Networking-Blog

My WordPress Blog

Cisco IP NaTing Source Outside

ip nat outside source static 172.16.10.20 10.11.254.212
ip nat outside source static 172.16.10.24 10.11.254.213
ip nat outside source static 172.16.10.25 10.11.254.216
ip nat outside source static 172.16.10.75 10.11.254.214
ip nat outside source static 172.16.10.76 10.11.254.215
!
!
ip route 0.0.0.0 0.0.0.0 1.1.1.1 (Wan Interface)
ip route 10.11.0.0 255.255.0.0 10.11.254.254 (Local LAN Gateway)
ip route 10.11.254.212 255.255.255.255 1.1.1.1
ip route 10.11.254.213 255.255.255.255 1.1.1.1
ip route 10.11.254.214 255.255.255.255 1.1.1.1
ip route 10.11.254.215 255.255.255.255 1.1.1.1
ip route 10.11.254.216 255.255.255.255 1.1.1.1

Route-Map NaTing

ip nat inside source route-map nonat interface GigabitEthernet0/1 overload
!
route-map nonat permit 12
match ip address NONAT
!
!
ip access-list extended NONAT
deny   ip 10.10.10.0 0.0.0.255 10.10.11.0 0.0.0.255 (deny NaTing across the link via ipsec vpn)
permit ip 10.10.10.0 0.0.0.255 any