10-20-2011 03:43 PM - edited 03-04-2019 02:00 PM
i have cisco router 1811 , i make port forwarding for my mail server ,
so from outside i can access to the mail server via my mobile but inside lan i cannot because
i use my global ip address at my mobile config .
Please fine attaced of my example config.
10-24-2011 05:44 AM
I normally have this set up using a FQDN (for example. mail.yourdomain.com). then make sure that your DNS server can resolve the FQDN from the local LAN.
10-24-2011 05:56 AM
Hi,
As already talked about in other theads here , this is called NAT hairpinning and this is not supported on Cisco routers at least on enterprise models like the 1800 serie but you can use a FQDN and I think that these routers can do DNS doctoring by default so you may not need an internal DNS server entry as it then will work with any public DNS having the record for your public IP.
Regards.
Alain.
10-24-2011 07:27 AM
hi,
thank you for your reply , i check many site's all talk the solution is add ASA device , but i don't understand if i don't need ASA no luck to make it , the problem my mail server is locally xxxxx.xxxxx.local , also i use port forwarding to reach the IP camera .
ip nat inside source static tcp 10.0.5.39 5039 interface Dialer0 5039
ip nat inside source static tcp 10.0.2.30 pop3 interface Dialer0 pop3
i try dyndns service but also no luck
you can find the example attached .
sorry for my bad english language
10-24-2011 10:16 AM
Hi,
If you try with the google dns server for inside hosts( 8.8.8.8) then this server will contact dyndns to get the IP and then dns doctoring should come into play and change the IP to private one and it should work.
Can you contact router by fqdn from outside now that you've got dyndns configured?
Regards.
Alain.
10-24-2011 10:40 AM
Thanks Mr. Alain
I use dyndns.org also I but name-server google DNS from outside I can reach router through dyndns or Static ip I already have it but the problem from inside LAN I can ping the static ip from inside but I can't go to exchange or ip camera through static ip and specific port
Sent from Cisco Technical Support iPhone App
10-24-2011 12:19 PM
Hi,
so from outside dyndns is working ok and you can contact router either with outside IP or name but you can't contact outside address with corresponding port from inside?What about by name+ port from inside if your inside host has any external dns server configured?
Alain.
10-24-2011 12:38 PM
yes from outside everything is ok by DNS name or ip but from inside nothing work only I can ping to the public ip and if telnet I arrive to router .
One question is my config displayed to you ?
Again many thanks for your cooperate .
Sent from Cisco Technical Support iPhone App
10-24-2011 01:59 PM
Hi,
yes I see your config in first post.
Can you show ipconfig of host and capture traffic from host when you try to communicate with fqdn and port to get to private address+ port.
Alain.
10-24-2011 02:58 PM
Hi,
sorry , i don't understand you too much , you mean ipconfig /all from my local pc ?
from my pc if i make telnet 10.0.2.30 110 , i get ok the port reply from exchange
ip camera same
if i change telnet
can you send to me what command you need i use it .
i see somebody but in this site soluwtion but he talk this work for more than 1 static IP.
http://ccie-in-3-months.blogspot.com/2008/12/nat-hairpinning-using-nat-pools-pbr.html
i try it but no luck
thanks
Marwan
10-24-2011 11:32 PM
When you say the ISP ip, i suppose you mean your outside interface IP? are you able to ping your outside interface? Are any other PC or server on the network able to ping or telnet to the outside interface IP?
10-25-2011 12:18 AM
Hi,
yes I want to see which dns server is configured on the PC. and I already told you that accessing your public IP from inside will never work because this feature is not supported in Cisco enterprise model routers.
So my question is Can you access it from inside with name eg telnet www.bla.bla.dyndns.org 110 if you have set an external dns server for your PC ? if not then can you capture traffic with wireshark when you do the above command.
Alain.
10-25-2011 06:00 AM
HI to all,
Mr. Marius , yes the ISP ip is my outside interface IP , i able to ping from LAN .
Mr. Alian , i can telnet xxxx.dyndns.org from local lan and get reply , also telnet
but when i add
------------------------------------------------------------------------------------------------------------------------
R1811#ping xxx.dyndns.org
Translating "xxx.dyndns.org"...domain server (8.8.4.4) [OK]
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 77.245.5.25, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 84/95/136 ms
R1811#telnet xxx.dyndns.org 110
Trying xxx.dyndns.org (77.245.5.25, 110)...
% Connection timed out; remote host not responding
------------------------------------------------------------------------------------------------------------------------
anyway i found today solution like this :-
i add to my config :-
R1811(config)# ip host xxxx.dyndns.org
then i amend my config at my mobile to use xxx.dyndns.org insted of
and i amend DNS server on my mobile to use Router IP insted of my windows server DNS
and it's work , i don't think this is the best way , but it's work .
one more question it's better to use the Router is DNS server instead of Windows Server 2003 DNS service ?
and what the best config DNS server for Router ?
with many thanks to all for your help .
Marwan Urabi
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: