Why packets are being translated by one route-map and not the other?

Hi,
I have 2 NAT rules, each with a route-map to determine which packets are translated. What I don't understand is how to control which NAT rule is applied first..?
In my config, the first of the following rules is applied first, and then the other. I would like to have it the other way round, the second being applied first, and the first being applied second.
ip nat inside source route-map NAT_INTERNET_ACCESS_RMAP interface GigabitEthernet0/1 overload
ip nat inside source static 172.16.101.1 10.10.11.1 route-map NAT_RADIANZ_PIXACCESS_RMAP
The reason why I want it this way round is because the first rule NAT's almost everything so that I can access the Internet. The second rule NAT's specific traffic to a different address.
If I want traffic to be NATTED according to the second rule, I have to deny traffic in the first associated ACL, and permit it in the second ACL. That means I basically have to configure each ACL each time I want packets to be matched by the second NAT rule - there must be a better way of doing it!!!
Any help would be most appreciated.
Many thanks,
Michael.

Hello, here's the basic (shortened list). If I want packets to be matched by NAT_RADIANZ_PIXACCESS_ACL I have to put a deny in NAT_INTERNET_ACCESS_ACL. If I could make sure that the first list is used first, and then anything left over compared against the second, then it would make life/editing much easier...
Cheers,
Michael
ip nat inside source route-map NAT_INTERNET_ACCESS_RMAP interface GigabitEthernet0/1 overload
ip nat inside source static udp 10.10.11.1 500 10.10.11.1 500 extendable
ip nat inside source static udp 10.10.11.1 4500 10.10.11.1 4500 extendable
ip nat inside source static 172.16.101.1 10.10.11.1 route-map NAT_RADIANZ_PIXACCESS_RMAP
ip access-list extended NAT_INTERNET_ACCESS_ACL
remark Traffic to Branch A (over VPN)
deny ip 172.16.101.0 0.0.0.255 192.168.1.0 0.0.0.255
remark Traffic to Branch B (over VPN)
deny ip 172.16.101.0 0.0.0.255 172.16.0.0 0.0.0.255
deny ip 172.16.101.0 0.0.0.255 172.16.1.0 0.0.0.255
deny ip 172.16.101.0 0.0.0.255 172.16.2.0 0.0.0.255
deny ip 172.16.101.0 0.0.0.255 172.16.3.0 0.0.0.255
remark Traffic to Cust A (over VPN)
deny ip host 172.16.101.1 host 192.168.0.1
deny ip host 172.16.101.2 host 192.168.0.1
remark Traffic to Cust B (over VPN)
deny ip host 172.16.101.1 host 192.168.0.2
deny ip host 172.16.101.2 host 192.168.0.2
remark Traffic to Cust C (over Radianz VPN)
deny ip host 172.16.101.1 host 192.168.0.3
deny ip host 172.16.101.2 host 192.168.0.3
remark Traffic to Cust D (over Radianz VPN)
deny ip host 172.16.101.1 host 192.168.0.4
deny ip host 172.16.101.2 host 192.168.0.4
permit ip any any
ip access-list extended NAT_RADIANZ_PIXACCESS_ACL
remark Manangement Traffic to Cust C
permit icmp host 172.16.101.1 host xxx.xxx.xxx.xxx
permit icmp host 172.16.101.2 host xxx.xxx.xxx.xxx
permit tcp host 172.16.101.1 host xxx.xxx.xxx.xxx eq 22
permit tcp host 172.16.101.2 host xxx.xxx.xxx.xxx eq 22
remark Manangement Traffic to Cust D
permit icmp host 172.16.101.1 host xxx.xxx.xxx.xxx
permit icmp host 172.16.101.2 host xxx.xxx.xxx.xxx
permit tcp host 172.16.101.1 host xxx.xxx.xxx.xxx eq 22
permit tcp host 172.16.101.2 host xxx.xxx.xxx.xxx eq 22
route-map NAT_RADIANZ_PIXACCESS_RMAP permit 10
match ip address NAT_RADIANZ_PIXACCESS_ACL
set ip next-hop 10.10.11.14
route-map NAT_INTERNET_ACCESS_RMAP permit 40
match ip address NAT_INTERNET_ACCESS_ACL
set ip next-hop xxx.xxx.xxx.xxx

Similar Messages

  • I bought a 5th Gen Touch. I use iTunes 12 on two computers. One computer allows me to drag and drop. The other does not.The one that allows it has problems. Any idea as to why I can drag and drop on one and not the other. Both are authorized.

