Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Task 1
R2 is the NAT router, R2’s S1/1 interface should be configured as the Inside and R2’s S1/3 interface should be configured as Outside domain.
Configure R2 such that R3 can ping 12.1.1.1. You should configure Static NAT on R2 to accomplish this task. DO NOT configure any static, dynamic routing, PBR, or
PAT on R2.
Before we configure the static NAT let’s define the NAT domains:
On R2:
R2(config)#int s1/2
R2(config-subif)#ip nat inside
R2(config)#int s1/3
R2(config-if)#ip nat outside
Since R3 is on the Outside NAT domain, the following Static NAT is configured to translate the source IP address of 23.1.1.3 for ingress traffic
to 12.1.1.3 :
On R2:
On R3:
On R2:
The NAT translation table reveals that when the NAT router (R2) received a packet on its Outside interface (S1/3) with an IP address of
23.1.1.3, it translated the source IP address of 23.1.1.3 to 12.1.1.3, then, R2 consulted its routing table and sent the packet to R1.
R1, and ping 12.1.1.1 from R3 and examine the output of the debug on R1:
On R1:
On R3:
On R1:
IP: s=12.1.1.3 (Serial1/2), d=12.1.1.1, len 100, input feature, MCI Check(80), rtype 0, forus FALSE,
sendself FALSE, mtu 0, fwdchk FALSE
IP: tableid=0, s=12.1.1.3 (Serial1/2), d=12.1.1.1 (Serial1/2), routed via RIB
IP: s=12.1.1.3 (Serial1/2), d=12.1.1.1 (Serial1/2), len 100, rcvd 3
IP: s=12.1.1.3 (Serial1/2), d=12.1.1.1, len 100, stop process pak for forus packet
We can see that R1 received the ICMP packet generated by R3; R2 received the packet with a source IP address of 12.1.1.3 (The translated
source IP address of R3), and it replied back with a source IP address of 12.1.1.1 destined to 12.1.1.3. So the problem must be on R2.
When traffic is received on the Outside interface, NAT occurs before routing.
When traffic is received on the Inside interface, routing occurs before NAT.
When R2 received the traffic from R1 on its Inside interface it looked for a route for 12.1.1.3 destination,
and since it did not see a route for that destination, the packet was dropped, let’s add a static route for 12.1.1.3 destination and verify the
result:
On R2:
On R3:
On R2:
But the task stated that static, Dynamic routing or PBR is prohibited, so how are we going to accomplish this task?
This task can be resolved by adding the “Add-route” keyword at the end of the “IP NAT Outside static” statement.
Let’s configure the keyword, remove the static route, and test and verify:
On R2:
On R2:
We can see that the “add-route” keyword added the static route for us, this is highlighted in yellow.
On R3:
R3#ping 12.1.1.1
On R2:
Narbik Kocharians
CCSI#30832, CCIE# 12410 (R&S, SP, Security)
www.MicronicsTraining.com
Sr. Technical Instructor, and a Cisco Press Author
A Cisco Learning Partner