NAT ROUTER

Dear All,
I HAVE cisco 1841.
it has 2 interfaces.
the first one which is f 0/0 is have public ip from my ISP.
the other one is normal, and i am going to give it 192.168.1.100 / 24.
now i have 3 subnets totally diffrent .
i want to create 3 subinterfaces from f0/1.
my question is , how many subinterfaces can i add under the f 0/1 ?
and can i make this Router work as NAT ( overloading ) but all the 4 subnet will use the same public IP Address ?
can it be done as per this diagram ?
please update me.

Mohammed,
From your diagram, it looks like you have a 3COM switch between the 1841 and the 172.16.0.6 device (Cisco Switch ?).
Any reasons you aren't connecting the 1841 directly to this device avoiding the extra hop on the 3COM switch ?
You can create the subinterfaces in the 1841 as you stated but keep in mind you need to trunk the link at the other end (3COM switch) so it can tag each VLAN you've created.
Based on your diagram, I recommend performing the interVLAN routing at the Core (4507 switch), send the default route over to the 1841 running as single interface -let's say 192.168.1.100/24- and do the NAT there.
Much simpler configuration.

Similar Messages

  • Problem with WRT54G and DSL NAT router

    I have a WRT54G connected to a Westell DSL NAT router. I would like to be able to allow incoming connections to my FreeBSD server.
    The Westell router allows me to set IP Passthrough (they call it "Single Static IP"). This gives the WRT54G the outside IP address given to the DSL router. I can then set up the WRT54G for DDNS and port forwarding to forward specific ports I want to my server.
    This works, for about 2-3 days. Then, I start to randomly lose outside connectivity. Web pages start coming up with missing elements, or taking a long time to load. This will eventually lead to total loss of outgoing communication.
    Normally, I would blame this on the Westell NAT router, but as I'm losing connectivity to the internet, I'm also losing connectivity to the WRT54G. It will try to load configuration pages but will be slow with missing elements, etc.
    All communications between computers on my inside network continue to function properly, it's just connectivity to the WRT54G and the internet that seem to start to fail.
    Does anyone have any idea what is going on? I just upgraded the firmware on the WRT54G from 1.01.1 to 1.02.0, but I don't imagine this will help.
    Thanks,
    David Chamberlain

    Try setting the MTU to manual and change the value to 1450
    "Only those who risk going too far can possibly find out how far one can go..."

  • Setting up as a NAT router

    I want to try using Leopard Server on an Xserve as a NAT router. With 2 NICs the hardware is perfectly capable, but there seems to be a glitch in OSX that is preventing me from getting there.
    I have Ethernet 2 (en1) set up for the LAN (10.0.0.0 network) and intend to use Ethernet 1 (en0) for the WAN side of things and to this end have the en0 configurations at the top of the list of ports (as per instructions). But...
    NAT setup in Server Admin only lists ethernet ports that are open/connected. In order to do this I turn on the modem connected to Ethernet 1 and OSX configures the port from the DHCP server on the modem (192.168.x.x). Although this 'works' and allows me to browse the modem's web config GUI, it absolutely STOPS Server Admin. e.g. if I try and launch SA after switching on the modem, it sits there spinning the wheel without even showing a window - for as long as I wait. As soon as I turn OFF the modem (which de-configures the Ethernet 1 port) the SA window IMMEDIATELY appears and it commences its normal startup process. After which of course the only available interface in NAT setup is ... Ethernet 2:-(
    Nothing else seems to suffer when the modem is ON and Ethernet 1 is configured and connected - just Server Admin and this leaves me with a bit of a problem.
    When the modem is off, I cannot configure NAT in Server Admin as the required ethernet port is not listed, but when I turn the modem ON, I cannot run Server Admin.
    Anyone any suggestions as to how I can prevent or get around this?