    I bought a 5th Gen Touch. I use iTunes 12 on my two computers. I first connected the Touch to my desktop and it allows me to drag and drop mp3 files from my old Classic, which is backed up to a directory. Unfortunately, that computer has gone down before I got a chance to fill the Touch. I have the files on another computer but when I connect the Touch to it, it doesn't allow me to drag and drop the files. I have iCloud set on both systems and I have manual management check marked. I'm not understanding why it allows drag and drop on one PC and not the other when they are both set the same way. My question? What do I need to do to be able to drag and drop in iTunes 12? I didn't do anything special on the computer that allows it so I am at a loss.
    Thank you!

    Oh, also want to add that the PC I'm currently using is:
    Windows Vista Home Premium Service Pack 2
    My other PC was:
    Windows 7 Ultimate
    My MacBook is:
    Max OSX 10.5.something (the last update available for it. .8 maybe? haha)
    Not sure if this stuff is important, but I thought I'd add it.

  • Why can one mac access the internet and not the other?

    Hi I have just installed a 2nd generation Airport Express base station. I have setup a network and I can connect to it to access the web. Here's the rub, only my Macbook Pro can connect. My Macbook Air cannot connect? A weird error message says (translated from Swedish): Airport has the selfapplied/selfselected IP adress 169.254.67.130 and will not be able to connect to the internet.
    Why can one mac access the internet and not the other? Is there something simple that I can do to get more macs to be able to use my Airport Express to access the internet?
    Tech details:
    Airport Express 2nd generation (just purchased) model 1392
    Macbook Pro running 10.8.2
    MacBook Air running 10.6.8

    It seems the Airbook assigns a dummy IP address so somehow it doesn't reach and receive an IP from the Express. I deleted the previous Express setting restarted the Air connected again, restarted the modem, restarted the Express nothing....
    I spoke to the internet provider and the cable modem does not require any username or pw. from the modem to the cable it's one public ip, pure internet is flowing from the modem to the Express but the express doesn't seem to assign any IP address apart from the one assigned to the Macbook Pro.
    Do you need a screendump of the settings on the functioning Mac or the faulty one? What settings are you interested in i.e. which tab should it shot?

  • When printing from aperture my margins are unequal, even if i set my margins they come out bigger one side  and not the other. i am using a macbook pro running osx lion and printing with a canon pro 9000

    when printing from aperture my margins are unequal, even if i set my margins they come out bigger one side  and not the other. i am using a macbook pro running osx lion and printing with a canon pro 9000.
    please can anbody help or advise?

    You didn't mention any color calibration being done on your monitor.  This is an essential part of any color-correct workflow.  What are you using to calibrate your monitor (and your printer)?
    Print profiles (for soft-proofing as well as printing) are for specific combinations of paper & printer.  The nine you have are each, most likely, for a common paper (perhaps mfr'd by Canon) to be used with your printer.
    I don't know what you mean when you say "I choose a high standard print option".
    Have you read the User Manual chapter on printing?
    Printing Your Images
    There is also a good appendix on calibration:
    Calibrating Your Aperture System

  • Request for advice: TM/TC fails on one Macbook Pro, but not the other?

    Dear All- looking for some advice.
    Background: I installed a 1TB TC about 3 months ago to improve the wireless connectivity around the home/small business and to act as 1 stop backup- primarily for 2 main Macbook Pro’s. Everything seems to work fine, with the exception that the time machine will only successfully back up one Macbook Pro (my wife's) and not the other (mine). In fact I have NEVER been able to get a full successful backup for my machine since I bought my TC.
    Scenario: My wireless router from my TC services 2 Macbook Pro’s, 1 iMac, iPhone, Sony PSP, Sony PS3 etc. All successfully and at a good speed. The TC also runs time machine for backups on the 2 Macbook Pros. One MBPro (my wife’s), has worked like a charm and flawless (pre Oct 2008 model 4.1, 2.5Ghz Intel core 2 Duo, 4GB (667MHz)DDR2 SDRAM, OSX 10.5.8, 250GB HD, 512MB video). TM Backup over wireless to my TC works great. While the other (mine) I have NEVER been able to get a successful backup once (MBPro post Nov 2008 model 5.1, 2.8GHz Intel Core 2 Duo, 4GB (1067MHz) DDR3 RAM, OSX 10.5.8, 300GB HD, 768MB Video).
    Problem: I have tried a number different combinations of backup without success. I have diligently read numerous posts before coming here. My attempts include, preferences resets, full disk erases (re-named the disk several times), wireless connectivity, hardwired connectivity (i.e no other devices connected), some software running/ no software running, in sleep mode/without sleep mode, all at once backup or intermittent backups.
    All provide me with the same message that it is not able to complete a full backup due to a writing error ‘Backup Failed’. At this stage I would not be convinced that the TC is actually working properly, with the exception that it works flawlessly with my wife’s Macbook Pro (yes every time I erase the drive) and that the wireless connectivity is great. My account preferences and setup/access for the TC/TM are identical to the machine that works. The volume I am trying to backup on my machine is ~258GB, while my wife’s machine that works is only around 78GB. I thought this may still be the source of the failure, but cannot see a work around or why.
    Considering I bought the TC to allow a solid reliable backup, I am still unhappy and would like to continue to work for a resolve. Does anyone have any suggestions?
    Thanks in advance.
    SDP

