Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Network Address Translation on a cisco router
From: Irwin Lazar <lazar @ netevolve . com>
Date: Fri, 14 Feb 1997 14:25:40 -0500
To: Jim Jones <jrjones @ comsource . net>, firewalls @ greatcircle . com
In-reply-to: <Pine . OSF . 3 . 95 . 970214092245 . 4799A-100000 @ alpha . comsource . ne t>

At 09:28 AM 2/14/97 -0600, Jim Jones wrote:
>
>Hello,
>
>Has anyone used the network address translation feature on a cisco router?
>I was wondering how well it works and has anyone used this feature from a
>cisco?  Any info would be appreciated.  It is suppose to be part of the
>cisco 11.2.3 relase and it comes with the IP plus software.
>
>jim jones
>jrjones @
 comsource .
 net
>
Jim,
We have used it and it works pretty well, except if you do your translation
from one ethernet port to another ethernet port, you will have to configure
a ton of static ARP entries.

The problem is this.  Say e0 is your private network, e1 is your public
network.  

Your network looks like this:

Internet --- Internet Router  ----DMZ----NAT Router---Private Network.

You configure say 123.45.67.50 to 123.47.67.100 as your pool of public
addresses.  When devices in your DMZ that are on the 123.45.67 network try
to ARP to send a message to anything in .50 to .100, the NAT Router will
not respond.  It should, but it won't.  This is a bug that Cisco is working
on.

The workaround is that you need a static ARP table on all devices in your DMZ.

Irwin.
 
<><><><><><><><><><>
Irwin Lazar
Network Consultant
Network Evolutions, Inc.
http://www.netevolve.com
lazar @
 netevolve .
 com
<><><><><><><><><><>

Indexed By Date Previous: Re: Disturbing e-mail
From: Pavel Galynin <pgalynin @ chipnet . cz>
Next: cancel
From: Julie Squire <jsquire @ ljcrf . edu>
Indexed By Thread Previous: Network Address Translation on a cisco router
From: Jim Jones <jrjones @ comsource . net>
Next: Re: What firewall do I need
From: harley @ icrf . icnet . uk

Google
 
Search Internet Search www.greatcircle.com