    BigBex wrote:
    1) If I restore my 3GS or set it up as a new phone will I lose all my wifi settings? I ask this as I use various wifi and can't remember all the passwords.
    If you set up as a new phone, your iPhone will not retain its WiFi settings. However, these settings are stored in backups on iTunes, and are recoverable. If you restore from a backup instead of restoring as new, (provided that you have your iPhone backed up), then your iPhone will retain its WiFi settings.
    More about backups: http://support.apple.com/kb/ht1766 If you read this, you will find WiFi passwords listed under "iTunes will back up the following information."
    BigBex wrote:
    2) Why should thousands of customers be treated with utter contempt by Apple?
    Get this into your thick head Jobs - IT DOESN'T "JUST WORK"!!
    This is a user-to-user support forum. Not sure how to answer this question. Not enough information provided.

  • How to use a fixed port for remote assistance in windows 8.1 behind a nat router freebox?

    Hello,
    Before to use remote assistance in windows 8.1, i need to configure my nat router freebox.
    But remote assistance ( msra.exe ) use a dynamique port and never the same.
    How to use a fixed port for remote assistance ini windows 8.1 ?
    And why i can't use easy connect ?
    i read that the router must implement the PNRP protocol. I think it's a propriatary microsoft's protocol unknow on my router.
    Thanks

    Hello,
    Very good. It's a big range ( 255 mini from 49152 )  for a single port but if it's the only one possibility...
    You are very helpfull ( i don't know if it's a good english but you make me very happy )
    Merci beaucoup

  • RV180 - DDNS behind 2nd NAT router

    Hello community,
    is it possible to use the DDNS feature (dyndns.com) behind a 2nd NAT router?
    Network is as follows:
    INTERNET - NAT-Router (unknown device) - Cisco RV-180 (NAT) - Clients
    Kind Regard,
    Michael

    If you put your dyndns client in front of the rv180 or one the nat router's dmz, you should get the correct IP address.  I usually use the DMZ port on a nat router when putting a vpn router behind a nat one--this solves a lot of the IP address issues for the vpn router.
    Huntsville's Premiere Car and Bike e-magazine: www.huntsvillecarscene.com

  • WLSE manage AP using SNMP through xDSL line with an NAT router

    Hi,
    This is the deployment architecture that I had :
    WLSE (Internet public add)--->xDSL----->NAT router---->BBSM--->APs
    I had a problem in managing the APs which the ip address will be translated to a public ip addresses. When I use discovery options from my WLSE, it does not find any AP. I enable the CDP on my router and APs. There is only 1 ssid on all my APs.
    Is it possible to manage the APs using snmp using this model?
    regards,
    Sam

    Since you have NAT in between the WLSE and the APs, this will not work. SNMP does not work over NAT. To test this, try using the SNMP Reachable Tool under Administration->Connectivity Tools. enter the ip address and click on SNMP Reachable, you'll see that it will time out.

  • Does Stratus/RTMFP support P2P behind the same NAT/Router?

    Does Stratus/RTMFP support peers behind the same NAT/Router?
    (such that both peers have the same public IP address)
    That is: if two computers (each running Flash) are behind the same NAT, and connect to Stratus to get peerID;
    do we expect they can connect p2p?
    Or will each one get/see just the public IP address:port of the other?
    My initial tests indicate that this scenario fails [ICMP Destination Unreachable (port unreachable)]
    Is this just a limitation of my local router? does this work for others?
    Does Status expect the local router to detect/decode/resolve this situation?
    If the solution requires 10.1 groups, is there support to detect/diagnose when/if the peer is on the same LAN?

    Thanks for the info, sounds like RTMFP supports this, and hopefully the AFP code does the right thing.
    [so, officially, the original question is answered]
    Note: In one instance, i'm running two browsers on the same host,
    so even the inner/LAN addresses would be the same. Therefore, if A sends to B's inner/LAN address,
    the [Windows] OS network layer *should* recognize that and 'hairpin' without leaving the host, or crossing the firewall.
    (I say "should" because Unix generally does that, but I'll have to check to see about Windoze).
    [And such packets are probably invisible to Wireshark also, so how do i verify what's happening?
    oh sure, just reconfigure to boot Linux... ]
    So glad you explained that the client tries all three pathways; if it works as you say,
    then I can probably ignore the ICMP error from the local router (or, as you say, teach it to do the hairpin).
    Can you confirm that P2P will work between browsers (say Chrome to Firefox) on a single Windows host?
    [I really want to know if I'm failing because of network configuration or application code/error;
    at this point, I am able to correctly exchange the peerIds, and start the NetSteam.play,
    but the two sides do not appear to be exchanging audio/video]

  • Airport Express (802.11n) as non-NAT router?

