Posted on May 10, 2017 10:42 pm
 |  Asked by amy amy
 |  1029 views
0
0
Print Friendly, PDF & Email

Hi, I am having a bit of an issue in getting this to work and if anyone could help it would be greatly appreciated.

I am trying to do a 1:1 Source and Destination NAT for a route advertised over BGP.

The SNAT rule is working but the DNAT is not.

Traffic hits the external interface but never exits the internal interface.

 

Thanks for taking a look!

 

Here is the relevant sanitized config:

! device: SSP2 (DCS-7150S-52-CL, EOS-4.17.0F)
!
! boot system flash:/EOS-4.17.0F.swi
!
vlan 105
   name Peer
!
vlan 505
   name Peer_TR
!
vrf definition Peer_vrf
   rd 65505:505
!
interface Ethernet14
   description Peer_TR
   switchport access vlan 505
!
interface Ethernet27
   switchport trunk allowed vlan 19,101-132
   switchport mode trunk
!
interface Vlan105
   vrf forwarding Peer_vrf
   ip address 10.xxx.xxx.252/24
!
interface Vlan505
   vrf forwarding Peer_vrf
   ip address 10.XXX.XXX.82/30
   ip nat source static 10.xxx.xxx.234 83.xxx.xxx.203
   ip nat destination static 83.xxx.xxx.203 10.xxx.xxx.234
!
ip virtual-router mac-address 00:1c:73:1f:84:c5
!
ip route vrf Peer_vrf 83.xxx.xxx.200/29 Null0
!
ip routing
ip routing vrf Peer_vrf
!
router bgp 65000
   vrf a1_vrf
      local-as 65505
      timers bgp 30 90
      neighbor 172.XXX.XXX.81 remote-as 12345
      neighbor 172.XXX.XXX.81 maximum-routes 12000
      network 83.xxx.xxx.200/29
Marked as spam
0
Posted by Sachin M Menon
Answered on May 11, 2017 6:58 am

Hi Amy,

Currently, we do not support NAT in a non-default VRF.

Could we configure VLAN 505 under default VRF and check if NAT is working as expected?

 

Thanks,

Sachin

Post your Answer

You must be logged in to post an answer.