cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1913
Views
0
Helpful
4
Replies

Double NAT over GRE

james.reeves
Level 1
Level 1

I am trying to setup a connection in my router that will staticly translate the sourec and destination of a packet and then send it over the GRE tunnel.

Original packet S-10.10.10.10 D-10.20.20.20

XLATE router

Desired packet

Global Packet S-172.16.10.10 D-172.16.20.20

Gig0/0

ip nat inside

ip accounting output-packets

Loopback 10

ip address 10.20.20.1/24

Tunnel4

ip nat outside

ip accounting output-packets

ip nat inside source static 10.10.10.10   10.20.20.20

ip nat outside source static 172.16.20.20 172.16.10.10

ip route 172.16.20.0/24 tunnel4

If I do a traceroute and source it from the loopback interface it works fine and I see the traffic hitting the upstream router.  When actual traffic traverses I see it hit the xlate table but I never see it on the upstream router.  I do see my ping and traceroute in ip accounting.

Any ideas?

1 Accepted Solution

Accepted Solutions

Yes. For an inside to outside translation routing decision occurs first.  Accordingly NAT occurs then. Here is the cisco page for NAT order of operation -

http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml

View solution in original post

4 Replies 4

skarthic
Cisco Employee
Cisco Employee

So you are saying that the NAT translations are seen in the NAT table.

Could you paste the output of "debug ip nat detailed" and the " debug ip packet detail"

Also does the "sh ip nat translations" show the complete translation being made?

I believe I have found the issue.  There is a static route in the configuration for the local outside address pointing out another interface.  I am assuming the router would route the traffic first and then translate still on the outbound interface.

Would you agree?

Yes. For an inside to outside translation routing decision occurs first.  Accordingly NAT occurs then. Here is the cisco page for NAT order of operation -

http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml

Thank you.