ACL, ip nat inside/outside and one public IP for the whole LAN
Level: IntermediateTime: 30 minDomain 4.0 IP Services
Scenario
The LAN uses private addresses (192.168.1.0/24) and the ISP doesn't know how to send traffic back to them: the PCs can't reach the Internet web server (198.51.100.10).
Configure PAT on R1 so the whole LAN goes out with the IP of its public interface (G0/1): a standard ACL 1 permitting the LAN, G0/0 as inside, G0/1 as outside and the translation with overload. Then ping from a PC and look at the translations with show ip nat translations.
Topology
Devices and cabling
R1, ISP·2911
SW1·2960-24TT
PC1, PC2·PC-PT
SRV1·Server-PT
From
To
Cable
R1Gi0/0
SW1Gi0/1
Straight-through
PC1Fa0
SW1Fa0/1
Straight-through
PC2Fa0
SW1Fa0/2
Straight-through
R1Gi0/1
ISPGi0/0
Crossover
ISPGi0/1
SRV1Fa0
Crossover
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
R1
G0/0 (inside)
192.168.1.1
255.255.255.0
—
R1
G0/1 (outside)
203.0.113.2
255.255.255.252
—
ISP
G0/0
203.0.113.1
255.255.255.252
—
ISP
G0/1
198.51.100.1
255.255.255.0
—
PC1
NIC
192.168.1.10
255.255.255.0
192.168.1.1
PC2
NIC
192.168.1.11
255.255.255.0
192.168.1.1
SRV1
NIC
198.51.100.10
255.255.255.0
198.51.100.1
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
R1hostname R1
no ip domain-lookup
interface g0/0
ip address 192.168.1.1 255.255.255.0
no shutdown
interface g0/1
ip address 203.0.113.2 255.255.255.252
no shutdown
ip route 0.0.0.0 0.0.0.0 203.0.113.1
ISPhostname ISP
no ip domain-lookup
interface g0/0
ip address 203.0.113.1 255.255.255.252
no shutdown
interface g0/1
ip address 198.51.100.1 255.255.255.0
no shutdown
SW1hostname SW1
no ip domain-lookup
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.1.10, mask 255.255.255.0, gateway 192.168.1.1
PC2: IP 192.168.1.11, mask 255.255.255.0, gateway 192.168.1.1
SRV1: IP 198.51.100.10, mask 255.255.255.0, gateway 198.51.100.1 (with the HTTP service on)
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
ACL 1 permitting 192.168.1.0/24
G0/0 as the inside interface
G0/1 as the outside interface
PAT using G0/1's IP
PC1 and PC2 reach server 198.51.100.10
Translations checked with show ip nat translations
In Packet Tracer
The ISP is another 2911 router and the server a Server-PT, which has the HTTP service on by default.
NAT only translates traffic that enters an inside interface and leaves through an outside one.
R1interface g0/0
ip nat inside
interface g0/1
ip nat outside
exit
3Enable PAT R1
overload lets the whole LAN share G0/1's IP, telling each connection apart by its port.
R1ip nat inside source list 1 interface g0/1 overload
end
Verification
Without NAT, the ISP has no route back to 192.168.1.0/24 and the ping fails. With NAT, it replies.
PC1C:\>ping 198.51.100.10
Pinging 198.51.100.10 with 32 bytes of data:
Reply from 198.51.100.10: bytes=32 time<1ms TTL=126
Reply from 198.51.100.10: bytes=32 time<1ms TTL=126
Reply from 198.51.100.10: bytes=32 time<1ms TTL=126
Reply from 198.51.100.10: bytes=32 time<1ms TTL=126
Ping statistics for 198.51.100.10:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Each echo shows up translated: inside, 192.168.1.10; outside, 203.0.113.2 with its own port.
R1R1#show ip nat translations
Pro Inside global Inside local Outside local Outside global
icmp 203.0.113.2:1 192.168.1.10:1 198.51.100.10:1 198.51.100.10:1
icmp 203.0.113.2:2 192.168.1.10:2 198.51.100.10:2 198.51.100.10:2
icmp 203.0.113.2:3 192.168.1.10:3 198.51.100.10:3 198.51.100.10:3
icmp 203.0.113.2:4 192.168.1.10:4 198.51.100.10:4 198.51.100.10:4
icmp 203.0.113.2:5 192.168.1.10:5 198.51.100.10:5 198.51.100.10:5
icmp 203.0.113.2:6 192.168.1.10:6 198.51.100.10:6 198.51.100.10:6
icmp 203.0.113.2:7 192.168.1.10:7 198.51.100.10:7 198.51.100.10:7
icmp 203.0.113.2:8 192.168.1.10:8 198.51.100.10:8 198.51.100.10:8
Common mistakes
Swapping inside and outside: nothing gets translated.
An ACL that doesn't match the LAN (for example, with the mask instead of the wildcard).
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.