<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Tech-Recipes - Latest Comments in Cisco: How to configure NAT [Network Address Translation] | Cisco router | Tech-Recipes</title><link>http://tech-recipes.disqus.com/</link><description>Cookbook of Tech Tutorials</description><language>en</language><lastBuildDate>Fri, 13 Mar 2009 15:09:41 -0000</lastBuildDate><item><title>Re: Cisco: How to configure NAT [Network Address Translation] | Cisco router | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/713/cisco_how_to_configure_nat_network_address_translation/#comment-7175803</link><description>Hello fellow, have problems with my vpn + Nat. I can connect to my other side of vpn (site to to site) but my local host cannot get to internet. Anybody can help? see below for my configurations. I ommited some portions of my live IPs for obvious reason please hlp out&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----------------------------------------------------------------------&lt;br&gt;Cisco Router and Security Device Manager (SDM) is installed on this device.&lt;br&gt;This feature requires the one-time use of the username "cisco"&lt;br&gt;with the password "cisco". The default username and password have a privilege le&lt;br&gt;vel of 15.&lt;br&gt;&lt;br&gt;Please change these publicly known initial credentials using SDM or the IOS CLI.&lt;br&gt;&lt;br&gt;Here are the Cisco IOS commands.&lt;br&gt;&lt;br&gt;username &amp;lt;myuser&amp;gt;  privilege 15 secret 0 &amp;lt;mypassword&amp;gt;&lt;br&gt;no username cisco&lt;br&gt;&lt;br&gt;Replace &amp;lt;myuser&amp;gt; and &amp;lt;mypassword&amp;gt; with the username and password you want to use&lt;br&gt;.&lt;br&gt;&lt;br&gt;For more information about SDM please follow the instructions in the QUICK START&lt;br&gt;&lt;br&gt;GUIDE for your router or go to &lt;a href="http://www.cisco.com/go/sdm" rel="nofollow"&gt;http://www.cisco.com/go/sdm&lt;/a&gt;&lt;br&gt;-----------------------------------------------------------------------&lt;br&gt;&lt;br&gt;&lt;br&gt;User Access Verification&lt;br&gt;&lt;br&gt;Username: Tutu&lt;br&gt;Password:&lt;br&gt;IKOYI#sh run&lt;br&gt;Building configuration...&lt;br&gt;&lt;br&gt;Current configuration : 4717 bytes&lt;br&gt;!&lt;br&gt;version 12.4&lt;br&gt;service timestamps debug datetime msec&lt;br&gt;service timestamps log datetime msec&lt;br&gt;no service password-encryption&lt;br&gt;!&lt;br&gt;hostname IKO&lt;br&gt;!&lt;br&gt;boot-start-marker&lt;br&gt;boot-end-marker&lt;br&gt;!&lt;br&gt;logging buffered 51200 warnings&lt;br&gt;enable secret 5 $1$I0iE$8pVL1AcDSoFbiIRp.sgv8/&lt;br&gt;!&lt;br&gt;no aaa new-model&lt;br&gt;!&lt;br&gt;resource policy&lt;br&gt;!&lt;br&gt;ip subnet-zero&lt;br&gt;!&lt;br&gt;!&lt;br&gt;ip cef&lt;br&gt;!&lt;br&gt;!&lt;br&gt;ip domain name &lt;a href="http://yourdomain.com" rel="nofollow"&gt;yourdomain.com&lt;/a&gt;&lt;br&gt;ip name-server 196.207.15.42&lt;br&gt;!&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto pki trustpoint TP-self-signed-145630655&lt;br&gt; enrollment selfsigned&lt;br&gt; subject-name cn=IOS-Self-Signed-Certificate-145630655&lt;br&gt; revocation-check none&lt;br&gt; rsakeypair TP-self-signed-145630655&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto pki certificate chain TP-self-signed-145630655&lt;br&gt; certificate self-signed 01&lt;br&gt;  3082024A 308201B3 A0030201 02020101 300D0609 2A864886 F70D0101 04050030&lt;br&gt;  30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274&lt;br&gt;  69666963 6174652D 31343536 33303635 35301E17 0D303930 33303630 32333233&lt;br&gt;  345A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F&lt;br&gt;  532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3134 35363330&lt;br&gt;  36353530 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100&lt;br&gt;  EE0D2291 66CCB6E7 54CBA7CE 9F40BEE8 29735E6F FFC917BC 7F981F6A 54DECBED&lt;br&gt;  60EB601B 6277B41A 5DF2E424 71FC057D 408BF779 212FC646 D39746C8 D2D57A28&lt;br&gt;  9658AED8 C0351113 