    Welcome to the discussions, xSDP!
    Apologies if you have already tried this, but I couldn't find it in your detailed list of prior actions.
    Note the exact name of your hard drive on your computer. If you haven't changed this, it will be named Macintosh HD
    Open Hard Drive > Applications > Utilities > Disk Utility
    Click on the icon on the left side of the window that has the exact same name as your hard drive on the desktop
    Click Repair Disk Permissions
    It will probably take several hours to do this, so allow plenty of time.
    Once the process is complete, see if you can backup now.

  • How can I get ALL of my Google Calendars to show on the iCal on my iPhone? I see all of my Google Calendars on the iCal on my Mac, but I do not see them in the iCal on my iPhone. I only see one Google Cal, but not the others.

    How can I get ALL of my Google Calendars to show on the iCal on my iPhone?
    I see all of my Google Calendars on the iCal on my Mac, but I do not see them in the iCal on my iPhone. I only see one Google Cal, but not the others.

    https://www.google.com/calendar/iphoneselect

  • I have CS6 and CC installed on my mac when I'm using CS6 and use bridge CC activates how can I set this to only work on one and not the other

    I have CS6 and CC installed on my mac when I'm using CS6 and use bridge CC activates how can I set this to only work on one and not the other

    If you want Bridge CS6 to open when using Photoshop CS6, you must quit Bridge CC.
    Then File menu > Browse in Bridge will bring up Bridge CS6.
    If Bridge CC is already open, The File > Browse in Bridge for Photoshop CS6 will use Bridge CC and Bridge CS6 will not open.
    I hope that's the answer you were looking for.
    Gene

  • When receiving a Group iMessage, i am only seeing one person's message, not the other.

    When receiving a Group iMessage, i am only seeing one person's message, not the other.

    Hi RumplestilskinToo!
    You may need to check and make sure that your Group Messaging setting is turned on:
    Messages settings - iPhone
    http://help.apple.com/iphone/7/#/iphf2d853e3
    Go to Settings > Messages to set options for Messages, including:
    Turning iMessage on or off
    Notifying others when you’ve read their messages
    Specifying an Apple ID or email address to use with Messages
    SMS and MMS options
    Turning group messaging on or off
    Showing the Subject field
    Showing the character count
    Blocking unwanted messages
    Thanks for using the Apple Support Communities. Have a good one!
    -Braden

  • My imessage texts are being sent from my email address and not my phone number.

    How do I change so imessages are sent from my phone number again and not my email?

    To identify your iMessages as coming from your phone number go to Settings>Messages>Receive At>Caller ID and select your phone number rather than your email address.  Also, the email can't be removed because this is the email address linked to the Apple ID you are using for iMessage.  If you really want to remove it you have to go to Settings>Messages>Receive At, tap the Apple ID at the top and sign out.

  • Why do I lose the sound effects for mail on my MBA and not the other Macs I have? Running ML.

    Why do I lose the sound effects in Mail for sending and receiving on my MBA and not on my other Macs? Running Mountain Lion. The problerm seems to be related to the sleep mode. When the MBA sleeps and then wakes up the sounds are missing. If I shut down and restart the machine the sounds will be back but only last until the maching goes through a sleep cycle.

    Primarily because, as ron245 points out, there is only ONE speaker on the bottom.

  • HT2731 I have 2 apple iPods on the same account, And they have the Same songs on them. How can I get a new account for one of them but not the other? Can I wipe the memory of 1? How would I do that?

    I have 2 iPods one I don't use anymore. I would like to make a new account for one but not the other. Is that possible? If I wipe the memory in one will the other wipe out too? How can I do all of this?

    You don't have to do anything with the first iPod that you don't use anymore. If you are planning on keeping it, put in a drawer in your house and forget about it.
    You don't need a second account to use with the new iPod. I use one Appl e ID and iTunes library for two iPods, and two iPad. I have different content on all four devices. You can select exactly what you want to sync to each device and it can be different content on all devices.

  • HT4539 Why I can download from iCloud on 1 iPod but not the other. It says downloaded but doesn't show up in music...