    I am considering to replace an old WLAN router by an Airport Extreme. For this, the Airport Extreme unit would need to work as a non-NAT router (my network consists of multiple independent subnets). I've looked through the (very helpful) discussions, but could not find a definitive answer to this question. So, can you tell me point-blank whether an Airport Express (802.11n) base station can be used as a *non-NAT router* (connected to subnet A via the WAN port, creating a different subnet B on the LAN ports)?

    broadwater, Welcome to the discussion area!
    No this can't be done. The AirPort Extreme base station (AEBS) can be configured to create a single subnet for all clients (LAN port or wireless) but in that mode DHCP and NAT are enabled.

  • Internal DNS server and NAT routing issue.

    Hi -- I am not terribly experienced with DNS and I am running into an issue that I can't seem to resolve. My company.com DNS information is hosted by an outside ISP for email, web, etc... but I have configured an A record there to point to the public IP to my mac os x server (server.company.com).
    We have a cisco router configured with one to one NAT from the public IP to the internal IP for our server in a 192.168.15.x subnet. The same router is running DHCP and and NAT on that subnet under a different public IP provided by our ISP.
    Our server is running DNS with recursion and has a "company.private" zone set up for internal services and machine names. Thus, the server is accessible via "server.company.com" from the outside and "server.company.private" from the private LAN.
    The problem is that I would like to be able to access some services simply via "server.company.com" both inside and outside the private network. Now, accessing the "server.company.com" services from the private lan does not work because the name resolves to the external IP and the external IP cannot be used internally due to NAT.
    Is there a way to configure my internal DNS server to respond with the appropriate private address when receiving a query only to "server.company.com" and forward requests on for anything else on "company.com"?
    I know that I could manually duplicate all entries for our domain from my ISP and host the same entries for internal clients, but it would be much easier to only have our server handle requests for itself. The server is running OS X Server 10.4.11.
    Thanks

    Is there a way to configure my internal DNS server to respond with the appropriate private address when receiving a query only to "server.company.com" and forward requests on for anything else on "company.com"?
    Ordinarily, no. Once your server thinks it is responsible for a zone (e.g. company.com) then it will answer all queries for that domain and never pass them upstream. Therefore you'd have to replicate all the zone data, including all the public records, and maintain them both.
    The one possible exception to this (I haven't tried) is to create a zone for server.company.com that has your internal address. In theory (like I said, I haven't tried this), the server should respond to 'server.company.com' lookups with its own zone data and defer all other lookups (including other company.com names since they're not in a zone it controls). Might be worth trying.

  • Mac OSX server not supported behind Airport Extreme NAT router?!!

    For a customer, I recently installed a new XServe, within a local network with an Airport Extreme (n) with FW 7.4.2. Mac OSX Server manages the router (which has a fixed IP from the ISP). Because the Mac OSX Server runs a DNS server (supporting a local domain), OSX Server reconfigured the Airport Extreme, so that it would forward DNS queries to the server. The server's dns server will forward queries for non-local domains to the ISP's dns servers.
    All clients get their IP configuration using DHCP from the router. You can't use the DHCP service of the server, as you can't disable DHCP on the router (in NAT mode).
    All clients get the router's IP as the dns server.
    HOWEVER:
    The Airport Extreme can't connect to the internal DNS server! *It doesn't seem to be able to route dns requests to the internal network* (verified using nslookup). Any dns queries sent to the router will time out.
    Come on, Airport Extreme team.. you can't claim the Airport Extreme to be the ideal router in combination with an OSX server, if this simple and very common setup is not supported! How hard can it be to either:
    ...*Allow us to disable DHCP on the router* (even when in NAT mode), so we can use the OSX server for this (which will dispatch the correct DNS settings)
    ...*Allow the router to route DNS queries to the local DNS* (OSX) server (which should be working anyway)
    Message was edited by: blackbit

    blackbit, Welcome to the discussion area!
    It doesn't seem to be able to route dns requests to the internal network (verified using nslookup).
    That is true.
    This is a user to user discussion area so Apple will not see your suggestions here. Instead go to www.apple.com/feedback/airportextreme.html and send them to Apple.