A54DA1BF FF2D3A8F D478B751 E298E0E2 5C879BB9 015AED71&lt;br&gt;  AAEB99EA B98777AF 002CD08B ACD91B5B CB0327A5 05847A8B 18EDB7E0 3722AB9D&lt;br&gt;  02030100 01A37430 72300F06 03551D13 0101FF04 05300301 01FF301F 0603551D&lt;br&gt;  11041830 16821449 4B4F5949 2E796F75 72646F6D 61696E2E 636F6D30 1F060355&lt;br&gt;  1D230418 30168014 8A9EFB00 CF24755D 76965DF2 A5AEC3ED 8C72D41C 301D0603&lt;br&gt;  551D0E04 1604148A 9EFB00CF 24755D76 965DF2A5 AEC3ED8C 72D41C30 0D06092A&lt;br&gt;  864886F7 0D010104 05000381 81009EA2 829BBA41 C9CDE377 CDE88735 621BE1F4&lt;br&gt;  DAD6CE7E 58C38786 638B5D2F 6A23A0FB 5C37538D 337EE2C0 9BCD65F1 6D9D24BA&lt;br&gt;  29A73A47 A13D08F2 097F3FB7 46708287 523C1ACE 5C4855B6 612FE99C A6DC6567&lt;br&gt;  6D3ABD6B EE73ED5D C9F1530E 3F55865E 6A7A8578 87EF7DD5 E387FB66 D75BCFD4&lt;br&gt;  EEBD7327 A6F437EE 82A0FFCA 41B8&lt;br&gt;  quit&lt;br&gt;username administrator privilege 15 secret 5 $1$nEox$0hYI/8hL2wG4BbmWtM55t.&lt;br&gt;username femi privilege 15 password 0 ok femi&lt;br&gt;username rama privilege 15 secret 5 $1$N42C$8miusbsth9k.SzizkaE520&lt;br&gt;!&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto isakmp policy 7&lt;br&gt; encr aes&lt;br&gt; hash md5&lt;br&gt; authentication pre-share&lt;br&gt;!&lt;br&gt;crypto isakmp policy 70&lt;br&gt; hash md5&lt;br&gt; authentication pre-share&lt;br&gt; group 2&lt;br&gt;crypto isakmp key kamasutral address 41.219.xx.xx no-xauth&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto ipsec transform-set BUKKY esp-aes esp-sha-hmac&lt;br&gt;!&lt;br&gt;crypto map VPN-MAP 10 ipsec-isakmp&lt;br&gt; set peer 41.219.xx.xx&lt;br&gt; set transform-set BUKKY&lt;br&gt; match address INT-TRAFFIC&lt;br&gt;!&lt;br&gt;!&lt;br&gt;!&lt;br&gt;interface FastEthernet0/0&lt;br&gt; description LAN$ES_LAN$$ETH-LAN$&lt;br&gt; ip address 192.168.0.1 255.255.255.0&lt;br&gt; ip nat inside&lt;br&gt; ip virtual-reassembly&lt;br&gt; duplex auto&lt;br&gt; speed auto&lt;br&gt;!&lt;br&gt;interface FastEthernet0/1&lt;br&gt; description WAN $ETH-WAN$&lt;br&gt; ip address 41.219.xx.xx 255.255.255.248&lt;br&gt; ip access-group 100 out&lt;br&gt; ip nat outside&lt;br&gt; ip virtual-reassembly&lt;br&gt; duplex auto&lt;br&gt; speed auto&lt;br&gt; crypto map VPN-MAP&lt;br&gt;!&lt;br&gt;ip classless&lt;br&gt;ip route 0.0.0.0 0.0.0.0 41.219.xx.xx&lt;br&gt;!&lt;br&gt;ip http server&lt;br&gt;ip http access-class 23&lt;br&gt;ip http authentication local&lt;br&gt;ip http secure-server&lt;br&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;br&gt;ip nat pool BUK 41.219.xx.xx 41.219.xx.xx netmask 255.255.255.248&lt;br&gt;ip nat inside source list 100 interface FastEthernet0/1 overload&lt;br&gt;!&lt;br&gt;ip access-list extended INT-TRAFFIC&lt;br&gt; permit ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;br&gt;!&lt;br&gt;access-list 100 deny   ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;br&gt;access-list 100 permit ip 192.168.0.0 0.0.0.255 any&lt;br&gt;!&lt;br&gt;!&lt;br&gt;control-plane&lt;br&gt;!&lt;br&gt;!&lt;br&gt;banner login ^C&lt;br&gt;-----------------------------------------------------------------------&lt;br&gt;Cisco Router and Security Device Manager (SDM) is installed on this device.&lt;br&gt;This feature requires the one-time use of the username "cisco"&lt;br&gt;with the password "cisco". The default username and password have a privilege le&lt;br&gt;vel of 15.&lt;br&gt;&lt;br&gt;Please change these publicly known initial credentials using SDM or the IOS CLI.&lt;br&gt;&lt;br&gt;Here are the Cisco IOS commands.&lt;br&gt;&lt;br&gt;username &amp;lt;myuser&amp;gt;  privilege 15 secret 0 &amp;lt;mypassword&amp;gt;&lt;br&gt;no username cisco&lt;br&gt;&lt;br&gt;Replace &amp;lt;myuser&amp;gt; and &amp;lt;mypassword&amp;gt; with the username and password you want to use&lt;br&gt;.&lt;br&gt;&lt;br&gt;For more information about SDM please follow the instructions in the QUICK START&lt;br&gt;&lt;br&gt;GUIDE for your router or go to &lt;a href="http://www.cisco.com/go/sdm" rel="nofollow"&gt;http://www.cisco.com/go/sdm&lt;/a&gt;&lt;br&gt;-----------------------------------------------------------------------&lt;br&gt;^C&lt;br&gt;!