Cisco – NAT Port Address Translation
Port Address Translation
NAT Translate Source tcp port 22 = ssh to Destination Service Port 22=ssh.
ip nat inside source static tcp 192.168.1.1 22 interface Dialer0 22
!
!
NAT Translate Source tcp port 10001 to Destination Service Port 22=ssh.
ip nat inside source static tcp 192.168.2.1 22 interface Dialer0 10001
!
!
NAT Translate Source tcp port 10001 to Destination Service Port 22=ssh.
ip nat inside source static tcp 192.168.2.1 22 interface Dialer0 10001
!
Note that the configuration description for the static NAT command indicates any
packet received in the inside interface with a source address of 192.168.2.1.22 is
translated to 0.0.0.0:10001.
This also implies that any packet received on the outside interface with a destination
address of 172.16.10.8:80 has the destination translated to
172.16.10.8:8080.
!
Allow tcp port 22 or 10001 on the firewall WAN facing ACL as incoming from the Internet.
Eg :
ip access-list extended INTERNET
permit ip any any eq 22
permit ip any any eq 10001
!
ip nat inside source static 172.16.50.8 172.16.10.8 !--- States that any packet received on the inside interface with a !--- source IP address of 172.16.50.8 is translated to 172.16.10.8.
Note that the inside source NAT command in this example also implies that
packets received on the outside interface with a destination address of
172.16.10.8 has the destination address translated to 172.16.50.8.
Difference between One-to-One Mapping and Many-to-Many
A static NAT configuration creates a one-to-one mapping and translates a
specific address to another address. This type of configuration creates a
permanent entry in the NAT table as long as the configuration is present and
enables both inside and outside hosts to initiate a connection.
This is mostly useful for hosts that provide application services like mail,
web, FTP and so forth. For example:
Router(config)#ip nat inside source static 10.3.2.11 10.41.10.12
Dynamic NAT is useful when fewer addresses are available than the actual
number of hosts to be translated. It creates an entry in the NAT table when
the host initiates a connection and establishes a one-to-one mapping between
the addresses.But, the mapping can vary and it depends upon the registered
address available in the pool at the time of the communication. Dynamic NAT
allows sessions to be initiated only from inside or outside networks for which
it is configured.
Dynamic NAT entries are removed from the translation table if the host does not
communicate for a specific period of time which is configurable. The address is
then returned to the pool for use by another host.
For example, complete these steps of the detailed configuration:
Create a pool of addresses
Router(config)#ip nat pool MYPOOLEXAMPLE
10.41.10.1 10.41.10.41 netmask 255.255.255.0
!
Create an access-list for the inside networks that has to be mapped
Router(config)#access-list 100 permit ip 10.3.2.0 0.0.0.255 any
Associate the access-list 100 that is selecting the internal network
10.3.2.0 0.0.0.255 to be natted to the pool MYPOOLEXAMPLE and then
overload the addresses.
Router(config)#ip nat inside source list 100 pool MYPOOLEXAMPLE overload