  • Open NAT Router vs. 2 Xbox 360

    I have researched this issue and am still unsuccessful. I have CM100 modem with a WRT54G2 version 1.5 all using 20meg Charter cable line to run 2 Xbox 360's in the same room. There is nothing else sharing the line. One xbox runs wireless and one xbox is wired to the router. I configured the router in the Port Triggering section to try and stop the NAT moderate restrictions that keep popping up on 1 of the Xbox 360's (wired). The upnp is enabled. The DMZ is not enabled. I have 4 Xbox configs listed on the Port Triggering section, 88, 3074, etc... but we are still running into the nat Moderate restriction. Other discussions say I should not input into the Port forwarding, only the port triggering. I check the xbox and they both are on automatic. Any help would be appreciated. The NAT moderate seems to trigger when they join the games but is open when we are just testing the network. I think I have reached the limit of my network/router expertise. Is it possible the modem is causing the NAT issues. Any help would be greatly appreciated.

    Check this link.Reduce the MTU value to 1365 on the router and uncheck "Block Anonymous Internet Requests" Under Security tab...

  • Firewall/nat/routing issue

    I am not able to setup a firwall box which will transmit internet packets from internal network to the internet and otherway. Could you please guide me what i am missing here and where I am going wrong?
    [internet] ----(public ip)---[cable modem]( 192.168.1.1)------( 192.168.1.51)[solaris 10 x86 f/w box]( 192.168.0.52)------[router]------(ip: 192.168.0.105/gw:192.168.0.52 ) [PC]
    On solaris box: I can ping 192.168.1.51 , 192.168.0.52, 192.168.1.1 & Internet
    From PC I am able to ping 192.168.1.51 to 192.168.0.52 but NOT 192.168.1.1 or internet.
    Routing table is :
    # netstat -rn
    Routing Table: IPv4
    Destination Gateway Flags Ref Use Interface
    192.168.0.0 192.168.0.52 U 1 2 rtls1
    192.168.1.0 192.168.1.51 U 1 8 rtls0
    224.0.0.0 192.168.1.51 U 1 0 rtls0
    default 192.168.1.1 UG 1 13
    127.0.0.1 127.0.0.1 UH 3 24 lo0
    # ndd -get /dev/ip ip_forwarding
    1
    Thanks in advance :-)
    Neeraj

    can you give us a debug ccsip output please with the SIP invite messages and so forth.

  • How to set up DNS behind a NAT router...

    I am trying to configure DNS in Panther Server as the SOA for my domains and as a LAN name server. I've read several explainations about setting up DNS including technical document 106853 "How to set up DNS in a NAT environment" which says:
    Note: For Mac OS X Server 10.3 or later, you should use the Server Admin
    application to configure DNS and NAT. Please see the Network Services
    Administration Guide for additional information.
    Seeing how picky BIND is, this sounds like a good idea, except I can't configure views like that.
    Questions:
    1) What happens if I create an A record in my main domain for newmac.mydomain.com-->10.0.1.2? People outside the LAN can't get to it, right?
    2) Can I create really simple names for the LAN like newmac-->10.0.1.2?
    Thanks!

    You can use "system-config-network" command to configure your DNS configuration.

  • EA4500 behind NAT Router - would cloud config work?

    This is the topology:  
    Internet +--(coax)--+ Modem/Wired Router Combo +--(cat5e)--+ EA4500
    Would it EVER be possible to configure the EA4500 with CiscoConnectCloud?   How could the cloud reach through to it?  
    I have an EA4500 that I have never been able to associate with a cloud account. 
    With another wireless router, all I did was turn off DHCP service on the wireless router, and plug the upstream ethernet cable into an ethernet port (i.e. the cat5e goes into the blue, not yellow, port.) and let it rip. 
      I wouldn't deliberately choose cloud config for this, but I am here.  Is it even possible?