&lt;br&gt;line con 0&lt;br&gt; password Tutu&lt;br&gt; login&lt;br&gt;line aux 0&lt;br&gt;line vty 0 4&lt;br&gt; access-class 23 in&lt;br&gt; privilege level 15&lt;br&gt; password Tutu&lt;br&gt; login local&lt;br&gt; transport input telnet ssh&lt;br&gt;line vty 5 15&lt;br&gt; access-class 23 in&lt;br&gt; privilege level 15&lt;br&gt; login local&lt;br&gt; transport input telnet ssh&lt;br&gt;!&lt;br&gt;scheduler allocate 20000 1000&lt;br&gt;!&lt;br&gt;end&lt;br&gt;&lt;br&gt;IKO#</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">femyadesina</dc:creator><pubDate>Fri, 13 Mar 2009 15:09:41 -0000</pubDate></item><item><title>Re: Cisco: How to configure NAT [Network Address Translation] | Cisco router | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/713/cisco_how_to_configure_nat_network_address_translation/#comment-5501167</link><description>1) config NAT on  router like this &lt;a href="http://wisedec.com/configuring-nat-on-cisco-routers.html" rel="nofollow"&gt;http://wisedec.com/configuring-nat-on-cisco-rou...&lt;/a&gt;&lt;br&gt;2) sign up for one free domain name &lt;a href="http://www.dyndns.com/" rel="nofollow"&gt;http://www.dyndns.com/&lt;/a&gt; &lt;br&gt;3) Add to your config this commands&lt;br&gt;no ip nat inside source list 1 interface fastethernet 1 overload&lt;br&gt;ip nat inside source static 10.10.10.10 interface fastethernet 0&lt;br&gt;&lt;br&gt;where 10.10.10.10 is address your cpu</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Wisedec</dc:creator><pubDate>Fri, 23 Jan 2009 16:19:34 -0000</pubDate></item><item><title>Re: Cisco: How to configure NAT [Network Address Translation] | Cisco router | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/713/cisco_how_to_configure_nat_network_address_translation/#comment-3007027</link><description>sorry i meant &lt;a href="http://www.dyndns.com/" rel="nofollow"&gt;http://www.dyndns.com/&lt;/a&gt; if you go to the link i added earlier it will take you somewhere different</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Yuraitis</dc:creator><pubDate>Sun, 12 Oct 2008 09:06:20 -0000</pubDate></item><item><title>Re: Cisco: How to configure NAT [Network Address Translation] | Cisco router | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/713/cisco_how_to_configure_nat_network_address_translation/#comment-3007012</link><description>if you go to &lt;a href="http://dyn-dns.com" rel="nofollow"&gt;dyn-dns.com&lt;/a&gt; you can sign up for one free domain name e.g. &lt;a href="http://yourdomain.homeip.net" rel="nofollow"&gt;yourdomain.homeip.net&lt;/a&gt; or &lt;a href="http://yourdomain.homelinux.com" rel="nofollow"&gt;yourdomain.homelinux.com&lt;/a&gt;. This domain name will be mapped out to your ip address each time it changes through either a software client on your server or through your router (mine is a Speedstream router and it had an option in the gui for dyn-dns where you simply enter your dyn-dns username and password)&lt;br&gt; each time your ip address changes the dns entry for it will be updated by the client and you will be able to access the ever changing ip adress from the outside by using the domain name.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Yuraitis</dc:creator><pubDate>Sun, 12 Oct 2008 09:04:05 -0000</pubDate></item><item><title>Re: Cisco: How to configure NAT [Network Address Translation] | Cisco router | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/713/cisco_how_to_configure_nat_network_address_translation/#comment-2811504</link><description>how i can configure the router if the isp tell me a ip that change evry moment that i restart my router, and i want to use the port 7717 with my cpu because i have a softwre client/server.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">wilson</dc:creator><pubDate>Thu, 02 Oct 2008 18:47:10 -0000</pubDate></item></channel></rss>