    I can download from iCloud to one iPod but not the other.  It says downloaded but doesn't show up in music...

    I'm not sure what you mean by the "music library" - are you looking in the Music app?  Or the iTunes app (which is not the one to be looking in)?

  • Audio audible in one Encore timline, but not the other?

    Hello,
    I'm trying to troubleshoot an issue in an Encore timeline for Blu-ray with an MPEG-2 and AC3 file.  It's odd because with the exact same file specs for both video and audio, I'm able to hear the audio from test project timeline (shorter in duration), but not the full length project timeline (roughly an hour and half in duration).
    I'm in the process of burning a disk to verfiy that the audio is simply not there, rather than a playback issue with the longer project, but can anyone suggest what might be failing here?  Again, the two projects appear to be identical in settings and file specs for video and audio, only the duration of one (working) is shorter than the other (not working).
    The audio file has been validated outside of Encore as playing back audio.
    Thanks for anything thoughts anyone might have here.  Btw, the project has no menu screens.  It is for a "play only" Blu-ray disk.
    Mtbakerstu

    Stan, thanks for the questions / feedback.
    As it turns out the file specs were not identical !  No fault of Adobe- an ingest / encode application from another company mysteriously swapped out channels 1/2 of audio to 5/6, and were not readable in Encore.   This information was not readiliy accessible within Encore, but was discovered in bringing the audio into Final Cut Pro (where it could be heard).
    Thanks again for your thoughts, as always.
    Mtbakerstu

  • Why does wireless work for one laptop and not the other?

    I have two laptops:
    1) MacBook: 10.4.8, Airport Exteme (Firmware 1.0.46)
    2) G4: 10.3.9, Airport Extreme (405.1 (3.90.0.p18)
    I have the two machines sitting right next to each other in my apartment. Machine #1 has full wireless signal strength. Machine #2 barely has any wireless signal. Neither is running Interference Robustness. Any ideas why one would work and the other would not, or suggestions as to how to debug this problem?
    I have tried stopping and restarting the Airport Extreme card on machine #2. I have also tried power cycling machine #2. This does not fix the problem.
    A little more history: for a long time I was having problems with machine #2 dropping the wireless connection. As part of trying to work around these problems I turned on Interference Robustness on machine #2. This fixed the dropping signal problem, but left me with weak signal strength. I shut off Interference Robustnes but ever since then the signal has still been weak on machine #2.
    Mac Mini Duo 1.66 GHz, 2 GB   Mac OS X (10.4.6)  

    The base station uses a single channel which all clients must use to connect.
    Have you checked the antenna connection into the card? Many people are surprised about how far the wire is actually supposed to be pushed into the card. Compare the connection with the photos in KB 108039, Properly attaching the antenna on an AirPort Extreme Card.

  • My notes are being stored on my outlook account and not icloud

    Hello,
    one of the email accounts on my iphone is linked with a work msoutlook account. A problem is that the notes that i enter into my iphone end up on my outlook account and not my icloud account. Does anyone know how to remedy this?
    -L8

    Go to Settings>Notes>Default Account and set it to iCloud.  Then open the Notes app, tap Accounts at the top, tap your iCloud account on the Accounts list, then try creating a new note and confirm that it appears on icloud.com now.  If it does, leave things this way and your notes will sync properly with iCloud.

Maybe you are looking for

  • [Solved] Adding Printer Marks to a Pages document in Acrobat

    By "Printer Marks" I mean "bleeds" and "crop marks". A bleed is the area of the paper that will be trimmed off after the job is printed. Crop marks indicate the exact place where the paper is to be trimmed. Background: I normally do programming and w

  • How to recompile with zinc?

    Hello, i wanted to change the name of the xml file that it saved to so i asked on the forum. A person gave me the editted script below however they also told me that in order for this to work i must recompile it with zinc. I have never worked with zi

  • W701 esata port suffering from poor design/qua​lity from manufactur​e?

    After having my W701 for 5 weeks, with 2 replacment of MB due to different problems, last time bios and port problems, I got i back from Lenovo today. I had reported it with a no functional/very poor functional esata port. What happens is that: With

  • Etrecheck vs Activity Monitor

    Hi, I've noticed (and not for the first time, BTW) that the results of Etrecheck don't match those of Activity Monitor on my Mac (the pics below). For example, Etrecheck displays CPU use percentage as followings: for WindowServer 3% while Activity Mo

  • Best way to outer join a table that is doing a sub query

    RDBMS : 11.1.0.7.0 Hello, What is the best way to outer join a table that is doing a sub query? This is a common scenario in EBS for the date tracked tables. SELECT papf.full_name, fu.description   FROM fnd_user fu       ,per_all_people_f papf WHERE