RM nie dziala bo i w specyfikacji IP NAT ENABLE w opisie nie ma takiej opcji przy PAT'owaniu tylko portow.
To dziala tylko dla NAT a nie dla PAT
Ale chyba rozwiazalem problem -
Dodalem do interfejsow LAN, DMZ, WifiGuest "ip nat enable" oraz zmienilem dla WifiGuest ip nat inside na outside i teraz kazdy interfejs ma:
Kod: Zaznacz cały
interface GigabitEthernet0/0
description Internet
bandwidth 150000
ip address xx.xx.xx.INETGW 255.255.255.252
ip access-group ATM_in in
ip nat outside
ip nat enable
ip virtual-reassembly in
duplex auto
speed auto
no snmp trap link-status
crypto map SDM_CMAP_1
interface GigabitEthernet0/1.22
description DMZ
encapsulation dot1Q 22
ip address xx.xx.xx.DMZGW maska
ip access-group DMZ_in in
ip nat outside
ip nat enable
ip virtual-reassembly in
ip policy route-map DMZ-ATM
interface GigabitEthernet0/1.11
description WifiGuest network
encapsulation dot1Q 11
ip address xx.xx.xxGuestGW 255.255.255.0
ip access-group Guest_in in
ip nat outside
ip nat enable
ip virtual-reassembly in
interface GigabitEthernet0/1.1
description LAN
encapsulation dot1Q 1 native
ip address xx.xx.xx.LAN
ip nat inside
ip nat enable
ip virtual-reassembly in
Zmodyfikowalem tez natowanie
Ruch do internetu i do DMZ z LAN obsluguje przez NVI:
Kod: Zaznacz cały
ip nat source route-map RM_LANtoDMZ interface GigabitEthernet0/1.22 overload
ip nat source route-map SDM_RMAP_1 interface GigabitEthernet0/0 overload
ip nat source route-map SDM_RMAP_2 interface GigabitEthernet0/2 overload
Natomiast PAT obsluguja mi stare reguly bo interfejs WifiGuest jest outside:
Kod: Zaznacz cały
ip nat inside source static tcp xx.xx.xx.LANSRVR 443 xx.xx.xx.DMZSRVR 443 route-map ATM-in-border extendable no-alias
Ruch z WifiGuest do internetu obsluguja NATy NVI
Co wy na takie rozwiazanie?