    Thank you for your careful answer.  These are really good suggestions, and I bet they will help many people.   In fact, at my house I should implement them even though my current best router is a Netgear N600 type.   That sounds bizarre, but it is because this EA4500 isn't mine. 
    It belongs to my parents, a thousand miles away.  Last April when I visited them, I set them up with a Roku XS.  They have necessary activities going on their computers, active trading and such.  Because I'm not there, at my recommendation, they rent their networking stuff from Comcast, so Comcast can help them if there's a problem.  They live in one of those houses that originally was one fourth of its current size, so they have different density walls, many different base electrical circuits: not what is best for wireless networking.  Their established wireless setup couldn't begin to deliver to the TV.
    I knew it was rather insulting to the EA4500, but I bought it and set it up solely to deliver content to the Roku.  I also figured if their wimpy wireless went out and Comcast made them wait, I would just tell them how to connect to the Cisco, as a backup, if necessary.   They didn't use the Roku a whole lot, and for a while they thought they did something wrong.  So it was a while before I even heard about their issues. It was a very early unit, purchased on April 9.  I may also have jumped to a conclusion - they said it stopped working in the week or two before the Fourth of July. , Dad and I did a lot of sleuthing over the phone, on and off for weeks.  Then  I assumed it was the firmware update that broke their connectivity.  So this week when I had them ship me the router so I could work on it at my house.
    Your ideas are great and I am going to set it up here the way you both say and let the Cisco do the heavy lifting.  That will tell me for sure whether the thing is working properly. 
    Because for right now, the only way it works as a router is when it is dumb and connected via LAN not WAN.  It's the only way I can log in to configure it, and it's the only way I can connect to the internet "through" it.  I've been going back and forth between the firmware versions, topology, and wireless versus wired.  And resetting.  Gosh, thanks for getting me out of that rat trap!  

  • Router NAT Configuration

    Hi,
    I have a pc behind a nat router with ip 192.168.1.2.
    Setting virtual server on my router configuration, when a request arrive on my router on 1099 port, router send this request to my pc.
    So clients can connect to rmiregistry running on my pc.
    Rmi Server Object is registered with option
    -Djava.rmi.server.hostname=82.xx.xx.xx (public ip of router)
    so clients connect to this public ip to find rmi object.
    My problem is this: when I run rmi server object with this option, after 25second the object falls.
    If I run it without this option, it doesn't fall but it is registered with local ip and clients can't connect to it.
    RmiRegistry and RmiServerObject run on the same local pc behind router.
    Thanks.
    Bye

    If I know why it falls I could resolve it.
    There isn't an exception error.
    This is the main function of MyServerImpl that extends UnicastRemoteObject and implements MyServer interface.
    public static void main(String args[]) {
    String rmiregistry_host="localhost";
    // String rmiregistry_host="192.168.1.5";
    //String rmiregistry_host="82.51.85.191";
    String URL="jdbc:odbc:DBExAllievi";
    String driver="sun.jdbc.odbc.JdbcOdbcDriver";
    if(args.length==1){
    rmiregistry_host = args[0];
    }else if(args.length==3){
    rmiregistry_host = args[0];
    driver=args[1];
    URL=args[2];
    System.setSecurityManager(new RMISecurityManager());
    try {
    GestioneDatiExAllievi_IMPL istanza = new GestioneDatiExAllievi_IMPL();
    istanza.settaggi(driver,URL);
    Naming.rebind("//"+rmiregistry_host+"/GestioneDatiExAllievi", istanza);
    System.out.println("Registrazione oggetto remoto effettuata");
    catch (Exception e) {
    System.out.println(e.getMessage());
    This is the output:
    http://www.cplusplus.it/file/output.jpg
    The String "Registrazione oggetto remoto effettuata" is shown so there isn't exception, but after 24 seconds the application exits.
    Instead if I run without -Djava.rmi.server.hostname=82.51.85.191 it's all ok, but my rmi object is registered with local ip, so I can't use it over the internet but only in lan.
    I hope now I explained better the problem.
    Sorry.

Maybe you are looking for