mean: 

Nat and cisco routing

Level 1
Level 1

I have following configuation. 

I dont have any access list or any thing. simple router configuration

Tunnel connection with my hub (ipsec)

crypto isakmp policy 100
encr aes
authentication pre-share
group 2
crypto isakmp key sams@ng address
crypto ipsec transform-set CR-TS-statement esp-aes esp-sha-hmac
mode transport
crypto ipsec profile CR-PR-statement
set transform-set CR-TS-statement

interface Tunnel2
ip address
no ip redirects
ip mtu 1390
ip nhrp authentication statement2
ip nhrp map multicast dynamic
ip nhrp map multicast
ip nhrp map
ip nhrp network-id 222
ip nhrp holdtime 60
ip nhrp nhs
ip nhrp registration no-unique
tunnel source FastEthernet8
tunnel mode gre multipoint
tunnel key 222
tunnel protection ipsec profile CR-PR-statement

interface FastEthernet8
ip address
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
interface Vlan1
ip address
ip nat inside
ip virtual-reassembly in
ip tcp adjust-mss 1452
router eigrp 2
passive-interface Vlan1
eigrp stub connected
no ip forward-protocol nd
ip http server
ip http authentication local
no ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip dns server
ip nat inside source list NAT interface FastEthernet8 overload
ip route
ip access-list extended NAT
permit ip any

The problem is i can ping every computer or hub from this (branch) router but i can not ping it from computers connected to (branch) router. what i am doing wrong ?????.

ping (this is from router to hub computer)
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/4 ms

3 Replies 3

Hall of Fame
Hall of Fame

but i can not ping it from computers connected to (branch) router. what i am doing wrong ?????.

network inside Lan ? 172.20.134.X network you mean ?

how is your show ip route looks like.


***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

IP routes

S* [5/0] via is subnetted, 1 subnets
S [1/0] via is variably subnetted, 8 subnets, 2 masks
C is directly connected, Tunnel1
L is directly connected, Tunnel1
C is directly connected, Tunnel2
L is directly connected, Tunnel2
D [90/26882560] via, 07:23:22, Tunnel1

D [90/26933760] via, 07:23:22, Tunnel1
D [90/26933760] via, 07:23:33, Tunnel1 is variably subnetted, 47 subnets, 2 masks
D EX [170/26882560] via, 07:23:22, Tunnel1
D EX [170/26882560] via, 01:39:07, Tunnel1
D EX [170/26882560] via, 00:13:22, Tunnel1
D [90/26933760] via, 07:23:33, Tunnel1
D EX [170/26882560] via, 01:39:07, Tunnel1

my routes are good. i cant ping from computer (network inside lan) but my router can ping successfully.

ip nhrp map multicast
ip nhrp map <<- this map is wrong you must change the IP to be
ip nhrp nhs

Review Cisco Networking for a $25 gift card