08-29-2023 05:02 AM
We have a handful of trunk interconnected CBS350 switches that comprise a test network of multiple private IP addresses using VLANs. e.g.
Our main switch is configured as a layer 3 router. Routing works great between all networks and properly configured devices.
We have a need for certain devices to access an external subnet (example) 123.123.123.0/24. We cannot allow routing, STP, bridge packets, etc... to appear on the 123.123.123.0/24 network.
I set up a static route to point to a router address of 192.168.255.25 which was very straightforward.
I do not believe that the CBS350 does NAT so I am looking for some recommended solutions. We are working with opnsense but it has been proving to be problematic.
Any guidance or advice? Thanks.
08-29-2023 05:52 AM - edited 08-29-2023 05:53 AM
hello @bakerjw,
You're right none of the CBS and entry-level Cisco switches does support NAT.
Since you mentioned that you're using opnsense, you can configure NAT rules on the opnsense router to achieve this.
08-29-2023 07:49 AM
CBS350 is switch -(latest models only have NAT feature like Cat 9300)
if you looking NAT - Looks some RV series router does all for you (but they going end of Life soon).
Buy any Rasberry Pi works as expected.
08-29-2023 08:23 AM
Many thanks for the responses.
For our needs, the CBS350 switch running as L3 works great for our needs. opnsense has proven problematic to get set up though. I'll keep plodding that way.
Again, thanks!
08-29-2023 10:42 AM
What is a low end Cisco router that does NAT? My managers are pretty tight with the budget but I might be able to run a router and shift routing from the CBS350.
08-29-2023 11:32 AM
cisco 800 routers is smallest one can do the job for you - check the requirement and EOL statement before buying.
https://www.cisco.com/c/en/us/products/routers/product-listing.html
08-29-2023 11:52 AM
Many thanks for the insight.
If we go with a new router to replace the L3 routing of the CBS350, it cannot be EOL. One of our other internal groups has a lot of $$$ in their budget and I might be able to talk them into getting us something decent and supported for a while.
08-29-2023 12:00 PM
Sure you need to look for the budget - I run my Home Small Rasberry Pi with simple NAT works for years - if you like to save money only for NAT.
08-29-2023 12:08 PM
If budget is not a problem, have look to C9300.
08-29-2023 06:14 PM
LOL... that would certainly fit the bill.
Something a little more mid range would be preferred though to keep any sticker shock down.
thanks
08-30-2023 06:54 AM
what costing we consiering here . rather playing numbers to get approve some time from business is difficult.
I have this in the past with small company - so for them i run any used PC with daul Ethernet Linux with NAT should fix the issue. (if you can not able to spend money).
08-30-2023 10:04 AM
One last question.
Our Cisco supplier has recommended get a C1111-8P router. It seems to be a very capable piece of equipment and I wondered if anyone had thoughts pro or con about the device.
Many thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide