Ip Nat Guide Cisco
Ip Nat Guide Cisco
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
[Link]
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 527-0883
© 2018 Cisco Systems, Inc. All rights reserved.
CONTENTS
CHAPTER 8 Interchassis Asymmetric Routing Support for Zone-Based Firewall and NAT 127
Finding Feature Information 127
Restrictions for Interchassis Asymmetric Routing Support for Zone-Based Firewall and
NAT 128
Information About Interchassis Asymmetric Routing Support for Zone-Based Firewall and
NAT 128
Asymmetric Routing Overview 128
Asymmetric Routing Support in Firewalls 130
Asymmetric Routing in NAT 130
Asymmetric Routing in a WAN-LAN Topology 131
VRF-Aware Asymmetric Routing in Zone-Based Firewalls 131
VRF-Aware Asymmetric Routing in NAT 132
How to Configure Interchassis Asymmetric Routing Support for Zone-Based Firewall and
NAT 132
Configuring a Redundancy Application Group and a Redundancy Group Protocol 132
Configuring Data, Control, and Asymmetric Routing Interfaces 135
Configuring a Redundant Interface Identifier and Asymmetric Routing on an Interface 137
Configuring Dynamic Inside Source Translation with Asymmetric Routing 139
Configuration Examples for Interchassis Asymmetric Routing Support for Zone-Based Firewall
and NAT 142
Example: Configuring a Redundancy Application Group and a Redundancy Group
Protocol 142
Example: Configuring Data, Control, and Asymmetric Routing Interfaces 142
Example: Configuring a Redundant Interface Identifier and Asymmetric Routing on an
Interface 142
Example: Configuring Dynamic Inside Source Translation with Asymmetric Routing 142
Example: Configuring VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 143
Example: Configuring Asymmetric Routing with VRF 145
Additional References for Interchassis Asymmetric Routing Support for Zone-Based Firewall
and NAT 146
Feature Information for Interchassis Asymmetric Routing Support for Zone-Based Firewall and
NAT 147
CHAPTER 9 VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing Box-to-Box
Redundancy 149
Finding Feature Information 149
Restrictions for VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing Box-to-Box
Redundancy 150
Information About VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 150
VRF-Aware Box-to-Box High Availability Support 150
Stateful Interchassis Redundancy Overview 151
Stateful Interchassis Redundancy Operation in NAT 151
How to Configure VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 152
Configuration Examples for VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 153
Example: Configuring VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 153
Additional References for VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 155
Feature Information for VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing
Box-to-Box Redundancy 156
CHAPTER 21 Sun RPC ALG Support for Firewalls and NAT 307
Finding Feature Information 307
Restrictions for Sun RPC ALG Support for Firewalls and NAT 307
Information About Sun RPC ALG Support for Firewalls and NAT 308
CHAPTER 23 ALG—H.323 vTCP with High Availability Support for Firewall and NAT 331
Finding Feature Information 331
Restrictions for ALG—H.323 vTCP with High Availability Support for Firewall and NAT 332
Information About ALG—H.323 vTCP with High Availability Support for Firewall and NAT 332
Application-Level Gateways 332
Basic H.323 ALG Support 332
Overview of vTCP for ALG Support 333
vTCP with NAT and Firewall ALGs 334
Overview of ALG—H.323 vTCP with High Availability Support 334
How to Configure ALG—H.323 vTCP with High Availability Support for Firewall and NAT 334
Configuring ALG-H.323 vTCP with High Availability Support for NAT 334
Configuration Examples for ALG—H.323 vTCP with High Availability Support for Firewall and
NAT 337
Example: Configuring ALG-H.323 vTCP with High Availability Support for NAT 337
Additional References for ALG-H.323 vTCP with High Availability Support for Firewall and
NAT 337
Feature Information for ALG—H.323 vTCP with High Availability Support for Firewall and
NAT 338
Configuration Examples for SIP ALG Hardening for NAT and Firewall 348
Example: Enabling NAT for SIP Support 348
Example: Enabling SIP Inspection 348
Example: Configuring a Zone Pair and Attaching a SIP Policy Map 348
Additional References for SIP ALG Hardening for NAT and Firewall 349
Feature Information for SIP ALG Hardening for NAT and Firewall 350
Feature Information
Use Cisco Feature Navigator to find information about feature support, platform support, and Cisco software
image support. An account on [Link] is not required.
Related References
• Cisco IOS Command References, All Releases
Access Lists
All access lists that are required for use with the configuration tasks described in this module should be
configured before beginning a configuration task. For information about how to configure an access list, see
the IP Access List EntrySequence Numbering document.
Note If you specify an access list with a NAT command, NAT will not support the permit ip any any command
that is commonly used in an access list.
NAT Requirements
Before configuring NAT in your network, you should know the interfaces on which NAT will be configured
and for what purposes. The following requirements will help you decide how to configure and use NAT:
• Define the NAT inside and outside interfaces if:
• Users exist off multiple interfaces.
• Multiple interfaces connect to the Internet.
From Cisco IOS XE Denali 16.3 release, NAT support is introduced on Bridge Domain Interface (BDI) for
enabling NAT configuration on BDI interface.
latency of all packet flows through the NAT interface. We highly recommend that a NAT interface must
be used only for NAT-only traffic. Any non-NAT packets must be separated and these packets should
go through an interface that does not have NAT configured on it. You can use Policy-Based Routing
(PBR) for separating non-NAT traffic.
• NAT Virtual Interfaces (NVIs) are not supported in the Cisco IOS XE software.
• In Cisco IOS XE software, NAT outside interfaces show up in the translations tables, by default. This
causes the connection originated from the outside interface of the device to fail. To restore connectivity,
you must explicitly deny the outside Interface within the NAT ACL using the deny command. After
using the deny command no translation is observerd for the outside interface.
• NAT is not practical if large numbers of hosts in the stub domain communicate outside of the domain.
• Some applications use embedded IP addresses in such a way that translation by a NAT device is
impractical. These applications may not work transparently or at all through a NAT device.
• In a NAT configuration, addresses configured for any inside mapping should not be configured for any
outside mapping.
• Do not configure the interface IP address as part of the IP address NAT pool.
• By default, support for the Session Initiation Protocol (SIP) is enabled on port 5060. Therefore,
NAT-enabled devices interpret all packets on this port as SIP call messages. If other applications in the
system use port 5060 to send packets, the NAT service may corrupt the packet as it attempts to interpret
the packet as a SIP call message.
• NAT hides the identity of hosts, which may be an advantage or a disadvantage depending on the desired
result.
• A device configured with NAT must not advertise the local networks to outside the network. However,
routing information that NAT receives from the outside can be advertised in the stub domain as usual.
• NAT outside interface is not supported on a VRF. However, NAT outside interface is supported in
iWAN and is part of the Cisco Validated Design.
• For VRF-aware NAT, remove the NAT configuration before you remove the VRF configuration.
• If you specify an access list to use with a NAT command, NAT does not support the permit ip any any
command that is commonly used in the access list.
• An access list with a port range is not supported on the Cisco ASR 1000 Series Aggregation Services
Routers.
• NAT configuration is not supported on the access side of the Intelligent Services Gateway (ISG).
• Using any IP address configured of a device as an address pool or in a NAT static rule is not supported.
NAT can share the physical interface address (not any other IP address) of a device only by using the
NAT interface overload configuration. A device uses the ports of its physical interface and NAT must
receive communication about the ports that it can safely use for translation. This communication happens
only when the NAT interface overload is configured.
• The output of the show ip nat statistics command displays information about all IP address pools and
NAT mappings that you have configured. If your NAT configuration has a high number of IP address
pools and NAT mappings (for example 1000 to 4000), the update rate of the pool and mapping statistics
in the show ip nat statistics is very slow.
• Static and dynamic NAT with generic routing encapsulation (generic GRE) and dynamic NAT with
Layer 2 do not work when used along with hardware-based Cisco AppNav appliances (for example,
Wide Area Application Services [WAAS]). In the context of WAAS, generic GRE is an out-of-path
deployment mechanism that helps to return packets from the WAAS Wide-Area Application Engine
(WAE) through the GRE tunnel to the same device from which they were originally redirected, after
completing optimization.
• Port Address Translation (also called NAT overload) only supports protocols whose port numbers are
known; these protocols are Internet Control Message Protocol (ICMP), TCP, and UDP. Other protocols
do not work with PAT because they consume the entire address in an address pool. Configure your
access control list to only permit ICMP, TCP, and UDP protocols, so that all other protocol traffic is
prevented from entering the network.
• NAT, Zone-Based Policy Firewall, and Web Cache Communication Protocol (WCCP) cannot coexist
in a network.
• NON-Pattable traffic, is a traffic for a protocol where there are no ports. PAT/Overload can only be
done on protocols where the ports are known, that is, UDP, TCP, and ICMP.
When ASR is configured for NAT overload (PAT) and non-pattable traffic hits the router, non-pattable
BIND entry gets created for this traffic. This leads to the following kind of an entry in the NAT table:
--- [Link] [Link] ---
This bind entry consumes an entire address from the pool. In this example, [Link] is an address
from an overloaded pool.
That means an inside local IP Address gets bound to the outside global IP which is similar to static NAT.
Because of this until the current entry gets timed out, new inside local IP Addresses cannot use this
global IP Address. All the translation created off this BIND is 1-to-1 translations instead of overload.
To avoid this, make sure that there are not any entries for the NON Pattable traffic across the router.
In Cisco IOS XE Denali 16.3 release, Multi-Tenant support for NAT feature was introduced. With Multi-Tenant
support for NAT feature, the configuration changes of a Virtual Routing and Forwarding (VRF) instance does
not interrupt the traffic flow of other VRFs in the network.
NAT is a feature that allows the IP network of an organization to appear from the outside to a use different
IP address space than what it actually uses. Thus, NAT allows an organization with nonglobally routable
addresses to connect to the Internet by translating those addresses into a globally routable address space. NAT
also allows a graceful renumbering strategy for organizations that are changing service providers or voluntarily
renumbering into classless interdomain routing (CIDR) blocks. NAT is described in RFC 1631.
Uses of NAT
NAT can be used for the following scenarios:
• To connect to the Internet, but not all of your hosts have globally unique IP addresses. Network Address
Translation (NAT) enables private IP internetworks that use nonregistered IP addresses to connect to
the Internet. NAT is configured on a device at the border of a stub domain (referred to as the inside
network) and a public network such as the Internet (referred to as the outside network). NAT translates
internal local addresses to globally unique IP addresses before sending packets to the outside network.
As a solution to the connectivity problem, NAT is practical only when relatively few hosts in a stub
domain communicate outside of the domain at the same time. When this is the case, only a small subset
of the IP addresses in the domain must be translated into globally unique IP addresses when outside
communication is necessary, and these addresses can be reused when they are no longer in use.
• Change your internal addresses. Instead of changing the internal addresses, which can be a considerable
amount of work, you can translate them by using NAT.
• For basic load-sharing of TCP traffic. You can map a single global IP address to many local IP addresses
by using the TCP Load Distribution feature.
Types of NAT
NAT operates on a router—generally connecting only two networks—and translates the private (inside local)
addresses within the internal network into public (inside global) addresses before any packets are forwarded
to another network. This functionality gives you the option to configure NAT so that it will advertise only a
single address for your entire network to the outside world. Doing this effectively hides the internal network
from the world, giving you some additional security.
The types of NAT include:
• Static address translation (static NAT)—Allows one-to-one mapping between local and global addresses.
• Dynamic address translation (dynamic NAT)—Maps unregistered IP addresses to registered IP addresses
from a pool of registered IP addresses.
• Overloading—Maps multiple unregistered IP addresses to a single registered IP address (many to one)
using different ports. This method is also known as Port Address Translation (PAT). By using overloading,
thousands of users can be connected to the Internet by using only one real global IP address.
VRF X Global VRF (also referred to as When NAT is not configured for
non-VRF interface) Match-in-VRF support. For more
details, refer to the Match-in-VRF
support for NAT chapter.
In Cisco IOS Release 15.1(3)T and later releases, when you configure the traceroute command, NAT returns
the same inside global IP address for all inside local IP addresses.
The figure below illustrates a device that is translating a source address inside a network to a source address
outside the network.
The following process describes the inside source address translation, as shown in the figure above:
1 The user at host [Link] opens a connection to Host B in the outside network.
2 The first packet that the device receives from host [Link] causes the device to check its Network Address
Translation (NAT) table. Based on the NAT configuration, the following scenarios are possible:
• If a static translation entry is configured, the device goes to Step 3.
• If no translation entry exists, the device determines that the source address (SA) [Link] must be
translated dynamically, selects a legal, global address from the dynamic address pool, and creates a
translation entry in the NAT table. This type of translation entry is called a simple entry.
3 The device replaces the inside local source address of host [Link] with the global address of the translation
entry and forwards the packet.
4 Host B receives the packet and responds to host [Link] by using the inside global IP destination address
(DA) [Link].
5 When the device receives the packet with the inside global IP address, it performs a NAT table lookup by
using the inside global address as a key. It then translates the address to the inside local address of host
[Link] and forwards the packet to host [Link].
Host [Link] receives the packet and continues the conversation. The device performs Steps 2 to 5 for each
packet that it receives.
The device performs the following process in the overloading of inside global addresses, as shown in the
figure above. Both Host B and Host C believe that they are communicating with a single host at address
[Link]. Where as, they are actually communicating with different hosts; the port number is the
differentiator. In fact, many inside hosts can share the inside global IP address by using many port numbers.
1 The user at host [Link] opens a connection to Host B.
2 The first packet that the device receives from host [Link] causes the device to check its NAT table. Based
on your NAT configuration the following scenarios are possible:
• If no translation entry exists, the device determines that IP address [Link] must be translated, and
translates inside local address [Link] to a legal global address.
• If overloading is enabled and another translation is active, the device reuses the global address from
that translation and saves enough information that can be used to translate the global address back,
as an entry in the NAT table. This type of translation entry is called an extended entry.
3 The device replaces inside local source address [Link] with the selected global address and forwards the
packet.
4 Host B receives the packet and responds to host [Link] by using the inside global IP address [Link].
5 When the device receives the packet with the inside global IP address, it performs a NAT table lookup by
using a protocol, the inside global address and port, and the outside address and port as keys; translates
the address to the inside local address [Link] and forwards the packet to host [Link].
Host [Link] receives the packet and continues the conversation. The device performs Steps 2 to 5 for each
packet it receives.
The device examines every DNS reply to ensure that the IP address is not in a stub network. If it is, the device
translates the address as described below:
1 Host [Link] opens a connection to [Link].
2 The device sets up the translation mapping of the inside local and global addresses to each other and the
outside global and local addresses to each other.
3 The device replaces the SA with the inside global address and replaces the DA with the outside global
address.
4 Host C receives the packet and continues the conversation.
5 The device does a lookup, replaces the DA with the inside local address, and replaces the SA with the
outside local address.
6 Host [Link] receives the packet and the conversation continues using this translation process.
5 The device receives the packet and performs a NAT table lookup by using the inside local address and
port number, and the outside address and port number as keys. The device then translates the source address
to the address of the virtual host and forwards the packet.
6 The device will allocate IP address [Link] as the inside local address for the next connection request.
RADIUS
RADIUS is a distributed client/server system that secures networks against unauthorized access. Communication
between a network access server (NAS) and a RADIUS server is based on UDP. Generally, the RADIUS
protocol is considered a connectionless service. Issues related to server availability, retransmission, and
timeouts are handled by RADIUS-enabled devices rather than the transmission protocol.
The RADIUS client is typically a NAS, and the RADIUS server is usually a daemon process running on a
UNIX or Windows NT machine. The client passes user information to designated RADIUS servers and acts
on the response that is returned. RADIUS servers receive user connection requests, authenticate the user, and
then return the configuration information necessary for the client to deliver the service to the user. A RADIUS
server can act as a proxy client to other RADIUS servers or other kinds of authentication servers.
Denial-of-Service Attacks
A denial-of-service (DoS) attack typically involves the misuse of standard protocols or connection processes
with the intent to overload and disable a target, such as a device or web server. DoS attacks can come from a
malicious user or from a computer infected with a virus or worm. An attack that comes from many different
sources at once, such as when a virus or worm has infected many computers, is known as a distributed DoS
attack. Such distributed DoS attacks can spread rapidly and involve thousands of systems.
When NAT pool overload and interface overload happens, ensure that the ports are free and the same port is
allocated for the global port and source port.
Note You must configure different IP addresses for an interface on which NAT is configured and for inside
addresses that are configured by using the ip nat inside source static command.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source static local-ip global-ip
4. interface type number
5. ip address ip-address mask [secondary]
6. ip nat inside
7. exit
8. interface type number
9. ip address ip-address mask [secondary]
10. ip nat outside
11. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat inside source static local-ip global-ip Establishes static translation between an inside local
address and an inside global address.
Example:
Device(config)# ip nat inside source static
[Link] [Link]
Step 4 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 1
Step 5 ip address ip-address mask [secondary] Sets a primary IP address for an interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 6 ip nat inside Connects the interface to the inside network, which is
subject to NAT.
Example:
Device(config-if)# ip nat inside
Step 8 interface type number Specifies a different interface and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 0/0/0
Step 9 ip address ip-address mask [secondary] Sets a primary IP address for an interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
Note When inside global or outside local addresses belong to a directly connected subnet on a Network Address
Translation (NAT) device, the device adds IP aliases for them so that it can answer Address Resolution
Protocol (ARP) requests. However, a situation can arise where the device answers packets that are not
destined for it, possibly causing a security issue. This can happen when an incoming Internet Control
Message Protocol (ICMP) packet or an UDP packet that is destined for one of the aliased addresses does
not have a corresponding NAT translation in the NAT table, and the device itself runs a corresponding
service, for example, Network Time Protocol (NTP). Such a situation might cause minor security risks.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
4. access-list access-list-number permit source [source-wildcard]
5. ip nat inside source list access-list-number pool name
6. interface type number
7. ip address ip-address mask
8. ip nat inside
9. exit
10. interface type number
11. ip address ip-address mask
12. ip nat outside
13. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} needed.
Example:
Device(config)# ip nat pool net-208 [Link]
[Link] prefix-length 28
Step 4 access-list access-list-number permit source Defines a standard access list permitting those
[source-wildcard] addresses that are to be translated.
Example:
Device(config)# access-list 1 permit [Link]
[Link]
Step 5 ip nat inside source list access-list-number pool name Establishes dynamic source translation, specifying the
access list defined in Step 4.
Example:
Device(config)# ip nat inside source list 1 pool
net-208
Step 7 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 8 ip nat inside Connects the interface to the inside network, which is
subject to NAT.
Example:
Device(config-if)# ip nat inside
Step 10 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 0
Step 11 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
4. access-list access-list-number permit source [source-wildcard]
5. ip nat inside source list access-list-number pool name overload
6. interface type number
7. ip address ip-address mask
8. ip nat inside
9. exit
10. interface type number
11. ip address ip-address mask
12. ip nat outside
13. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} needed.
Example:
Device(config)# ip nat pool net-208
[Link] [Link] netmask
[Link]
Step 4 access-list access-list-number permit source Defines a standard access list permitting those addresses
[source-wildcard] that are to be translated.
• The access list must permit only those addresses that
Example: are to be translated. (Remember that there is an
Device(config)# access-list 1 permit
[Link] [Link] implicit “deny all” at the end of each access list.) Use
of an access list that is too permissive can lead to
unpredictable results.
Example:
Device(config)# ip nat inside source list 1 pool
net-208 overload
Step 6 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 1
Step 7 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 8 ip nat inside Connects the interface to the inside network, which is
subject to NAT.
Example:
Device(config-if)# ip nat inside
Step 10 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 0
Step 11 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat translation seconds
4. ip nat translation udp-timeout seconds
5. ip nat translation dns-timeout seconds
6. ip nat translation tcp-timeout seconds
7. ip nat translation finrst-timeout seconds
8. ip nat translation icmp-timeout seconds
9. ip nat translation syn-timeout seconds
10. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat translation seconds (Optional) Changes the amount of time after which NAT
translations time out.
Example: • The default timeout is 24 hours, and it applies to the aging
Device(config)# ip nat translation 300
time for half-entries.
Step 4 ip nat translation udp-timeout seconds (Optional) Changes the UDP timeout value.
Example:
Device(config)# ip nat translation
udp-timeout 300
Step 5 ip nat translation dns-timeout seconds (Optional) Changes the Domain Name System (DNS) timeout
value.
Example:
Device(config)# ip nat translation
dns-timeout 45
Step 6 ip nat translation tcp-timeout seconds (Optional) Changes the TCP timeout value.
• The default is 24 hours.
Example:
Device(config)# ip nat translation
tcp-timeout 2500
Step 7 ip nat translation finrst-timeout seconds (Optional) Changes the finish and reset timeout value.
• finrst-timeout—The aging time after a TCP session
Example: receives both finish-in (FIN-IN) and finish-out (FIN-OUT)
Device(config)# ip nat translation
finrst-timeout 45 requests or after the reset of a TCP session.
Step 8 ip nat translation icmp-timeout seconds (Optional) Changes the ICMP timeout value.
Example:
Device(config)# ip nat translation
icmp-timeout 45
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source static local-ip global-ip
4. interface type number
5. ip address ip-address mask
6. ip nat inside
7. exit
8. interface type number
9. ip address ip-address mask
10. ip nat outside
11. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat inside source static local-ip global-ip Establishes static translation between an inside local
address and an inside global address.
Example:
Device(config)# ip nat inside source static
[Link] [Link]
Step 4 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 1
Step 5 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat inside
Step 8 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 0
Step 9 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
4. access-list access-list-number permit source [source-wildcard]
5. ip nat outside source list access-list-number pool name
6. interface type number
7. ip address ip-address mask
8. ip nat inside
9. exit
10. interface type number
11. ip address ip-address mask
12. ip nat outside
13. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} needed.
Example:
Device(config)# ip nat pool net-10 [Link]
[Link] prefix-length 24
Step 4 access-list access-list-number permit source Defines a standard access list permitting those addresses
[source-wildcard] that are to be translated.
• The access list must permit only those addresses that
Example: are to be translated. (Remember that there is an
Device(config)# access-list 1 permit [Link]
[Link] implicit “deny all” at the end of each access list.) Use
of an access list that is too permissive can lead to
unpredictable results.
Step 6 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 1
Step 7 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat inside
Step 10 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 0
Step 11 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
What to Do Next
When you have completed the required configuration, go to the “Monitoring and Maintaining NAT” module.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length} type rotary
4. access-list access-list-number permit source [source-wildcard]
5. ip nat inside destination-list access-list-number pool name
6. interface type number
7. ip address ip-address mask
8. ip nat inside
9. exit
10. interface type number
11. ip address ip-address mask
12. ip nat outside
13. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ip nat pool real-hosts
[Link] [Link] prefix-length 28 type
rotary
Step 4 access-list access-list-number permit source Defines an access list permitting the address of the
[source-wildcard] virtual host.
Example:
Device(config)# access-list 1 permit [Link]
[Link]
Step 5 ip nat inside destination-list access-list-number pool name Establishes dynamic inside destination translation,
specifying the access list defined in the prior step.
Example:
Device(config)# ip nat inside destination-list 2
pool real-hosts
Step 6 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 0
Step 7 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat inside
Step 10 interface type number Specifies a different interface and enters interface
configuration mode.
Example:
Device(config)# interface serial 0
Step 11 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source {list {access-list-number | access-list-name} pool pool-name [overload]| static
local-ip global-ip [route-map map-name]}
4. exit
5. show ip nat translations [verbose]
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat inside source {list {access-list-number | Enables route mapping with static NAT configured
access-list-name} pool pool-name [overload]| static local-ip on the NAT inside interface.
global-ip [route-map map-name]}
Example:
Device(config)# ip nat inside source static
[Link] [Link] route-map isp2
Example:
Device# show ip nat translations
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip netmask netmask
4. ip nat pool name start-ip end-ip netmask netmask
5. ip nat inside source route-map name pool name [reversible]
6. ip nat inside source route-map name pool name [reversible]
7. end
DETAILED STEPS
Example:
Device(config)# configure terminal
Step 3 ip nat pool name start-ip end-ip netmask netmask Defines a pool of network addresses for NAT.
Example:
Device(config)# ip nat pool POOL-A [Link]
[Link] netmask [Link]
Step 4 ip nat pool name start-ip end-ip netmask netmask Defines a pool of network addresses for NAT.
Example:
Device(config)# ip nat pool POOL-B [Link]
[Link] netmask [Link]
Step 5 ip nat inside source route-map name pool name [reversible] Enables outside-to-inside initiated sessions to use
route maps for destination-based NAT.
Example:
Device(config)# ip nat inside source route-map MAP-A
pool POOL-A reversible
Step 6 ip nat inside source route-map name pool name [reversible] Enables outside-to-inside initiated sessions to use
route maps for destination-based NAT.
Example:
Device(config)# ip nat inside source route-map MAP-B
pool POOL-B reversible
Note When you configure the ip nat outside source static command to add static routes for outside local
addresses, there is a delay in the translation of packets and packets are dropped. Packets are dropped
because a shortcut is not created for the initial synchronization (SYN) packet when NAT is configured
for static translation. To avoid dropped packets, configure either the ip nat outside source static add-route
command or the ip route command.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source {list {access-list-number | access-list-name} pool pool-name [overload] | static
network local-ip global-ip [no-payload]}
4. ip nat inside source {list {access-list-number | access-list-name} pool pool-name [overload] | static {tcp
| udp} local-ip local-port global-ip global-port [no-payload]}
5. ip nat inside source {list {access-list-number | access-list-name} pool pool-name [overload] | static
[network] local-network-mask global-network-mask [no-payload]}
6. ip nat outside source {list {access-list-number | access-list-name} pool pool-name | static local-ip
global-ip [no-payload]}
7. ip nat outside source {list {access-list-number | access-list-name} pool pool-name | static {tcp | udp}
local-ip local-port global-ip global-port [no-payload]}
8. ip nat outside source {list {access-list-number | access-list-name} pool pool-name | static [network]
local-network-mask global-network-mask [no-payload]}
9. exit
10. show ip nat translations [verbose]
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat inside source {list {access-list-number | access-list-name} pool Disables the network packet translation on
pool-name [overload] | static network local-ip global-ip [no-payload]} the inside host device.
Example:
Device(config)# ip nat inside source static network [Link]
[Link]/24 no-payload
Step 4 ip nat inside source {list {access-list-number | access-list-name} pool Disables port packet translation on the
pool-name [overload] | static {tcp | udp} local-ip local-port global-ip inside host device.
global-port [no-payload]}
Example:
Device(config)# ip nat inside source static tcp [Link] 2000
[Link] 2000 no-payload
Step 5 ip nat inside source {list {access-list-number | access-list-name} pool Disables packet translation on the inside
pool-name [overload] | static [network] local-network-mask host device.
global-network-mask [no-payload]}
Example:
Device(config)# ip nat inside source static [Link]
[Link] no-payload
Step 6 ip nat outside source {list {access-list-number | access-list-name} pool Disables packet translation on the outside
pool-name | static local-ip global-ip [no-payload]} host device.
Example:
Device(config)# ip nat outside source static [Link]
[Link] no-payload
Step 7 ip nat outside source {list {access-list-number | access-list-name} pool Disables port packet translation on the
pool-name | static {tcp | udp} local-ip local-port global-ip global-port outside host device.
[no-payload]}
Example:
Device(config)# ip nat outside source static tcp [Link]
20000 [Link] 20000 no-payload
Step 8 ip nat outside source {list {access-list-number | access-list-name} pool Disables network packet translation on the
pool-name | static [network] local-network-mask global-network-mask outside host device.
[no-payload]}
Example:
Device(config)# ip nat outside source static network [Link]
[Link]/24 no-payload
Example:
Device# show ip nat translations
Note • You can use this feature to configure gaming devices with an IP address that is different from that
of the PC. To avoid unwanted traffic or DoS attacks, use access lists.
• For traffic going from the PC to the outside, it is better to use a route map so that extended entries
are created.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source static local-ip interface type number
4. ip nat inside source static tcp local-ip local-port interface global-port
5. exit
6. show ip nat translations [verbose]
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat inside source static local-ip interface type number Enables static NAT on the interface.
Example:
Device(config)# ip nat inside source static [Link]
interface Ethernet 1/1
Step 4 ip nat inside source static tcp local-ip local-port interface (Optional) Enables the use of telnet to the device
global-port from the outside.
Example:
Device(config)# ip nat inside source static tcp
[Link] 23 interface 23
Example:
Device# show ip nat translations
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. ip nat inside
5. exit
6. ip nat allow-static-host
7. ip nat pool name start-ip end-ip netmask netmask accounting list-name
8. ip nat inside source list access-list-number pool name
9. access-list access-list-number deny ip source
10. end
11. show ip nat translations verbose
DETAILED STEPS
Example:
Device# configure terminal
Step 3 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface ethernet 1
Example:
Device(config-if)# ip nat inside
Step 7 ip nat pool name start-ip end-ip netmask netmask Specifies an existing RADIUS profile name to be used for
accounting list-name authentication of the static IP host.
Example:
Device(config)# ip nat pool pool1 [Link]
[Link] netmask [Link]
accounting WLAN-ACCT
Step 8 ip nat inside source list access-list-number pool Specifies the access list and pool to be used for static IP
name support.
• The specified access list must permit all traffic.
Example:
Device(config)# ip nat inside source list 1
pool net-208
Step 9 access-list access-list-number deny ip source Removes the traffic of the device from NAT.
• The source argument is the IP address of the device that
Example: supports the NAT Static IP Support feature.
Device(config)# access-list 1 deny ip
[Link]
Step 11 show ip nat translations verbose (Optional) Displays active NAT translations and additional
information for each translation table entry, including how
Example: long ago the entry was created and used.
Device# show ip nat translations verbose
Examples
The following is sample output from the show ip nat translations verbose command:
Device# show ip nat translations verbose
create 00:05:59, use 00:03:39, left 23:56:20, Map-Id(In): 1, flags: none wlan-flags: Secure
ARP added, Accounting Start sent Mac-Address:0010.7bc2.9ff6 Input-IDB:Ethernet1/2, use_count:
0, entry-id:7, lc_entries: 0
1. enable
2. show ip nat translations
3. configure terminal
4. ip nat translation max-entries {number | all-vrf number | host ip-address number | list listname number
| vrf name number}
5. end
6. show ip nat statistics
DETAILED STEPS
Example:
Device# configure terminal
Step 4 ip nat translation max-entries {number | Configures the maximum number of NAT entries allowed from the
all-vrf number | host ip-address number | specified source.
list listname number | vrf name number}
• The maximum number of allowed NAT entries is 2147483647,
although a typical range for a NAT rate limit is 100 to 300 entries.
Example:
Device(config)# ip nat translation • When you configure a NAT rate limit for all VRF instances, each
max-entries 300
VRF instance is limited to the maximum number of NAT entries
that you specify.
• When you configure a NAT rate limit for a specific VRF instance,
you can specify a maximum number of NAT entries for the named
VRF instance that is greater than or less than that allowed for all
VRF instances.
Example:
Device(config)# end
Step 6 show ip nat statistics (Optional) Displays current NAT usage information, including NAT rate
limit settings.
Example: • After setting a NAT rate limit, use the show ip nat statistics
Device# show ip nat statistics
command to verify the current NAT rate limit settings.
The following example shows NAT configured on the provider edge (PE) device with a static route to the
shared service for the vrf1 and vrf2 VPNs. NAT is configured as inside source static one-to-one translation.
The following example shows how only traffic local to the provider edge (PE) device running NAT is translated:
ip nat inside source list 1 interface gigabitethernet 0/0/0 vrf vrf1 overload
ip nat inside source list 1 interface gigabitethernet 0/0/0 vrf vrf2 overload
!
ip route vrf vrf1 [Link] [Link] [Link]
ip route vrf vrf2 [Link] [Link] [Link]
!
access-list 1 permit [Link].0 [Link]
!
ip nat inside source list 1 interface gigabitethernet 1/1/1 vrf vrf1 overload
ip nat inside source list 1 interface gigabitethernet 1/1/1 vrf vrf2 overload
!
ip route vrf vrf1 [Link] [Link] [Link] global
ip route vrf vrf2 [Link] [Link] [Link] global
access-list 1 permit [Link] [Link]
!
local IP addresses. The ip nat outside source list 1 pool net-10 command translates the addresses of hosts
from the outside overlapping network to addresses in that pool.
ip nat pool net-208 [Link] [Link] prefix-length 28
ip nat pool net-10 [Link] [Link] prefix-length 24
access-list 1 permit [Link] [Link]
ip nat inside source list 1 pool net-208
ip nat outside source list 1 pool net-10
!
interface gigabitethernet 1/1/1
ip address [Link] [Link]
ip nat inside
!
interface gigabitethernet 0/0/0
ip address [Link] [Link]
ip nat outside
!
ip nat outside source static tcp [Link] 20000 [Link] 20000 no-payload
ip nat outside source static network [Link] [Link]/24 no-payload
The following example shows how to limit the access control list named “vrf3” to 100 NAT entries:
ip nat translation max-entries list vrf3 100
The following example shows how to limit the host at IP address [Link] to 300 NAT entries:
ip nat translation max-entries host [Link] 300
Where to Go Next
• To configure NAT for use with application-level gateways, see the “Using Application Level Gateways
with NAT” module.
• To verify, monitor, and maintain NAT, see the “Monitoring and Maintaining NAT” module.
• To integrate NAT with Multiprotocol Label Switching (MPLS) VPNs, see the “Integrating NAT with
MPLS VPNs” module.
• To configure NAT for high availability, see the “Configuring NAT for High Availability” module.
NAT commands: complete command syntax, Cisco IOS IP Addressing Services Command Reference
command mode command history, defaults,
usage guidelines, and examples
IP access list sequence numbering IP Access List Entry Sequence Numbering document
RADIUS attributes overview RADIUS Attributes Overview and RADIUS IETF Attributes
module
Standard/RFC Title
IETF Behave Draft NAT MIB Definitions of Managed Objects for Network Address
Translators (NAT) draft-ietf-behave-nat-mib-11
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
NAT Duplicate Inside Global Cisco IOS XE Release The Cisco IOS XE software supports the NAT
Address 2.1 Duplicate Inside Global Addresses feature.
NAT Host Number Preservation Cisco IOS XE Release For ease of network management, some sites
2.1 prefer to translate prefixes rather than addresses.
These sites want the translated address to have
the same host number as the original address.
The two prefixes must be of the same length.
The NAT Host Number Preservation feature
can be enabled by configuring dynamic
translation with the address pool of the type,
match-host.
NAT Route Maps Outside-to- Cisco IOS XE Release The NAT Route Maps Outside-to- Inside
Inside Support 2.2 Support feature enables the deployment of a
NAT route map configuration that will allow IP
sessions to be initiated from the outside to the
inside.
NAT Static IP Support Cisco IOS XE Release The NAT Static IP Support feature provides
2.1 support for users with static IP addresses,
enabling those users to establish an IP session
in a public wireless LAN environment.
NAT Timers Cisco IOS XE Release The NAT Timers feature allows you to change
2.1 the amount of time after which NAT translations
time out.
NAT Translation of External IP Cisco IOS XE Release You can use the NAT Translation of External
Addresses Only 2.1 IP Address Only feature to configure NAT to
ignore all embedded IP addresses for any
application and traffic type.
Rate Limiting NAT Translation Cisco IOS XE Release The Rate Limiting NAT Translation feature
2.1 provides the ability to limit the maximum
number of concurrent Network Address
Translation (NAT) operations on a router. In
addition to giving users more control over how
NAT addresses are used, the Rate Limiting NAT
Translation feature can be used to limit the
effects of viruses, worms, and denial-of-service
attacks.
NAT support on BDI interface Cisco IOS XE Denali The NAT support on BDI interface feature
16.3.1 enables you to configure NAT on Bridge
Domain Interface (BDI).
No commands were introduced or modified for
this feature.
Multi-Tenant support for NAT Cisco IOS XE Denali With Multi-Tenant support for NAT feature,
16.3.1 the configuration changes of a VRF instance
does not interrupt the traffic flow of other VRFs
in the network.
No commands were introduced or modified for
this feature.
Bypass NAT functionality Cisco IOS XE Denali The Bypass NAT functionality feature enables
16.3.2 you to permit an ACL with deny statements
Cisco IOS XE Everest using a bypass pool. The Bypass NAT
functionality feature reduces the TCAM size by
16.4.1
resolving the deny jump issue.
No commands were introduced or modified for
this feature
In Cisco IOS XE Denali 16.3
Bypass NAT functionality
.2, support was added for Cisco Cloud Services
Router 1000V Series, Cisco ASR 1000 Series
Routers with Route Processors (RP2 and RP3),
Cisco 4000 Series Integrated Services Routers.
In Cisco IOS XE Everest 16.4.1, support was
extended to Cisco ASR 1001-HX Router, Cisco
ASR 1001-X Router, Cisco ASR 1002-HX
Router, Cisco ASR 1002-X Router.
• Before performing the tasks in this module, you should verify that the Session Initiation Protocol (SIP)
and H.323 are not disabled. SIP and H.323 are enabled by default.
IPsec
IPsec is a set of extensions to the IP protocol family in a framework of open standards for ensuring secure
private communications over the Internet. Based on standards developed by the IETF, IPsec ensures
confidentiality, integrity, and authenticity of data communications across the public network and provides
cryptographic security services.
Secure tunnels between two peers, such as two routers, are provided and decisions are made as to which
packets are considered sensitive and should be sent through these secure tunnels, and which parameters should
be used to protect these sensitive packets by specifying characteristics of these tunnels. When the IPsec peer
receives a sensitive packet, it sets up the appropriate secure tunnel and sends the packet through the tunnel to
the remote peer.
IPsec using Encapsulating Security Payload (ESP) can pass through a router running NAT without any specific
support from it as long as Network Address Port Translation (NAPT) or address overloading is not configured.
You can enable IPsec packet processing using ESP with the ip nat service ipsec-esp enable command.
There are a number of factors to consider when attempting an IPsec VPN connection that traverses a NAPT
device that represents multiple private internal IP addresses as a single public external IP address. Such factors
include the capabilities of the VPN server and client, the capabilities of the NAPT device, and whether more
than one simultaneous connection is attempted across the NAPT device.
There are two possible methods for configuring IPsec on a router with NAPT:
• Encapsulate IPsec in a Layer 4 protocol such as TCP or UDP. In this case, IPsec is sneaking through
NAT. The NAT device is unaware of the encapsulation.
• Add IPsec-specific support to NAPT. IPsec works with NAT in this case as opposed to sneaking through
NAT. The NAT Support for IPsec ESP-- Phase II feature provides support for Internet Key Exchange
(IKE) and ESP without encapsulation in tunnel mode through a Cisco IOS router configured with NAPT.
We recommend that TCP and UDP be used when conducting IPsec sessions that traverse a NAPT device.
However, not all VPN servers or clients support TCP or UDP.
SPI Matching
SPI matching is used to establish VPN connections between multiple pairs of destinations. NAT entries will
immediately be placed in the translation table for endpoints matching the configured access list..
Note By default support for SIP is enabled on port 5060. Therefore, NAT-enabled devices interpret all packets
on this port as SIP call messages. If other applications in the system use port 5060 to send packets, the
NAT service may corrupt the packet as it attempts to interpret the packet as a SIP call message.
CallManager is on the inside (behind the NAT device), or static NAT should be configured to reach the Cisco
CallManager in the inside.
When an IP phone attempts to connect to the Cisco CallManager and it matches the configured NAT rules,
NAT will translate the original source IP address and replace it with one from the configured pool. This new
address will be reflected in the Cisco CallManager and be visible to other IP phone users.
Restrictions
The NAT Segmentation with Layer 4 Forwarding feature does not work when:
• Firewalls are configured using the ip inspect name command. (Context-Based Access Control (CBAC)
firewalls are not supported. Zone-based firewalls are supported.)
• H.323, SCCP, or TCP DNS messages are larger than 18 KB.
• Multiprotocol Label Switching (MPLS) is configured.
• NAT and the Cisco Unified CallManager are configured on the same device. In this case, a colocated
solution in Call Manager Express is used.
• NAT Virtual Interface (NVI) is configured.
• Stateful Network Address Translation (SNAT) is enabled.
Note Effective January 31, 2014, Stateful NAT is not available in Cisco IOS software. For
more information, see End-of-Sale and End-of-Life Announcement for the Cisco IOS
Stateful Failover of Network Address Translation (SNAT).
• The match-in-vrf keyword is configured along with the ip nat inside source command for packet
translation.
• The packets are IPv6 packets.
Note IPsec can be configured for any NAT configuration, not just static NAT configurations.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat [inside | outside] source static local-ip global-ip [vrf vrf-name]
4. exit
5. show ip nat translations
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat [inside | outside] source static local-ip global-ip [vrf Enables static NAT.
vrf-name]
Example:
Router(config)# ip nat inside source static
[Link] [Link]
Example:
Router(config)# exit
Example:
Router# show ip nat translations
Note This task is required by certain VPN concentrators. Cisco VPN devices generally do not use this feature.
>
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat service list access-list-number IKE preserve-port
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat service list access-list-number IKE preserve-port Specifies IPsec traffic that matches the access list to
preserve the port.
Example:
Router(config)# ip nat service list 10 IKE
preserve-port
Security parameter index (SPI) matching is used to establish VPN connections between multiple pairs of
destinations. NAT entries are immediately placed in the translation table for endpoints matching the configured
access list. SPI matching is available only for endpoints that choose SPIs according to the predictive algorithm
implemented in Cisco IOS Release 12.2(15)T.
The generation of SPIs that are predictable and symmetric is enabled. SPI matching should be used in
conjunction with NAT devices when multiple ESP connections across a NAT device are desired.
Note SPI matching must be configured on the NAT device and both endpoint devices.
>
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat service list access-list-number ESP spi-match
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat service list access-list-number ESP Specifies an access list to enable SPI matching.
spi-match
• This example shows how to enter ESP traffic matching list
10 into the NAT table, making the assumption that both
Example: devices are Cisco devices and are configured to provide
Router(config)# ip nat service list 10 ESP matchable SPIs.
spi-match
Note Security parameter index (SPI) matching must be configured on the Network Address Translation (NAT)
device and on both endpoint devices.
SUMMARY STEPS
1. enable
2. configure terminal
3. crypto ipsec nat-transparency spi-matching
4. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 crypto ipsec nat-transparency spi-matching Enables SPI matching on both endpoints.
Example:
Device(config)# crypto ipsec nat-transparency
spi-matching
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat service allow-multipart
4. exit
5. show ip nat translations
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ip nat service allow-multipart
Example:
Device# show ip nat translations
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat service skinny tcp port number
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat service skinny tcp port number Configures the skinny protocol on the specified TCP
port.
Example:
Router(config)# ip nat service skinny tcp port
20002
Where to Go Next
• To learn about NAT and configure NAT for IP address conservation, see the “Configuring NAT for IP
Address Conservation” module.
• To verify monitor, and maintain NAT, see the “Monitoring and Maintaining NAT” module.
• To integrate NAT with MPLS VPNs, see the “Integrating NAT with MPLS VPNs” module.
• To configure NAT for high availability, see the “Configuring NAT for High Availability” module.
NAT commands: complete command syntax, Cisco IOS IP Addressing Services Command
command mode, defaults, usage guidelines, and Reference
examples
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
ALG—SCCP Version 17 Support Cisco IOS XE The ALG—SCCP Version 17 Support feature
Release 3.5S enables the SCCP ALG to parse SCCP Version
17 packets. Cisco Unified Communications
Manager 7.0 and IP phones that use Cisco Unified
Communications Manager 7.0 support only SCCP
Version 17 messages. The SCCP Version 17
packets support IPv6 packets. The SCCP ALG
supports the inspection and translation of IPv4
address information in SCCP messages.
NAT ALG—SIP REFER Method Cisco IOS XE The NAT ALG—SIP REFER method feature
Release 3.2S supports two types of call transfers, unattended
(blind) transfer and attended (consultative)
transfer.
NAT Basic H.323 ALG Support Cisco IOS XE NAT requires a variety of ALGs to handle Layer
Release 2.1 7 protocol-specific services such as translating
embedded IP addresses and port numbers in the
packet payload and extracting new
connection/session information from control
channels. The NAT Basic H.323 ALG support
feature provides these specific services for H.323
messages.
NAT DNS ALG Support Cisco IOS XE The NAT DNS ALG Support feature supports
Release 2.1 translation of DNS packets.
NAT FTP ALG Support Cisco IOS XE The NAT FTP ALG Support feature supports
Release 2.1 translation of FTP packets.
NAT H.323 RAS Cisco IOS XE NAT supports all H.225 and H. 245 message
Release 2.4 types, including those sent in the Registration,
Admission, and Status (RAS) protocol. RAS
provides a number of messages that are used by
software clients and VoIP devices to register their
location, request assistance in call setup, and
control bandwidth. The RAS messages are
directed toward an H.323 gatekeeper.
NAT ICMP ALG Support Cisco IOS XE The NAT ICMP ALG Support feature supports
Release 2.1 translation of ICMP packets.
NAT NetBIOS ALG Support Cisco IOS XE NAT provides Network Basic Input Output
Release 3.1S System (NetBIOS) message translation support.
The NAT NetBIOS ALG Support feature
introduced the following command to display
NetBIOS-specific information for a device: show
platform hardware qfp [active | standby]
feature alg statistics netbios.
NAT NetMeeting Directory Cisco IOS XE The NAT NetMeeting Directory (LDAP) feature
(LDAP) Release 2.4 provides ALG support for NetMeeting directory
LDAP messages.
NAT RTSP ALG Support Cisco IOS XE The NAT RTSP ALG Support feature provides
Release 3.1S RTSP message translation support.
NAT—SCCP for Video Cisco IOS XE The NAT—SCCP for Video feature provides
Release 2.4 SCCP video message translation support.
NAT—SIP ALG Enhancement for Cisco IOS XE The NAT—SIP ALG Enhancement for T.38 Fax
T.38 Fax Relay Release 2.4.1 Relay feature provides translation support for SIP
ALG support of T.38 Fax Relay over IP.
NAT—SIP Extended Methods Cisco IOS XE The NAT—SIP Extended Methods feature
Release 2.4 supports extended methods for SIP.
NAT Support of IP Phone to Cisco Cisco IOS XE The NAT Support of IP Phone to Cisco
CallManager Release 2.1 CallManager feature adds NAT support for
configuring Cisco SCCP for a Cisco IP phone-to-
Cisco CallManager communication.
NAT Support for IPsec Cisco IOS XE The NAT Support for IPsec ESP-- Phase II feature
ESP—Phase II Release 2.1 provides support for Internet Key Exchange (IKE)
and ESP without encapsulation in tunnel mode
through a device configured with NAPT.
NAT Support for SIP Cisco IOS XE The NAT Support for SIP feature adds the ability
Release 2.1 to deploy NAT between VoIP solutions based on
SIP.
Cisco IOS XE
Release 3.2S
NAT TFTP ALG Support Cisco IOS XE The NAT TFTP ALG Support feature supports
Release 2.1 translation of TFTP packets.
NAT VRF-Aware ALG Support Cisco IOS XE The NAT VRF-Aware ALG Support feature
Release 2.5 supports VPN routing and forwarding (VRF) for
protocols that have a supported ALG.
NAT vTCP ALG Support Cisco IOS XE The NAT vTCP ALG Support feature provides
Release 3.1S vTCP support to handle TCP segmentation and
reassembling for ALG.
Cisco IOS XE
Release 3.2S
• Logging of NAT high-speed logging (HSL) records. For more information about HSL, see the section
“High-Speed Logging for NAT” in the Maintaining and Monitoring NAT module of the IP Addressing:
NAT Configuration Guide.
• Multihoming, which is the ability to support multiple outside interfaces to provide connectivity through
redundant or standby exit points. Depending on the configured routing topology, any exit interface that
is marked as an outside interface can use a translation that was created previously.
• TCP timeout value of 2 hours and 4 minutes.
• VPN routing and forwarding (VRF)-aware NAT.
• CGN NAT can scale to higher number of translations on ESP200 using the ip nat settings scale bind
command.
Note You must use at least one of the configurations described in the following tasks for Carrier Grade NAT
to work.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat settings mode cgn
4. ip nat inside source static local-ip global-ip
5. interface gigabitethernet card/spaslot/[Link]-number
6. ip nat inside
7. exit
8. interface type number
9. ip nat outside
10. end
11. show ip nat translations [verbose]
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ip nat settings mode cgn
Step 4 ip nat inside source static local-ip global-ip Enables static Carrier Grade NAT of the inside source
address.
Example:
Device(config)# ip nat inside source static
[Link] [Link]
Step 6 ip nat inside Indicates that the interface is connected to the inside
network (the network that is subject to NAT translation).
Example:
Device(config-if)# ip nat inside
Step 8 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/0
Step 9 ip nat outside Indicates that the interface is connected to the outside
network.
Example:
Device(config-if)# ip nat outside
Example:
Device# show ip nat translations
Example
The following is sample output from the show ip nat translations command:
Device# show ip nat translations
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat settings mode cgn
4. access-list standard-access-list-number permit source wildcard
5. access-list standard-access-list-number permit source wildcard
6. route-map map-tag
7. match ip address [access-list-number]
8. match ip next-hop [access-list-number]
9. exit
10. ip nat pool name start-ip end-ip prefix-length prefix-length
11. ip nat inside source route-map name pool name
12. interface gigabitethernet card/spaslot/[Link]-number
13. ip nat inside
14. exit
15. interface type number
16. ip nat outside
17. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ip nat settings mode cgn
Step 4 access-list standard-access-list-number permit source Defines a standard access list and specifies a host.
wildcard
• Access list 1 defined in this step is used by the match
ip address command.
Example:
Device(config)# access-list 1 permit [Link]
[Link]
Step 5 access-list standard-access-list-number permit source Defines a standard access list and specifies a host.
wildcard
• Access list 2 defined in this step is used by the match
ip next-hop command.
Example:
Device(config)# access-list 2 permit [Link]
[Link]
Step 6 route-map map-tag Defines conditions for redistributing routes from one routing
protocol into another or enables policy routing and enters
Example: route-map configuration mode.
Device(config)# route-map nat-route-map
Step 7 match ip address [access-list-number] Distributes any routes that have a destination network number
address that is permitted by a standard access list, an extended
Example: access list, or a prefix list or performs policy routing on
Device(config-route-map)# match ip address 1 packets.
Step 8 match ip next-hop [access-list-number] Redistributes any routes that have a next-hop router address
passed by one of the specified access lists.
Example:
Device(config-route-map)# match ip next-hop 2
Example:
Device(config)# ip nat pool nat-pool [Link]
[Link] prefix-length 16
Step 11 ip nat inside source route-map name pool name Enables dynamic NAT of the inside source address.
Example:
Device(config)# ip nat inside source route-map
nat-route-map pool nat-pool
Step 13 ip nat inside Indicates that the interface is connected to the inside network
(the network that is subject to NAT translation).
Example:
Device(config-if)# ip nat inside
Step 15 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet
0/0/1
Step 16 ip nat outside Indicates that the interface is connected to the outside
network.
Example:
Device(config-if)# ip nat outside
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat settings mode cgn
4. ip nat inside source list number pool name [overload]
5. ip nat pool name start-ip end-ip netmask netmask
6. access-list standard-access-list-number permit source wildcard
7. interface gigabitethernet card/spaslot/[Link]-number
8. ip nat inside
9. exit
10. interface type number
11. ip nat outside
12. end
13. show ip nat statistics
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ip nat settings mode cgn
Step 4 ip nat inside source list number pool name [overload] Enables the router to use one global address for many local
addresses.
Example: • When you configure the overload keyword, the TCP
Device(config)# ip nat inside source list 1
pool nat-pool overload or UDP port number of each inside host distinguishes
Step 5 ip nat pool name start-ip end-ip netmask netmask Defines a pool of IP addresses for NAT.
Example:
Device(config)# ip nat pool nat-pool [Link]
[Link] netmask [Link]
Step 6 access-list standard-access-list-number permit source Defines a standard access list and specifies a host.
wildcard
Example:
Device(config)# access-list 1 permit [Link]
[Link]
Step 10 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/2
Step 11 ip nat outside Indicates that the interface is connected to the outside
network.
Example:
Device(config-if)# ip nat outside
Example:
Device# show ip nat statistics
Example
The following is sample output from the show ip nat statistics command:
Device# show ip nat statistics
Standard/RFC Title
RFC 4787 Network Address Translation (NAT) Behavioral
Requirements for Unicast UDP
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Static Mapping Support with HSRP for High Availability Feature Overview
When an Address Resolution Protocol (ARP) query is triggered for an address that is configured with NAT
static mapping and owned by the device, NAT responds with the burned in MAC (BIA MAC) address on the
interface to which the ARP is pointing. Two devices act as the Hot Standby Router Protocol (HSRP) active
and standby. You must enable and configure the NAT inside interfaces of the active and standby devices to
belong to a group.
ARP is used to associate IP addresses with media or MAC addresses. Taking an IP address as input, ARP
determines the associated media address. Once a media or MAC address is determined, the IP address or
media address association is stored in an ARP cache for rapid retrieval. Then the IP datagram is encapsulated
in a link-layer frame and sent over the network. Encapsulation of IP datagrams and ARP requests and replies
on IEEE 802 networks other than Ethernet is specified by the Subnetwork Access Protocol (SNAP).
Gratuitous ARP
When a host sends an ARP request to resolve its own IP address, it is called gratuitous ARP. In the ARP
request packet, the source and destination IP addresses are filled with the same source IP address itself. The
destination MAC address is the Ethernet broadcast address.
When a router becomes active, it broadcasts a gratuitous ARP packet with the Hot Standby Router Protocol
(HSRP) virtual MAC address to the affected LAN segment. If the segment uses an Ethernet switch, this allows
the switch to change the location of the virtual MAC address so that packets flow to the new router instead
of the one that is no longer active. End devices do not actually need gratuitous ARP if routers use the default
HSRP MAC address.
Both of the following tasks are required and must be performed on both the active and standby routers to
configure NAT static mapping support for HSRP:
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. ip address ip-address mask
5. no ip redirects
6. ip nat {inside | outside}
7. standby [group-number] ip [ip-address [secondary]]
8. standby [group-number] preempt
9. standby [group-number] ip [ip-address | secondary]
10. standby [group-number] name [group-name]
11. standby [group-number] track interface-number
12. end
13. show standby
14. show ip nat translations [verbose]
DETAILED STEPS
Example:
Device# configure terminal
Step 4 ip address ip-address mask Sets the primary IP address on the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# no ip redirects
Example:
Device(config)# ip nat inside
Example:
Device(config-if)# standby 10 priority 105
Example:
Device(config-if)# standby 10 preempt
Example:
Device(config-if)# standby 10 ip [Link]
Step 10 standby [group-number] name [group-name] Sets the HSRP group name.
Example:
Device(config-if)# standby 10 name HSRP1
Step 11 standby [group-number] track interface-number Configures HSRP to track an object and to change
the hot standby priority on the basis of the state of
Example: the object.
Device(config-if)# standby 10 track
gigabitethernet1/1/1
Example:
Device# show standby
Step 14 show ip nat translations [verbose] (Optional) Displays active NAT translations.
Example:
Device# show ip nat translations verbose
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source static local-ip global-ip redundancy group-name
4. ip classless
5. ip route prefix mask interface-type interface-number
6. no ip http server
7. end
8. show ip nat translations [verbose]
DETAILED STEPS
Example:
Device> enable
Step 3 ip nat inside source static local-ip global-ip redundancy Enables a device to respond to Address Resolution
group-name Protocol (ARP) queries using BIA MAC, if HSRP is
configured on the NAT inside interface.
Example:
Device(config)# ip nat inside source static
[Link] [Link] redundancy HSRP1
Step 4 ip classless Enables a device to forward packets that are destined for
a subnet of a network that has no network default route,
Example: to the best supernet route possible.
Device(config)# ip classless
Example:
Device(config)# ip route [Link]
[Link] gigabitethernet 0/0/0
Example:
Device(config)# no ip http server
Step 8 show ip nat translations [verbose] (Optional) Displays active NAT translations.
Example:
Device# show ip nat translations verbose
interface BVI10
ip address [Link] [Link].0
no ip redirects
ip nat inside
standby 10 priority 105 preempt
standby 10 name HSRP1
standby 10 ip [Link]
standby 10 track gigabitethernet1/1/1
!
!
ip default-gateway [Link]
ip nat inside source static [Link] [Link] redundancy HSRP1
ip classless
ip route [Link] [Link] gigabitethernet1/1/1
ip route [Link] [Link] gigabitethernet1/1/1
no ip http server
interface BVI10
ip address [Link] [Link].0
no ip redirects
ip nat inside
standby 10 priority 100 preempt
standby 10 name HSRP1
standby 10 ip [Link]
standby 10 track gigabitethernet0/0/1
!
ip default-gateway [Link]
ip nat inside source static [Link] [Link] redundancy HSRP1
ip classless
ip route [Link] 255.255.255 gigabitethernet0/0/1
ip route [Link] [Link] gigabitethernet0/0/1
no ip http server
NAT commands: complete command syntax, Cisco IOS IP Addressing Services Command
command mode, command history, usage guidelines, Reference
and examples
Using NAT with MPLS VPNs “Integrating NAT with MPLS VPNs” module
Standard/RFC Title
RFC 903 Reverse Address Resolution Protocol
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
active and the other standby. This feature supports VRF-aware NAT translation and Carrier Grade NAT
(CGN) mode.
This feature supports the LAN-LAN topology as well as the LAN-WAN topology. In the LAN-WAN topology,
only symmetric routing is supported.
When an Address Resolution Protocol (ARP) query is triggered for an address that is configured with dynamic
NAT mapping and owned by the device, NAT responds with the burned-in MAC (BIA MAC) address on the
interface to which the ARP is pointing. You must enable and configure the NAT inside interfaces of the active
and standby devices to belong to a group.
In Cisco IOS XE Denali 16.3 release, the Allow same ACL/router-map on multiple NAT statements feature
was introduced to support usage of same ACL for configuring both dynamic mapping and static mapping in
NAT. Dynamic mapping is given the precedence over static mapping regardless of the configuration order.
The precedence of dynamic mapping over static mapping using the sequence number of the class ensures
class order consistency in NAT.
Gratuitous ARP
When a host sends an ARP request to resolve its own IP address, it is called gratuitous ARP. In the ARP
request packet, the source and destination IP addresses are filled with the same source IP address itself. The
destination MAC address is the Ethernet broadcast address.
When a router becomes active, it broadcasts a gratuitous ARP packet with the Hot Standby Router Protocol
(HSRP) virtual MAC address to the affected LAN segment. If the segment uses an Ethernet switch, this allows
the switch to change the location of the virtual MAC address so that packets flow to the new router instead
of the one that is no longer active. End devices do not actually need gratuitous ARP if routers use the default
HSRP MAC address.
1. enable
2. configure terminal
3. track object-number interface type number {ip | ipv6 | line-protocol}
4. exit
5. interface type number
6. ip nat inside
7. ip address ip-address mask
8. standby group-number ip [ip-address]
9. standby use-bia
10. standby group-number priority priority
11. standby group-number preempt [delay]
12. standby group-number track object-number [decrement priority-decrement]
13. exit
14. ip nat pool pool-name start-ipend-ip netmask netmask
15. access-list standard-access-list permit ip-address mask
16. ip nat inside source list list-name pool pool-name [overload]
17. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 track object-number interface type number {ip | Configures an interface to be tracked where the Gateway Load
ipv6 | line-protocol} Balancing Protocol (GLBP) weighting changes based on the state
of the interface
Example:
Device(config)# track 10 interface
gigabitethernet 0/0/0 line-protocol
Step 5 interface type number Configures an interface and enters interface configuration mode.
Example:
Device(config)# interface gigabitethernet
1/2/1
Step 6 ip nat inside Connects the interface to the inside network, which is subject to
Network Address Translation (NAT).
Example:
Device(config-f)# ip nat inside
Step 7 ip address ip-address mask Sets a primary or secondary IP address for an interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 8 standby group-number ip [ip-address] Activates the Hot Standby Router Protocol (HSRP).
Example:
Device(config-if)# standby 1 ip [Link]
Step 9 standby use-bia Configures HSRP to use the burned-in address of the interface as
its virtual MAC address, instead of the preassigned MAC address
Example: or the functional address.
Device(config-if)# standby use-bia
Step 11 standby group-number preempt [delay] Configures HSRP preemption and preemption delay.
• If you configure this command, when a local device has an
Example: HSRP priority higher than the current active device, the
Device(config-if)# standby 1 preempt
local device assumes control as the active device. If
preemption is not configured, the local device assumes
control as the active device only if it receives information
indicating no device is in the active state (acting as the
designated device).
Step 14 ip nat pool pool-name start-ipend-ip netmask Defines a pool of IP addresses for Network Address Translation
netmask (NAT) translations.
Example:
Device(config)# ip nat pool pool1 [Link]
[Link] netmask [Link]
Example:
Device(config)# acces-list 1 permit
[Link] [Link]
Step 16 ip nat inside source list list-name pool pool-name Enables NAT of the inside source address.
[overload]
• When overloading is configured, it enables the device to use
one global address for many local addresses. The TCP or
Example: UDP port number of each inside host distinguishes between
Device(config)# ip nat inside source list
list1 pool pool1 overload the multiple conversations using the same local IP address.
Step 17 end Exits global configuration mode and returns to privileged EXEC
mode.
Example:
Device(config)# end
The following example shows a LAN-WAN configuration for dynamic Network Address Translation (NAT)
overload mapping with Hot Standby Router Protocol (HSRP). A virtual routing and forwarding (VRF) instance
is enabled for this configuration. Devices that are configured with NAT do not have any route configurations
related to HSRP Virtual IP Address (VIP). LAN users using static routes have to set the default route or
next-hop to the HSRP VIP; for example configure the ip route [Link] [Link] [Link] command.
! Active device configuration:
Device# configure terminal
Device(config)# vrf definition vrf1
Device(config-vrf)# exit
Device(config)# track 10 interface fastethernet 1/1/1 line-protocol
Device(config-track)# exit
Device(config)# interface fastethernet 1/1/0
Device(config-if)# vrf forwarding vrf1
Device(config-if)# ip nat inside
Device(config-if)# ip address [Link] [Link]
Device(config-if)# standby 1 ip [Link]
Device(config-if)# standby use-bia
Device(config-if)# standby 1 priority 120
Device(config-if)# standby 1 preempt
Device(config-if)# standby 1 track 10 decrement 15
Device(config-if)# exit
SUMMARY STEPS
1. enable
2. show arp
3. show ip alias
4. show ip nat translations
5. show standby brief
DETAILED STEPS
Step 1 enable
Example:
Device> enable
enables privileged EXEC mode.
• Enter your password if prompted.
Example:
Device# show arp
Example:
Device# show ip alias
Example:
Device# show ip nat translations
Example:
Device# show standby brief
Static NAT with HSRP "Static NAT Mapping with HSRP" module of the IP
Addressing: NAT Configuration Guide
Standard/RFC Title
RFC 826 An Ethernet Address Resolution Protocol or
Converting Network Protocol Addresses
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Table 6: Feature Information for VRF-Aware Dynamic NAT Mapping with HSRP
Allow same Cisco IOS XE Denali The Allow use of same ACL/router-map on multiple
ACL/router-map on 16.3.1 NAT statements feature supports usage of same ACL
multiple NAT for configuring both dynamic mapping and static
statements mapping in NAT. Dynamic mapping is given the
precedence over static mapping regardless of the
configuration order. The precedence of dynamic
mapping over static mapping using the sequence
number of the class ensures class order consistency
in NAT.
This feature uses no new or modified commands.
Note For a standalone NAT router, shut down the NAT interfaces before you make a configuration change.
The pairs of redundant interfaces are configured with the same unique ID number known as the redundant
interface identifier (RII).
The status of redundancy group members is determined through the use of hello messages sent over the control
link. The software considers either device not responding to a hello message within a configurable amount
of time to be a failure and initiates a switchover. For the software to detect a failure in milliseconds, control
links run the failover protocol that is integrated with the Bidirectional Forwarding Detection (BFD) protocol.
You can configure the following parameters for hello messages:
• Hello time—Interval at which hello messages are sent.
• Hold time—Amount of time before which the active or standby device is declared to be down.
The hello time defaults to 3 seconds to align with the Hot Standby Router Protocol (HSRP), and the hold time
defaults to 10 seconds. You can also configure these timers in milliseconds by using the timers hellotime
msec command.
To determine the pairs of interfaces that are affected by the switchover, you must configure a unique ID for
each pair of redundant interfaces. This ID is known as the RII that is associated with the interface.
A switchover to the standby device can occur when the priority setting that is configured on each device
changes. The device with the highest priority value acts as the active device. If a fault occurs on either the
active or standby device, the priority of the device is decremented by a configurable amount known as the
weight. If the priority of the active device falls below the priority of the standby device, a switchover occurs
and the standby device becomes the active device. This default behavior can be overridden by disabling the
preemption attribute for the RG. You can also configure each interface to decrease the priority when the Layer
1 state of the interface goes down. The priority that is configured overrides the default priority of an RG.
Each failure event that causes a modification of an RG priority generates a syslog entry that contains a time
stamp, the RG that was affected, the previous priority, the new priority, and a description of the failure event
cause.
A switchover also can occur when the priority of a device or interface falls below a configurable threshold
level.
A switchover to the standby device occurs under the following circumstances:
• Power loss or a reload occurs on the active device (including reloads).
• The run-time priority of the active device goes below that of the standby device (with preempt configured).
• The run-time priority of the active device goes below that of the configured threshold.
• The redundancy group on the active device is reloaded manually. Use the redundancy application
reload group rg-number command for a manual reload.
LAN-LAN Topology
The figure below shows the LAN-LAN topology. In a LAN-LAN topology, all participating devices are
connected to each other through LAN interfaces on both the inside and the outside. In this scenario, traffic is
often directed to the correct firewall if static routing is configured on the upstream or downstream devices to
an appropriate virtual IP address. Cisco ASR 1000 Aggregation Services Routers participate in dynamic
routing with upstream or downstream devices. The dynamic routing configuration supported on LAN-facing
interfaces must not introduce a dependency on the routing protocol convergence; otherwise, fast failover
requirements will not be met.
SUMMARY STEPS
1. enable
2. configure terminal
3. redundancy
4. mode none
5. application redundancy
6. protocol number
7. name instance-name
8. timers hellotime [msec] number holdtime [msec] number
9. authentication {text string | md5 key-string [0 | 7] key | md5 key-chain key-chain-name}
10. bfd
11. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Step 4 mode none Sets the redundancy mode to none, which is required for this
feature.
Example:
Device(config-red)# mode none
Example:
Device(config-red)# application redundancy
Step 6 protocol number Specifies the protocol instance that will be attached to a
control interface, and enters redundancy application protocol
Example: configuration mode.
Device(config-red-app)# protocol 4
Example:
Device(config-red-app-prot)# name rg1
Step 8 timers hellotime [msec] number holdtime [msec] Specifies the interval between hello messages sent and the
number time before a device is declared to be down.
• The default time for hello time is 3 seconds and for hold
Example: time is 10 seconds.
Device(config-red-app-prot)# timers hellotime
3 holdtime 10
Example:
Device(config-red-app-prot)# authentication
text password
SUMMARY STEPS
1. enable
2. configure terminal
3. redundancy
4. application redundancy
5. group {1 | 2}
6. name group-name
7. preempt
8. priority number failover-threshold number
9. track object-number [decrement number | shutdown]
10. timers delay seconds [reload seconds]
11. control interface-name protocol instance
12. data interface-name
13. To create another redundancy group, repeat Steps 3 through 12.
14. end
15. configure terminal
16. interface type number
17. redundancy group number ip address exclusive [decrement number]
18. redundancy rii number
19. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Example:
Device(config-red)# application redundancy
Step 6 name group-name (Optional) Specifies an optional alias for the protocol
instance.
Example:
Device(config-red-app-grp)# name rg1
Step 7 preempt Enables preemption on the group and enables the standby
device to preempt the active device regardless of which
Example: device has higher priority.
Device(config-red-app-grp)# preempt
Step 8 priority number failover-threshold number Specifies the initial priority and failover threshold for the
redundancy group.
Example:
Device(config-red-app-grp)# priority 120
failover-threshold 80
Step 9 track object-number [decrement number | shutdown] Specifies the amount by which the priority of a redundancy
group will be decremented if an event occurs.
Example: • You can track multiple objects that influence the
Device(config-red-app-grp)# track 44 decrement
20 priority of the redundancy group.
Step 10 timers delay seconds [reload seconds] Specifies the amount of time by which the redundancy group
will delay role negotiations that start after a fault occurs or
Example: after the system is reloaded.
Device(config-red-app-grp)# timers delay 10
reload 20
Step 11 control interface-name protocol instance Specifies the control interface that is used by the redundancy
group.
Example: • This interface is also associated with an instance of the
Device(config-red-app-grp)# control
GigabitEthernet0/1/0 protocol 1 control interface protocol.
Step 12 data interface-name Specifies the data interface that is used by the redundancy
group.
Example:
Device(config-red-app-grp)# data
GigabitEthernet0/1/2
Example:
Device# configure terminal
Step 16 interface type number Selects an interface to associate with the redundancy group
and enters interface configuration mode.
Example:
Device(config)# interface gigabitethernet
0/0/1
Step 17 redundancy group number ip address exclusive Associates the interface with the redundancy group identified
[decrement number] by the number argument.
Example:
Device(config-if)# redundancy group 1 ip
[Link] exclusive decrement 20
Step 18 redundancy rii number Specifies a number for the RII associated with this interface.
• This number must match the RII of the other interface
Example: in the redundancy group.
Device(config-if)# redundancy rii 40
1. enable
2. configure terminal
3. interface type number
4. ip address ip-address mask
5. ip nat outside
6. ip virtual-reassembly
7. negotiation auto
8. redundancy rii number
9. redundancy group number ip address exclusive [decrement number]
10. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet
0/1/5
Step 4 ip address ip-address mask Sets a primary or secondary IP address for an interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 5 ip nat outside Configures the outside interface for IP address translation.
Example:
Device(config-if)# ip nat outside
Step 7 negotiation auto Enables the autonegotiation protocol to configure the speed,
duplex, and automatic flow control of the Gigabit Ethernet
Example: interface.
Device(config-if)# negotiation auto
Step 8 redundancy rii number Specifies a number for the redundancy interface identifier
(RII) that is associated with this interface.
Example: • This number must match the RII of the other interface
Device(config-if)# redundancy rii 200
in the redundancy group.
Step 9 redundancy group number ip address exclusive Associates the interface with the redundancy group identified
[decrement number] by the number argument.
Example:
Device(config-if)# redundancy group 1 ip
[Link] exclusive decrement 10
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
4. ip nat inside source list {{access-list-number | access-list-name} | route-map name} pool name
[redundancy redundancy-id [mapping-id map-id | overload | reversible | vrf name]]
5. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of IP addresses for NAT.
prefix-length prefix-length}
Example:
Device(config)# ip nat pool VPN-18 [Link]
[Link] netmask [Link]
Step 4 ip nat inside source list {{access-list-number | access-list-name} Enables NAT of the inside source address.
| route-map name} pool name [redundancy redundancy-id
[mapping-id map-id | overload | reversible | vrf name]] • You must use a mapping ID to associate NAT
with the redundancy group.
Example:
Device(config)# ip nat inside source list acl-18 pool
VPN-18 redundancy 2 mapping-id 152
SUMMARY STEPS
1. enable
2. redundancy application reload group number [peer | self]
3. show redundancy application group [group-id | all]
4. show redundancy application transport {clients | group [group-id]}
5. show redundancy application protocol {protocol-id | group [group-id]}
6. show redundancy application faults group [group-id]
7. show redundancy application if-mgr group [group-id]
8. show redundancy application control-interface group [group-id]
9. show redundancy application data-interface group [group-id]
10. show monitor event-trace rg_infra all
DETAILED STEPS
Step 2 redundancy application reload group number [peer | Forces the active redundancy group (RG) to reload and
self] the standby RG to become the active RG.
• Use the redundancy application reload command
Example: to verify if the redundancy configuration is working.
Device# redundancy application reload group 2 self
You must enter this command on the active RG.
Step 3 show redundancy application group [group-id | all] Displays summary information for the specified group or
for all groups.
Example:
Device# show redundancy application group 2
Step 4 show redundancy application transport {clients | group Displays transport information for the specified group or
[group-id]} for all groups.
Example:
Device# show redundancy application transport group
2
Step 5 show redundancy application protocol {protocol-id | Displays protocol information for the specified group or
group [group-id]} for all groups.
Example:
Device# show redundancy application protocol 2
Step 7 show redundancy application if-mgr group [group-id] Displays information about the interface manager (if-mgr)
for the specified group or for all groups.
Example:
Device# show redundancy application if-mgr group
2
Step 8 show redundancy application control-interface group Displays interface information associated with redundancy
[group-id] groups for the specified control interface.
Example:
Device# show redundancy application
control-interface group IF-2
Step 9 show redundancy application data-interface group Displays interface information associated with redundancy
[group-id] groups for the specified data interface.
Example:
Device# show redundancy application data-interface
group IF-2
Step 10 show monitor event-trace rg_infra all Displays event trace information associated with all
redundancy groups.
Example:
Device# show monitor event-trace rg_infra all
IP addressing commands: complete command Cisco IOS IP Addressing Services Command Reference
syntax, command mode, command history,
defaults, usage guidelines, and examples
Standards/RFCs Title
RFC 791 Internet Protocol
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
The following features are not supported by the VRF-Aware Asymmetric Routing Support feature:
• Cisco Trustsec
• Edge switching services
• Header compression
• IPsec
• Policy Based Routing (PBR)
• Port bundle
• Lawful intercept
• Layer 2 Tunneling Protocol (L2TP)
• Locator/ID Separation Protocol (LISP) inner packet inspection
• Secure Shell (SSL) VPN
• Session Border Controller (SBC)
The figure below shows an asymmetric routing scenario with a separate asymmetric-routing interlink interface
to divert packets to the active RG.
Asymmetric routing consists of an interlink interface that handles all traffic that is to be diverted. The bandwidth
of the asymmetric-routing interlink interface must be large enough to handle all expected traffic that is to be
diverted. An IPv4 address must be configured on the asymmetric-routing interlink interface, and the IP address
of the asymmetric routing interface must be reachable from this interface.
Note We recommend that the asymmetric-routing interlink interface be used for interlink traffic only and not
be shared with high availability control or data interfaces because the amount of traffic on the
asymmetric-routing interlink interface could be quite high.
Note The firewall does not support the asymmetric-routing always-divert enable command that diverts packets
received on the standby RG to the active RG. By default, the firewall forces all packet flows to be diverted
to the active RG.
VRF-Aware Software Infrastructure (VASI) support was added in Cisco IOS XE Release 3.16S. Multiprotocol
Label Switching (MPLS) asymmetric routing is also supported.
In Cisco IOS XE Release 3.16S, NAT supports asymmetric routing with ALGs, Carrier Grade NAT (CGN),
and virtual routing and forwarding (VRF) instances. No configuration changes are required to enable asymmetric
routing with ALGs, CGN, or VRF. For more information, see the section, “Example: Configuring Asymmetric
Routing with VRF”.
When diverted packets reach the active device on which Network Address Translation (NAT) and the
zone-based firewall are configured, the firewall retrieves the VRF ID from NAT or NAT64 and saves the
VRF ID in the firewall session key.
The following section describes the asymmetric routing packet flow when only the zone-based firewall is
configured on a device:
• When MPLS is configured on a device, the VRF ID handling for diverted packets is the same as the
handling of non-asymmetric routing diverted packets. An MPLS packet is diverted to the active device,
even though the MPLS label is removed at the standby device. The zone-based firewall inspects the
packet at the egress interface, and the egress VRF ID is set to zero, if MPLS is detected at this interface.
The firewall sets the ingress VRF ID to zero if MPLS is configured at the ingress interface.
• When a Multiprotocol Label Switching (MPLS) packet is diverted to the active device from the standby
device, the MPLS label is removed before the asymmetric routing diversion happens.
• When MPLS is not configured on a device, an IP packet is diverted to the active device and the VRF
ID is set. The firewall gets the local VRF ID, when it inspects the packet at the egress interface.
VRF mapping between active and standby devices require no configuration changes.
• Failover threshold
• Group instance
• Group name
• Initialization delay timer
SUMMARY STEPS
1. enable
2. configure terminal
3. redundancy
4. application redundancy
5. group id
6. name group-name
7. priority value [failover threshold value]
8. preempt
9. track object-number decrement number
10. exit
11. protocol id
12. timers hellotime {seconds | msec msec} holdtime {seconds | msec msec}
13. authentication {text string | md5 key-string [0 | 7] key [timeout seconds] | key-chain key-chain-name}
14. bfd
15. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Step 6 name group-name Specifies an optional alias for the protocol instance.
Example:
Device(config-red-app-grp)# name group1
Step 7 priority value [failover threshold value] Specifies the initial priority and failover threshold for a
redundancy group.
Example:
Device(config-red-app-grp)# priority 100
failover threshold 50
Step 8 preempt Enables preemption on the redundancy group and enables the
standby device to preempt the active device.
Example: • The standby device preempts only when its priority is
Device(config-red-app-grp)# preempt
higher than that of the active device.
Step 9 track object-number decrement number Specifies the priority value of a redundancy group that will be
decremented if an event occurs on the tracked object.
Example:
Device(config-red-app-grp)# track 50
decrement 50
Step 11 protocol id Specifies the protocol instance that will be attached to a control
interface and enters redundancy application protocol
Example: configuration mode.
Device(config-red-app)# protocol 1
Step 12 timers hellotime {seconds | msec msec} holdtime Specifies the interval between hello messages sent and the time
{seconds | msec msec} period before which a device is declared to be down.
• Holdtime should be at least three times the hellotime.
Example:
Device(config-red-app-prtcl)# timers
hellotime 3 holdtime 10
Example:
Device(config-red-app-prtcl)# authentication
md5 key-string 0 n1 timeout 100
Step 14 bfd Enables the integration of the failover protocol running on the
control interface with the Bidirectional Forwarding Detection
Example: (BFD) protocol to achieve failure detection in milliseconds.
Device(config-red-app-prtcl)# bfd
• BFD is enabled by default.
Note Asymmetric routing, data, and control must be configured on separate interfaces for zone-based firewall.
However, for Network Address Translation (NAT), asymmetric routing, data, and control can be configured
on the same interface.
SUMMARY STEPS
1. enable
2. configure terminal
3. redundancy
4. application redundancy
5. group id
6. data interface-type interface-number
7. control interface-type interface-number protocol id
8. timers delay seconds [reload seconds]
9. asymmetric-routing interface type number
10. asymmetric-routing always-divert enable
11. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Step 6 data interface-type interface-number Specifies the data interface that is used by the RG.
Example:
Device(config-red-app-grp)# data GigabitEthernet
0/0/1
Step 8 timers delay seconds [reload seconds] Specifies the time required for an RG to delay role
negotiations that start after a fault occurs or the system is
Example: reloaded.
Device(config-red-app-grp)# timers delay 100
reload 400
Step 9 asymmetric-routing interface type number Specifies the asymmetric routing interface that is used by
the RG.
Example:
Device(config-red-app-grp)# asymmetric-routing
interface GigabitEthernet 0/1/1
Step 10 asymmetric-routing always-divert enable Always diverts packets received from the standby RG to
the active RG.
Example:
Device(config-red-app-grp)# asymmetric-routing
always-divert enable
Note • You must not configure a redundant interface identifier (RII) on an interface that is configured either
as a data interface or as a control interface.
• You must configure the RII and asymmetric routing on both active and standby devices.
• You cannot enable asymmetric routing on the interface that has a virtual IP address configured.
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. redundancy rii id
5. redundancy group id [decrement number]
6. redundancy asymmetric-routing enable
7. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 interface type number Selects an interface to be associated with the redundancy group
(RG) and enters interface configuration mode.
Example:
Device(config)# interface GigabitEthernet
0/1/3
Example:
Device(config-if)# redundancy rii 600
Step 5 redundancy group id [decrement number] Enables the RG redundancy traffic interface configuration and
specifies the amount to be decremented from the priority when
Example: the interface goes down.
Device(config-if)# redundancy group 1
decrement 20 Note You need not configure an RG on the traffic interface
on which asymmetric routing is enabled.
Step 6 redundancy asymmetric-routing enable Establishes an asymmetric flow diversion tunnel for each RG.
Example:
Device(config-if)# redundancy
asymmetric-routing enable
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. ip address ip-address mask
5. ip nat outside
6. exit
7. redundancy
8. application redundancy
9. group id
10. asymmetric-routing always-divert enable
11. end
12. configure terminal
13. ip nat pool name start-ip end-ip {mask | prefix-length prefix-length}
14. exit
15. ip nat inside source list acl-number pool name redundancy redundancy-id mapping-id map-id
16. access-list standard-acl-number permit source-address wildcard-bits
17. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/1/3
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
Example:
Device(config-red-app-grp)# asymmetric-routing
always-divert enable
Example:
Device# configure terminal
Step 13 ip nat pool name start-ip end-ip {mask | prefix-length Defines a pool of global addresses.
prefix-length}
• Enters IP NAT pool configuration mode.
Example:
Device(config)# ip nat pool pool1 prefix-length
24
Step 14 exit Exits IP NAT pool configuration mode and enters global
configuration mode.
Example:
Device(config-ipnat-pool)# exit
Step 15 ip nat inside source list acl-number pool name Enables NAT of the inside source address and associates
redundancy redundancy-id mapping-id map-id NAT with a redundancy group by using the mapping ID.
Example:
Device(config)# ip nat inside source list pool
pool1 redundancy 1 mapping-id 100
Step 16 access-list standard-acl-number permit source-address Defines a standard access list for the inside addresses
wildcard-bits that are to be translated.
Example:
Device(config)# access-list 10 permit [Link]
[Link]
Device(config)# redundancy
Device(config-red)# application redundancy
Device(config-red-app)# group 1
Device(config-red-app-grp)# asymmetric-routing always-divert enable
Device(config-red-app-grp)# end
Device# configure terminal
Device(config)# ip nat pool pool1 prefix-length 24
Device(config-ipnat-pool)# exit
Device(config)# ip nat inside source list pool pool1 redundancy 1 mapping-id 100
Device(config)# access-list 10 permit [Link] [Link]
!
ip prefix-list VRF_Pool seq 5 permit [Link]/27
ip prefix-list p1-adv-1 seq 5 permit [Link]/27
ip prefix-list p1-exist-1 seq 5 permit [Link]/27
logging esm config
access-list 4 permit [Link] [Link]
!
control-plane
line console 0
stopbits 1
!
line vty 0 3
login
!
line vty 4
password lab
login
!
end
Security commands
• Cisco IOS Security Command Reference
Commands A to C
• Cisco IOS Security Command Reference
Commands D to L
• Cisco IOS Security Command Reference
Commands M to R
• Cisco IOS Security Command Reference
Commands S to Z
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 8: Feature Information for Interchassis Asymmetric Routing Support for Zone-Based Firewall and NAT
Interchassis Asymmetric Routing Cisco IOS XE Release 3.5S The Interchassis Asymmetric Routing
Support for Zone-Based Firewall Support for Zone-Based Firewall and NAT
and NAT feature supports the forwarding of packets
from a standby redundancy group to the
active redundancy group for packet
handling.
The following commands were introduced
or modified: asymmetric-routing,
redundancy asymmetric-routing enable.
VRF-Aware Interchassis Cisco IOS XE Release NAT supports the VRF-Aware Interchassis
Asymmetric Routing Support for 3.14S Asymmetric Routing feature. This feature
NAT supports MPLS. There are no configuration
changes for this feature.
No commands were introduced or modified.
Note In some cases you might experience FTP disconnection after failover in a NAT B2B scenario. To resolve
this issue, quit the existing FTP connection and start a new FTP connection.
Redundant devices are joined by a configurable control link and a data synchronization link. The control link
is used to communicate the status of devices. The data synchronization link is used to transfer stateful
information from Network Address Translation (NAT) and the firewall and synchronize the stateful database.
The pairs of redundant interfaces are configured with the same unique ID number known as the redundant
interface identifier (RII).
The status of redundancy group members is determined through the use of hello messages sent over the control
link. The software considers either device not responding to a hello message within a configurable amount
of time to be a failure and initiates a switchover. For the software to detect a failure in milliseconds, control
links run the failover protocol that is integrated with the Bidirectional Forwarding Detection (BFD) protocol.
You can configure the following parameters for hello messages:
• Hello time—Interval at which hello messages are sent.
• Hold time—Amount of time before which the active or standby device is declared to be down.
The hello time defaults to 3 seconds to align with the Hot Standby Router Protocol (HSRP), and the hold time
defaults to 10 seconds. You can also configure these timers in milliseconds by using the timers hellotime
msec command.
To determine the pairs of interfaces that are affected by the switchover, you must configure a unique ID for
each pair of redundant interfaces. This ID is known as the RII that is associated with the interface.
A switchover to the standby device can occur when the priority setting that is configured on each device
changes. The device with the highest priority value acts as the active device. If a fault occurs on either the
active or standby device, the priority of the device is decremented by a configurable amount known as the
weight. If the priority of the active device falls below the priority of the standby device, a switchover occurs
and the standby device becomes the active device. This default behavior can be overridden by disabling the
preemption attribute for the RG. You can also configure each interface to decrease the priority when the Layer
1 state of the interface goes down. The priority that is configured overrides the default priority of an RG.
Each failure event that causes a modification of an RG priority generates a syslog entry that contains a time
stamp, the RG that was affected, the previous priority, the new priority, and a description of the failure event
cause.
A switchover also can occur when the priority of a device or interface falls below a configurable threshold
level.
A switchover to the standby device occurs under the following circumstances:
• Power loss or a reload occurs on the active device (including reloads).
• The run-time priority of the active device goes below that of the standby device (with preempt configured).
• The run-time priority of the active device goes below that of the configured threshold.
• The redundancy group on the active device is reloaded manually. Use the redundancy application
reload group rg-number command for a manual reload.
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Table 9: Feature Information for VRF-Aware NAT for WAN-WAN Topology with Symmetric Routing Box-to-Box Redundancy
[Link]
Note If you specify an access list to use with a NAT command, NAT does not support the commonly used
permit ip any any command in the access list.
• NAT interface--The shared access gateway interface most often is configured as the outside interface
of NAT. The inside interface of NAT can be either the PE-CE interface of a VPN, the interface to the
MPLS backbone, or both. The shared access gateway interface can also be configured as the inside
interface.
• Routing type--Common service can be Internet connectivity or a common server. For Internet connectivity,
a default route should be propagated to all the VPN customers that use the service. For common server
access, a static or dynamically learned route should be propagated to the VPN customers.
• NAT configuration--NAT can have different configurations: static, dynamic, pool/interface overloading,
and route-map.
The figure below shows a typical NAT integration with MPLS VPNs. The PE router connected to the internet
and centralized mail service is employed to do the address translation.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip netmask netmask
4. ip nat [inside | outside] source [list {access-list-number | access-list-name} | route-map name] [interface
type number | pool pool-name] vrf vrf-name[overload]
5. Repeat Step 4 for each VPN being configured
6. ip route vrf vrf-name prefix mask interface-type interface-number next-hop-address
7. Repeat Step 6 for each VPN being configured.
8. exit
9. show ip nat translations vrf vrf-name
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat pool name start-ip end-ip netmask netmask Defines a pool of IP addresses for NAT.
Example:
Router(config)# ip nat pool inside [Link] [Link]
netmask [Link]
Step 4 ip nat [inside | outside] source [list {access-list-number | Allows NAT to be configured on a particular
access-list-name} | route-map name] [interface type number | VPN.
pool pool-name] vrf vrf-name[overload]
Example:
Router(config)# ip nat inside source list 1 pool mypool
vrf shop overload
Step 6 ip route vrf vrf-name prefix mask interface-type Allows NAT to be configured on a particular
interface-number next-hop-address VPN.
Example:
Router(config)#
ip route vrf shop [Link] [Link] ethernet 0 [Link]
Example:
Router(config)# exit
Step 9 show ip nat translations vrf vrf-name (Optional) Displays the settings used by virtual
routing/forwarding (VRF) table translations.
Example:
Router# show ip nat translations vrf shop
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source {static {esp local-ip interface type number | local-ip global-ip}} [extendable |
mapping-id map-id| no-alias | no-payload | redundancy group-name | route-map | vrf name]
4. Repeat Step 3 for each VPN being configured.
5. ip route vrf vrf-name prefix prefix mask next-hop-address global
6. Repeat Step 5 for each VPN being configured.
7. exit
8. show ip nat translations vrf vrf-name
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat inside source {static {esp local-ip interface type number Enables inside static translation on the VRF.
| local-ip global-ip}} [extendable | mapping-id map-id| no-alias
| no-payload | redundancy group-name | route-map | vrf name]
Example:
Router(config)#
ip nat inside source static [Link] [Link] vrf
shop
Step 5 ip route vrf vrf-name prefix prefix mask next-hop-address Allows the route to be shared by several
global customers.
Example:
Router(config)#
ip route vrf shop [Link] [Link] [Link] global
Example:
Router(config)# exit
Step 8 show ip nat translations vrf vrf-name (Optional) Displays the settings used by VRF
translations.
Example:
Router# show ip nat translations vrf shop
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool outside global-ip local-ip netmask netmask
4. ip nat inside source static local-ip global-ip vrf vrf-name
5. Repeat Step 4 for each VRF being configured.
6. ip nat outside source static global-ip local-ip vrf vrf-name
7. exit
8. show ip nat translations vrf vrf-name
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat pool outside global-ip local-ip netmask netmask Allows the configured VRF to be associated with
the NAT translation rule.
Example:
Router(config)#
ip nat pool outside [Link] [Link] netmask
[Link]
Step 4 ip nat inside source static local-ip global-ip vrf vrf-name Allows the route to be shared by several customers.
Example:
Router(config)#
ip nat inside source static [Link] [Link]
vrf shop
Step 5 Repeat Step 4 for each VRF being configured. Allows the route to be shared by several customers.
Example:
Router(config)#
ip nat outside source static [Link] [Link] vrf
shop
Example:
Router(config)# exit
Step 8 show ip nat translations vrf vrf-name (Optional) Displays the settings used by VRF
translations.
Example:
Router# show ip nat translations vrf shop
SUMMARY STEPS
1. enable
2. configure {terminal | memory | network}
3. ip nat pool inside global-ip local-ip netmask netmask
4. Repeat Step 3 for each pool being configured.
5. ip nat inside source list access-list-number pool pool-name vrf vrf-name
6. Repeat Step 5 for each pool being configured.
7. ip nat outside source static global-ip local-ip vrf vrf-name
8. Repeat Step 7 for all VPNs being configured.
9. exit
10. show ip nat translations vrf vrf-name
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat pool inside global-ip local-ip netmask netmask Allows the configured VRF to be associated with
the NAT translation rule.
Example:
Router(config)# ip nat pool inside1 [Link] [Link]
netmask [Link]
Step 5 ip nat inside source list access-list-number pool pool-name Allows the route to be shared by several
vrf vrf-name customers.
Example:
Router(config)#
ip nat inside source list 1 pool inside2 vrf shop
Step 6 Repeat Step 5 for each pool being configured. Defines the access list.
Step 7 ip nat outside source static global-ip local-ip vrf vrf-name Allows the route to be shared by several
customers.
Example:
Router(config)#
ip nat outside source static [Link] [Link] vrf
shop
Example:
Router(config)# exit
Step 10 show ip nat translations vrf vrf-name (Optional) Displays the settings used by VRF
translations.
Example:
Router# show ip nat translations vrf shop
!
ip nat pool inside [Link] [Link] netmask [Link]
ip nat inside source list 1 pool inside vrf bank overload
ip nat inside source list 1 pool inside vrf park overload
ip nat inside source list 1 pool inside vrf shop overload
!
ip route vrf shop [Link] [Link] Ethernet1/3 [Link]
ip route vrf bank [Link] [Link] Ethernet1/3 [Link]
ip route vrf park [Link] [Link] Ethernet1/3 [Link]
!
access-list 1 permit [Link] [Link]
!
ip nat inside source static [Link] [Link] vrf shop
ip nat inside source static [Link] [Link] vrf shop
ip nat inside source static [Link] [Link] vrf bank
ip nat inside source static [Link] [Link] vrf bank
ip nat inside source static [Link] [Link] vrf park
ip nat inside source static [Link] [Link] vrf park
ip nat inside source static [Link] [Link] vrf shop
ip nat inside source static [Link] [Link] vrf shop
ip nat inside source static [Link] [Link] vrf shop
!
ip route [Link] [Link] Ethernet1/0 [Link]
ip route [Link] [Link] Ethernet1/0 [Link]
ip route [Link] [Link] Serial2/1.1 [Link]
ip route [Link] [Link] Serial2/1.1 [Link]
ip route [Link] [Link] FastEthernet0/0 [Link]
ip route [Link] [Link] FastEthernet0/0 [Link]
ip route [Link] [Link] Ethernet1/0 [Link]
ip route [Link] [Link] Ethernet1/0 [Link]
ip route [Link] [Link] Ethernet1/0 [Link]
!
ip nat pool outside [Link] [Link] netmask [Link]
ip nat inside source static [Link] [Link] vrf shop
ip nat inside source static [Link] [Link] vrf shop
ip nat inside source static [Link] [Link] vrf bank
ip nat inside source static [Link] [Link] vrf bank
ip nat inside source static [Link] [Link] vrf park
!
ip default-gateway [Link]
ip nat pool inside1 [Link] [Link] netmask [Link]
ip nat pool inside2 [Link] [Link] netmask [Link]
ip nat pool inside3 [Link] [Link] netmask [Link]
ip nat inside source list 1 pool inside2 vrf bank
ip nat inside source list 1 pool inside3 vrf park
ip nat inside source list 1 pool inside1 vrf shop
ip nat outside source static [Link] [Link] vrf bank
ip nat outside source static [Link] [Link] vrf park
ip nat outside source static [Link] [Link] vrf shop
ip classless
ip route [Link] [Link] Ethernet1/0 [Link]
ip route [Link] [Link] Serial2/1.1 [Link]
ip route [Link] [Link] FastEthernet0/0 [Link]
ip route vrf shop [Link] [Link] [Link] global
ip route vrf bank [Link] [Link] [Link] global
ip route vrf park [Link] [Link] [Link] global
no ip http server
!
access-list 1 permit [Link] [Link]
Where to Go Next
• To learn about Network Address Translation and configure NAT for IP address conservation, see the
“Configuring NAT for IP Address Conservation” module.
• To verify, monitor, and maintain NAT, see the “Monitoring and Maintaining NAT” module.
• To use NAT with application level gateways, see the “Using Application Level Gateways with NAT”
module.
• To configure NAT for high availability, see the “Configuring NAT for High Availability” module.
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 10: Feature Information for Integrating NAT with MPLS VPNs
Translation Entries
Translation entry information includes the following:
• The protocol of the port identifying the address.
• The legitimate IP address that represents one or more inside local IP addresses to the outside world.
• The IP address assigned to a host on the inside network; probably not a legitimate address assigned by
the NIC or service provider.
• The IP address of an outside host as it appears to the inside network; probably not a legitimate address
assigned by the NIC or service provider.
• The IP address assigned to a host on the outside network by its owner.
• The time since the entry was created (in hours:minutes:seconds).
• The time since the entry was last used (in hours:minutes:seconds).
• Flags indicating the type of translation. Possible flags are:
• extended—Extended translation.
• static—Static translation.
• destination—Rotary translation.
• outside—Outside translation.
• timing out—Translation will no longer be used, due to a TCP finish (FIN) or reset (RST) flag.
Statistical Information
Statistical information includes the following:
• The total number of translations active in the system. This number is incremented each time a translation
is created and is decremented each time a translation is cleared or times out.
• A list of interfaces marked as outside with the ip nat outside command.
• A list of interfaces marked as inside with the ip nat inside command.
• The number of times the software does a translations table lookup and finds an entry.
• The number of times the software does a translations table lookup, fails to find an entry, and must try
to create one.
• A cumulative count of translations that have expired since the router was booted.
• Information about dynamic mappings.
• Information about an inside source translation.
• The access list number being used for the translation.
• The name of the pool.
• The number of translations using this pool.
• The IP network mask being used in the pool.
• The starting IP address in the pool range.
• The ending IP address in the pool range.
• The type of pool. Possible types are generic or rotary.
• The number of addresses in the pool available for translation.
• The number of addresses being used.
• The number of failed allocations from the pool.
NAT does not support access control lists (ACLs) with the log option. The same functionality can be achieved
by using one of the following options:
• By having a physical interface or virtual LAN (VLAN) with the logging option
• By using NetFlow
1. enable
2. show ip nat translations [verbose]
3. show ip nat statistics
DETAILED STEPS
Step 2 show ip nat translations [verbose] (Optional) Displays active NAT translations.
Example:
Device# show ip nat translations
Step 3 show ip nat statistics (Optional) Displays active NAT translation statistics.
Example:
Device# show ip nat statistics
Example:
The following is sample output from the show ip nat translations command:
Device# show ip nat translations
SUMMARY STEPS
1. enable
2. clear ip nat translation inside global-ip local-ip outside local-ip global-ip
3. clear ip nat translation outside global-ip local-ip
4. clear ip nat translation protocol inside global-ip global-port local-ip local-port outside local-ip
local-port global-ip global-port
5. clear ip nat translation {* | [forced] | [inside global-ip local-ip] [outside local-ip global-ip]}
6. clear ip nat translation inside global-ip local-ip [forced]
7. clear ip nat translation outside local-ip global-ip [forced]
DETAILED STEPS
Step 3 clear ip nat translation outside global-ip local-ip (Optional) Clears a single dynamic half-entry containing an
outside translation created in a dynamic configuration.
Example: • A dynamic half-entry is cleared only if it does not have any
Device# clear ip nat translation outside
[Link] [Link] child translations.
Step 4 clear ip nat translation protocol inside global-ip (Optional) Clears a UDP translation entry.
global-port local-ip local-port outside local-ip
local-port global-ip global-port
Example:
Device # clear ip nat translation udp inside
[Link] 1220 [Link] 1220 outside
[Link] 53 [Link] 53
Step 5 clear ip nat translation {* | [forced] | [inside (Optional) Clears either all dynamic translations (with the * or
global-ip local-ip] [outside local-ip global-ip]} forced keyword), a single dynamic half-entry containing an inside
translation, or a single dynamic half-entry containing an outside
Example: translation.
Device# clear ip nat translation *
• A single dynamic half-entry is cleared only if it does not
have any child translations.
Step 6 clear ip nat translation inside global-ip local-ip (Optional) Forces the clearing of a single dynamic half-entry and
[forced] its child translations containing an inside translation created in a
dynamic configuration, with or without its corresponding outside
Example: translation.
Device# clear ip nat translation inside
[Link] [Link] forced • A dynamic half-entry is always cleared, regardless of
whether it has any child translations.
Step 7 clear ip nat translation outside local-ip global-ip (Optional) Forces the clearing of a single dynamic half-entry and
[forced] its child translations containing an outside translation created in
a dynamic configuration.
Example: • A dynamic half-entry is always cleared, regardless of
Device# clear ip nat translation outside
[Link] [Link] forced whether it has any child translations.
NAT commands: complete command syntax, Cisco IOS IP Addressing Services Command
command mode, command history, defaults, usage Reference
guidelines, and examples
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
sessions are created and destroyed. Session records contain the full 5-tuple of information (the source IP
address, destination IP address, source port, destination port, and protocol). A tuple is an ordered list of
elements. NAT also sends an HSL message when a NAT pool runs out of addresses (also called pool
exhaustion). Because the pool exhaustion messages are rate limited, each packet that hits the pool exhaustion
condition does not trigger an HSL message.
The table below describes the templates for HSL bind and session create or destroy.
Table 12: Template for HSL Bind and Session Create or Destroy
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat log translations flow-export v9 udp destination addr|ipv6-destination IPv6 address vrfvrf
name source interface type interface-number
4. ip nat log translations flow-export v9 {vrf-name | global-on}
5. exit
DETAILED STEPS
Example:
Device# configure terminal
Example:
This example shows how to enable high-speed logging using an
IPv6 address
Device(config)# ip nat log translations flow-export v9
udp ipv6-destination 2001::06 5050 source GigabitEthernet
0/0/0
Example:
This example shows how to enable high-speed logging using an
IPv6 address for a destination VRF
Device(config)# ip nat log translations flow-export v9
udp ipv6-destination 2001::06 5050 vrf hslvrf source
GigabitEthernet 0/0/0
Step 4 ip nat log translations flow-export v9 {vrf-name | global-on} Enables or disables the high-speed logging of
specific NAT VPN translations.
Example:
Device(config)# ip nat log translations flow-export v9
VPN-18
Standard/RFC Title
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 14: Feature Information for Enabling NAT HIgh-Speed Logging per VRF
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to [Link]/go/cfn. An account on [Link] is not required.
Prefixes Format
A set of bits at the start of an IPv6 address is called the format prefix. Prefix length is a decimal value that
specifies how many of the leftmost contiguous bits of an address comprise the prefix.
An embedded IPv4 address is used to construct IPv4 addresses from the IPv6 packet. The Stateless NAT64
translator has to derive the IPv4 addresses that are embedded in the IPv6-translatable address by using the
prefix length. The translator has to construct an IPv6-translatable address based on the prefix and prefix length
and embed the IPv4 address based on the algorithm.
According to the IETF address format BEHAVE draft, a u-bit (bit 70) defined in the IPv6 architecture should
be set to zero. For more information on the u-bit usage, see RFC 2464. The reserved octet, also called u-octet,
is reserved for compatibility with the host identifier format defined in the IPv6 addressing architecture. When
constructing an IPv6 packet, the translator has to make sure that the u-bits are not tampered with and are set
to the value suggested by RFC 2373. The suffix will be set to all zeros by the translator. IETF recommends
that the 8 bits of the u-octet (bit range 64-71) should be set to zero.
The prefix lengths of 32, 40, 48, 56, 64, or 96 are supported for Stateless NAT64 translation. The Well Known
Prefix (WKP) is not supported. When traffic flows from the IPv4-to-IPv6 direction, either a WKP or a
configured prefix can be added only in stateful translation.
The figure below shows stateless translation for scenarios 1 and 2. An IPv6-only network communicates with
the IPv4 Internet.
Scenario 1 is an IPv6 initiated connection and scenario 2 is an IPv4 initiated connection. Stateless NAT64
translates these two scenarios only if the IPv6 addresses are IPv4 translatable. In these two scenarios, the
Stateless NAT64 feature does not help with IPv4 address depletion, because each IPv6 host that communicates
with the IPv4 Internet is a globally routable IPv4 address. This consumption is similar to the IPv4 consumption
rate as a dual-stack. The savings, however, is that the internal network is 100 percent IPv6, which eases
management (Access Control Lists, routing tables), and IPv4 exists only at the edge where the Stateless
translators live.
The figure below shows stateless translation for scenarios 5 and 6. The IPv4 network and IPv6 network are
within the same organization.
The IPv4 addresses used are either public IPv4 addresses or RFC 1918 addresses. The IPv6 addresses used
are either public IPv6 addresses or Unique Local Addresses (ULAs).
Both these scenarios consist of an IPv6 network that communicates with an IPv4 network. Scenario 5 is an
IPv6 initiated connection and scenario 6 is an IPv4 initiated connection. The IPv4 and IPv6 addresses may
not be public addresses. These scenarios are similar to the scenarios 1 and 2. The Stateless NAT64 feature
supports these scenarios if the IPv6 addresses are IPv4 translatable.
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. description string
6. ipv6 enable
7. ipv6 address {ipv6-address/prefix-length | prefix-name sub-bits/prefix-length}
8. nat64 enable
9. exit
10. interface type number
11. description string
12. ip address ip-address mask
13. nat64 enable
14. exit
15. nat64 prefix stateless ipv6-prefix/length
16. nat64 route ipv4-prefix/mask interface-type interface-number
17. ipv6 route ipv4-prefix/length interface-type interface-number
18. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ipv6 unicast-routing
Step 4 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 0/0/0
Example:
Device(config-if)# description interface facing
ipv6
Example:
Device(config-if)# ipv6 enable
Step 7 ipv6 address {ipv6-address/prefix-length | prefix-name Configures an IPv6 address based on an IPv6 general
sub-bits/prefix-length} prefix and enables IPv6 processing on an interface.
Example:
Device(config-if)# ipv6 address 2001:DB8::1/128
Example:
Device(config-if)# nat64 enable
Step 10 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 1/2/0
Example:
Device(config-if)# description interface facing
ipv4
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# nat64 enable
Step 15 nat64 prefix stateless ipv6-prefix/length Defines the Stateless NAT64 prefix to be added to the
IPv4 hosts to translate the IPv4 address into an IPv6
Example: address.
Device(config)# nat64 prefix stateless • The command also identifies the prefix that must be
2001:0db8:0:1::/96 used to create the IPv4-translatable addresses for the
IPv6 hosts.
Step 16 nat64 route ipv4-prefix/mask interface-type Routes the IPv4 traffic towards the correct IPv6 interface.
interface-number
Example:
Device(config)# nat64 route [Link]/24
gigabitethernet 0/0/0
Step 17 ipv6 route ipv4-prefix/length interface-type Routes the translated packets to the IPv4 address.
interface-number
• You must configure the ipv6 route command if your
network is not running IPv6 routing protocols.
Example:
Device(config)# ipv6 route
2001:DB8:0:1::CB00:7100/120 gigabitethernet
0/0/0
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. ipv6 address {ipv6-address/prefix-length | prefix-name sub-bits/prefix-length}
6. ipv6 enable
7. nat64 enable
8. nat64 prefix stateless v6v4 ipv6-prefix/length
9. exit
10. interface type number
11. ip address ip-address mask
12. negotiation auto
13. nat64 enable
14. exit
15. nat64 prefix stateless v4v6 ipv6-prefix/length
16. nat64 route ipv4-prefix/mask interface-type interface-number
17. ipv6 route ipv6-prefix/length interface-type interface-number
18. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Router(config)# ipv6 unicast-routing
Step 5 ipv6 address {ipv6-address/prefix-length | prefix-name Configures an IPv6 address based on an IPv6 general prefix
sub-bits/prefix-length} and enables IPv6 processing on an interface.
Example:
Device(config-if)# ipv6 address 2001:DB8::1/128
Example:
Device(config-if)# ipv6 enable
Example:
Device(config-if)# nat64 enable
Step 8 nat64 prefix stateless v6v4 ipv6-prefix/length Maps an IPv6 address to an IPv4 host for Stateless NAT 64
translation.
Example: • The NAT64 prefix in the command is the same as the
Device(config-if)# nat64 prefix stateless v6v4 prefix of the source packet that is coming from the
2001:0db8:0:1::/96 IPv6-to-IPv4 direction.
Step 10 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 1/2/0
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Router(config-if)# nat64 enable
Step 15 nat64 prefix stateless v4v6 ipv6-prefix/length Maps an IPv4 address to an IPv6 host for Stateless NAT 64
translation.
Example: • This command identifies the prefix that creates the
Device(config)# nat64 prefix stateless v4v6 IPv4-translatable addresses for the IPv6 hosts.
2001:DB8:2::/96
Step 16 nat64 route ipv4-prefix/mask interface-type Routes the IPv4 traffic towards the correct IPv6 interface.
interface-number
Example:
Device(config)# nat64 route [Link]/24
gigabitethernet 0/0/0
Step 17 ipv6 route ipv6-prefix/length interface-type Routes the translated packets to the IPv4 address.
interface-number
• You must configure the ipv6 route command if your
network is not running IPv6 routing protocols.
Example:
Device(config)# ipv6 route
2001:DB8:0:1::CB00:7100/120 gigabitethernet
0/0/0
SUMMARY STEPS
DETAILED STEPS
Example:
Device# show nat64 statistics
NAT64 Statistics
Global Stats:
Packets translated (IPv4 -> IPv6): 21
Packets translated (IPv6 -> IPv4): 15
GigabitEthernet0/0/1 (IPv4 configured, IPv6 configured):
Packets translated (IPv4 -> IPv6): 5
Packets translated (IPv6 -> IPv4): 0
Packets dropped: 0
GigabitEthernet1/2/0 (IPv4 configured, IPv6 configured):
Packets translated (IPv4 -> IPv6): 0
Packets translated (IPv6 -> IPv4): 5
Packets dropped: 0
Example:
Device# show ipv6 route
Example:
Device# show ip route
Step 4 debug nat64 {all | ha {all | info | trace | warn} | id-manager | info | issu {all | message | trace} | memory | statistics
| trace | warn}
This command enables Stateless NAT64 debugging.
Example:
Device# debug nat64 statistics
Example:
Device# ping [Link]
ipv6 unicast-routing
!
interface gigabitethernet 0/0/0
description interface facing ipv6
ipv6 enable
ipv6 address 2001:DB8::1/128
nat64 enable
!
ipv6 unicast-routing
!
interface gigabitethernet 0/0/0
ipv6 address 2001:DB8::1/128
ipv6 enable
nat64 enable
nat64 prefix stateless v6v4 2001:0db8:0:1::/96
!
interface gigabitethernet 1/2/0
ip address [Link] [Link]
negotiation auto
nat64 enable
!
nat64 prefix stateless v4v6 2001:DB8:2::/96
nat64 route [Link]/24 gigabitethernet 0/0/0
ipv6 route 2001:DB8:0:1::CB00:7100/120 gigabitethernet 0/0/0
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to [Link]/go/cfn. An account on [Link] is not required.
Glossary
ALG—application-layer gateway or application-level gateway.
FP—Forward Processor.
IPv4-converted address—IPv6 addresses used to represent the IPv4 hosts. These have an explicit mapping
relationship to the IPv4 addresses. This relationship is self-described by mapping the IPv4 address in the IPv6
address. Both stateless and stateful translators use IPv4-converted IPv6 addresses to represent the IPv4 hosts.
IPv6-converted address—IPv6 addresses that are assigned to the IPv6 hosts for the stateless translator. These
IPv6-converted addresses have an explicit mapping relationship to the IPv4 addresses. This relationship is
self-described by mapping the IPv4 address in the IPv6 address. The stateless translator uses the corresponding
IPv4 addresses to represent the IPv6 hosts. The stateful translator does not use IPv6-converted addresses,
because the IPv6 hosts are represented by the IPv4 address pool in the translator via dynamic states.
NAT—Network Address Translation.
RP—Route Processor.
stateful translation—In stateful translation a per-flow state is created when the first packet in a flow is
received. A translation algorithm is said to be stateful if the transmission or reception of a packet creates or
modifies a data structure in the relevant network element. Stateful translation allows the use of multiple
translators interchangeably and also some level of scalability. Stateful translation is defined to enable the IPv6
clients and peers without mapped IPv4 addresses to connect to the IPv4-only servers and peers.
stateless translation—A translation algorithm that is not stateful is called stateless. A stateless translation
requires configuring a static translation table, or may derive information algorithmically from the messages
it is translating. Stateless translation requires less computational overhead than stateful translation. It also
requires less memory to maintain the state, because the translation tables and the associated methods and
processes exist in a stateful algorithm and do not exist in a stateless one. Stateless translation enables the
IPv4-only clients and peers to initiate connections to the IPv6-only servers or peers that are equipped with
IPv4-embedded IPv6 addresses. It also enables scalable coordination of IPv4-only stub networks or ISP
IPv6-only networks. Because the source port in an IPv6-to-IPv4 translation may have to be changed to provide
adequate flow identification, the source port in the IPv4-to-IPv6 direction need not be changed.
When an incoming packet is stateful (if a state exists for an incoming packet), NAT64 identifies the state and
uses the state to translate the packet.
When Stateful NAT64 is configured on an interface, Virtual Fragmentation Reassembly (VFR) is configured
automatically.
constructing an IPv6 packet, the translator has to make sure that the u-bits are not tampered with and are set
to the value suggested by RFC 2373. The suffix will be set to all zeros by the translator. IETF recommends
that the 8 bits of the u-octet (bit range 64–71) be set to zero.
All subsequent IPv4-initiated packets are translated based on the previously created session.
• A new NAT64 translation is created in the session database and in the bind database. The pool and port
databases are updated depending on the configuration. The return traffic and the subsequent traffic of
the IPv6 packet flow will use this session database entry for translation.
IP Packet Filtering
Stateful Network Address Translation 64 (NAT64) filters IPv6 and IPv4 packets. All IPv6 packets that are
transmitted into the stateful translator are filtered because statefully translated IPv6 packets consume resources
in the translator. These packets consume processor resources for packet processing, memory resources (always
session memory) for static configuration, IPv4 address resources for dynamic configuration, and IPv4 address
and port resources for Port Address Translation (PAT).
Stateful NAT64 utilizes configured access control lists (ACLs) and prefix lists to filter IPv6-initiated traffic
flows that are allowed to create the NAT64 state. Filtering of IPv6 packets is done in the IPv6-to-IPv4 direction
because dynamic allocation of mapping between an IPv6 host and an IPv4 address can be done only in this
direction.
Stateful NAT64 supports endpoint-dependent filtering for the IPv4-to-IPv6 packet flow with PAT configuration.
In a Stateful NAT64 PAT configuration, the packet flow must have originated from the IPv6 realm and created
the state information in NAT64 state tables. Packets from the IPv4 side that do not have a previously created
state are dropped. Endpoint-independent filtering is supported with static Network Address Translation (NAT)
and non-PAT configurations.
Address space IPv6 systems may use any type of IPv6 IPv6 systems must have
addresses. IPv4-translatable addresses (based on
RFC 6052).
Table 17: Templates for HSL Bind and Session Create or Destroy
The table below describes the HSL pool exhaustion templates (in the order they are available in the template).
SUMMARY STEPS
1. enable
2. configure terminal
3. nat64 logging translations flow-export v9 udp destination addr|ipv6-destination IPv6 address
vrfvrf name source interface type interface-number
4. nat64 logging translations flow-export v9 {vrf-name | global-on}
5. exit
DETAILED STEPS
Example:
Device# configure terminal
Step 3 nat64 logging translations flow-export v9 udp destination Enables the high-speed logging of all VPN and
addr|ipv6-destination IPv6 address vrfvrf name source interface non-VPN translations for up to four destinations.
type interface-number You can enable logging for a specific destination
VRF using the vrf keyword. To specify an IPv6
Example: address for the UDP destination, use the
This example shows how to enable high-speed logging using an IPv4 ipv6-destination keyword followed by the IPv6
address address.
Device(config)# nat64 logging translations flow-export
v9 udp destination [Link] 1020 source GigabitEthernet
0/0/0
Example:
This example shows how to enable high-speed logging using an IPv6
address
Device(config)# nat64 logging translations flow-export
v9 udp ipv6-destination 2001::06 5050 source
GigabitEthernet 0/0/0
Example:
This example shows how to enable high-speed logging using an IPv6
address for a destination VRF
Device(config)# nat64 logging translations flow-export
v9 udp ipv6-destination 2001::06 5050 vrf hslvrf source
GigabitEthernet 0/0/0
Note The FTP64 ALG does not support IPv4-compatible IPv6 addresses.
Based on IPv6-to-IPv4 translation FTP considerations draft-ietf-behave-ftp64-02 and RFC 2228, the FTP64
ALG must switch to transparent mode (a device in a transparent mode is invisible in the network; however,
this device can act as a bridge and inspect or filter packets), when commands and responses flow between the
FTP client and the FTP server. When a client issues the FTP AUTH command, the FTP64 ALG transparently
forwards all data on the control channel in both (ingress and egress) directions, until the end of the control
channel session. Similarly, during an AUTH negotiation, the ALG must be in transparent mode, whether the
negotiation is successful or not.
Based on RFC 6384, the behavior of the FTP64 ALG during a client-server communication is different. During
an IPv6-to-IPv4 translation, the FTP64 ALG must transparently copy data transmitted over the control channel
so that the transport layer security (TLS) session works correctly. However, the client commands and server
responses are hidden from the FTP64 ALG. To ensure a consistent behavior, as soon as the initial FTP AUTH
command is issued by a client, the FTP64 ALG must stop translating commands and responses and start
transparently copying TCP data that is sent by the server to the client and vice versa. The FTP64 ALG must
ignore the AUTH command and not go into transparent mode if the server response is in the 4xx or 5xx ranges,
which comprise FTP error/warning messages.
Prior to CSCtu37975, when an IPv6 FTP client issues an FTP AUTH command, irrespective of whether the
IPv4 FTP server accepts or rejects that authorization negotiation, the FTP64 ALG moves the AUTH session
to transparent mode (or bypass mode). When a session is in transparent mode, NAT cannot perform translation
on the packets within the session. With CSCtu37975, during a client-server communication, the FTP64 ALG’s
behavior is compliant with RFC 6384.
at the time of change. The most critical updates are sent immediately, and other changes are communicated
by periodic updates.
When a standby FP is inserted or when a standby FP recovers from a reload, the active FP performs a bulk
synchronization to synchronize the standby FP with the active FP. NAT does an aggressive synchronization
by which the active FP pushes all the state information forcefully to the standby FP.
In addition to NAT64 session information, application-specific information (application-level gateway [ALG]
information) also has to be communicated to the standby FP. Each ALG has a per-session state that needs to
be synchronized in the standby. The ALG triggers the sending of all ALG state information to the standby
FP. NAT provides the mechanism for actually sending the ALG state and associates the state to a particular
session.
HTTP sessions are not backed up on the standby FP. To replicate HTTP sessions on the standby FP during a
switchover, you must configure the nat64 switchover replicate http enable command.
Note The Stateful NAT64—Intrachassis Redundancy feature does not support box-to-box (B2B) redundancy
or asymmetric routing.
Note You need to configure at least one of the configurations described in the following tasks for Stateful
NAT64 to work.
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. description string
6. ipv6 enable
7. ipv6 address {ipv6-address/prefix-length | prefix-name sub-bits/prefix-length}
8. nat64 enable
9. exit
10. interface type number
11. description string
12. ip address ip-address mask
13. nat64 enable
14. exit
15. nat64 prefix stateful ipv6-prefix/length
16. nat64 v6v4 static ipv6-address ipv4-address
17. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ipv6 unicast-routing
Step 4 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 0/0/0
Example:
Device(config-if)# description interface facing
ipv6
Example:
Device(config-if)# ipv6 enable
Step 7 ipv6 address {ipv6-address/prefix-length | prefix-name Configures an IPv6 address based on an IPv6 general
sub-bits/prefix-length} prefix and enables IPv6 processing on an interface.
Example:
Device(config-if)# ipv6 address
2001:DB8:1::1/96
Example:
Device(config-if)# nat64 enable
Step 10 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 1/2/0
Example:
Device(config-if)# description interface facing
ipv4
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# nat64 enable
Step 15 nat64 prefix stateful ipv6-prefix/length Defines the Stateful NAT64 prefix to be added to IPv4
hosts to translate the IPv4 address into an IPv6 address.
Example: • The Stateful NAT64 prefix can be configured at the
Device(config)# nat64 prefix stateful
2001:DB8:1::1/96 global configuration level or at the interface level.
Step 16 nat64 v6v4 static ipv6-address ipv4-address Enables NAT64 IPv6-to-IPv4 static address mapping.
Example:
Device(config)# nat64 v6v4 static
2001:DB8:1::FFFE [Link]
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. description string
6. ipv6 enable
7. ipv6 {ipv6-address/prefix-length | prefix-name sub-bits/prefix-length}
8. nat64 enable
9. exit
10. interface type number
11. description string
12. ip address ip-address mask
13. nat64 enable
14. exit
15. ipv6 access-list access-list-name
16. permit ipv6 ipv6-address any
17. exit
18. nat64 prefix stateful ipv6-prefix/length
19. nat64 v4 pool pool-name start-ip-address end-ip-address
20. nat64 v6v4 list access-list-name pool pool-name
21. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ipv6 unicast-routing
Example:
Device(config-if)# description interface facing
ipv6
Example:
Device(config-if)# ipv6 enable
Step 7 ipv6 {ipv6-address/prefix-length | prefix-name Configures an IPv6 address based on an IPv6 general
sub-bits/prefix-length} prefix and enables IPv6 processing on an interface.
Example:
Device(config-if)# ipv6 2001:DB8:1::1/96
Example:
Device(config-if)# nat64 enable
Step 10 interface type number Configures an interface type and enters interface
configuration mode
Example:
Device(config)# interface gigabitethernet 1/2/0
Example:
Device(config-if)# description interface facing
ipv4
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# nat64 enable
Step 15 ipv6 access-list access-list-name Defines an IPv6 access list and enters IPv6 access list
configuration mode.
Example:
Device(config)# ipv6 access-list nat64-acl
Step 16 permit ipv6 ipv6-address any Sets permit conditions for an IPv6 access list.
Example:
Device(config-ipv6-acl)# permit ipv6
2001:DB8:2::/96 any
Step 17 exit Exits IPv6 access list configuration mode and enters
global configuration mode.
Example:
Device(config-ipv6-acl# exit
Step 18 nat64 prefix stateful ipv6-prefix/length Enables NAT64 IPv6-to-IPv4 address mapping.
Example:
Device(config)# nat64 prefix stateful
2001:DB8:1::1/96
Step 19 nat64 v4 pool pool-name start-ip-address end-ip-address Defines the Stateful NAT64 IPv4 address pool.
Example:
Device(config)# nat64 v4 pool pool1
[Link] [Link]
Step 20 nat64 v6v4 list access-list-name pool pool-name Dynamically translates an IPv6 source address to an IPv6
source address and an IPv6 destination address to an
Example: IPv4 destination address for NAT64.
Device(config)# nat64 v6v4 list nat64-acl pool
pool1
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. description string
6. ipv6 enable
7. ipv6 {ipv6-address/prefix-length | prefix-name sub-bits/prefix-length}
8. nat64 enable
9. exit
10. interface type number
11. description string
12. ip address ip-address mask
13. nat64 enable
14. exit
15. ipv6 access-list access-list-name
16. permit ipv6 ipv6-address any
17. exit
18. nat64 prefix stateful ipv6-prefix/length
19. nat64 v4 pool pool-name start-ip-address end-ip-address
20. nat64 v6v4 list access-list-name pool pool-name overload
21. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ipv6 unicast-routing
Step 4 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 0/0/0
Example:
Device(config-if)# description interface facing
ipv6
Example:
Device(config-if)# ipv6 enable
Step 7 ipv6 {ipv6-address/prefix-length | prefix-name Configures an IPv6 address based on an IPv6 general
sub-bits/prefix-length} prefix and enables IPv6 processing on an interface.
Example:
Device(config-if)# ipv6 2001:DB8:1::1/96
Step 10 interface type number Configures an interface type and enters interface
configuration mode
Example:
Device(config)# interface gigabitethernet 1/2/0
Example:
Device(config-if)# description interface facing
ipv4
Example:
Device(config-if)# ip address [Link]
[Link]
Step 15 ipv6 access-list access-list-name Defines an IPv6 access list and places the device in
IPv6 access list configuration mode.
Example:
Device(config)# ipv6 access-list nat64-acl
Step 16 permit ipv6 ipv6-address any Sets permit conditions for an IPv6 access list.
Example:
Device(config-ipv6-acl)# permit ipv6
2001:db8:2::/96 any
Step 17 exit Exits IPv6 access list configuration mode and enters
global configuration mode.
Example:
Device(config-ipv6-acl)# exit
Step 18 nat64 prefix stateful ipv6-prefix/length Enables NAT64 IPv6-to-IPv4 address mapping.
Example:
Device(config)# nat64 prefix stateful
2001:db8:1::1/96
Step 19 nat64 v4 pool pool-name start-ip-address end-ip-address Defines the Stateful NAT64 IPv4 address pool.
Example:
Device(config)# nat64 v4 pool pool1 [Link]
[Link]
Example:
Device(config)# nat64 v6v4 list nat64-acl pool
pool1 overload
SUMMARY STEPS
DETAILED STEPS
Example:
Device# show nat64 aliases
Aliases configured: 1
Address Table ID Inserted Flags Send ARP Reconcilable Stale Ref-Count
[Link] 0 FALSE 0x0030 FALSE TRUE FALSE 1
Example:
Device# show nat64 logging
translation
flow export UDP [Link] 5000 60087
Step 3 show nat64 prefix stateful {global | {interfaces | static-routes} [prefix ipv6-address/prefix-length]}
This command displays information about NAT64 stateful prefixes.
Example:
Device# show nat64 prefix stateful interfaces
Stateful Prefixes
Example:
Device# show nat64 timeouts
NAT64 Timeout
! Router B Configuration
Standard/RFC Title
Framework for IPv4/IPv6 Translation Framework for IPv4/IPv6 Translation
draft-ietf-behave-v6v4-framework-06
FTP ALG for IPv6-to-IPv4 translation An FTP ALG for IPv6-to-IPv4 translation
draft-ietf-behave-ftp64-06
Standard/RFC Title
IP/ICMP Translation Algorithm IP/ICMP Translation Algorithm draft-ietf-behave-v6v4-xlate-10
Stateful NAT64: Network Address and Stateful NAT64: Network Address and Protocol Translation from
Protocol Translation from IPv6 Clients IPv6 Clients to IPv4 Servers
to IPv4 Servers draft-ietf-behave-v6v4-xlate-stateful-12
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
FTP64 NAT ALG Intrabox HA Cisco IOS XE Release In Cisco IOS XE Release 3.5S, the FTP64
Support 3.5S ALG adds HA support for Stateful NAT64.
The FTP64 NAT ALG Intrabox HA Support
feature supports the stateful switchover
between redundant FPs within a single chassis.
The HA support provided by the FTP64 ALG
is applicable to both intrabox and interbox HA
and In-Service Software Upgrade (ISSU).
Stateful NAT64 ALG—Stateful Cisco IOS XE Release Cisco IOS XE Release 3.4S and later releases
FTP64 ALG Support 3.4S support FTP64 (or service FTP) ALGs. The
FTP64 ALG helps Stateful NAT64 operate on
Layer 7 data. An FTP ALG translates IP
addresses and the TCP port information
embedded in the payload of an FTP control
session.
The following commands were introduced or
modified: nat64 service ftp.
Stateful Network Address Cisco IOS XE Release The Stateful Network Address Translation 64
Translation 64 3.4S feature provides a translation mechanism that
translates IPv6 packets into IPv4 packets and
vice versa. The Stateful NAT64 translator,
algorithmically translates the IPv4 addresses
of IPv4 hosts to and from IPv6 addresses by
using the configured stateful prefix. In a similar
manner, the IPv6 addresses of IPv6 hosts are
translated to and from IPv4 addresses through
NAT.
The following commands were introduced or
modified: clear nat64 statistics, debug nat64,
nat64 logging, nat64 prefix stateful, nat64
translation, nat64 v4, nat64 v4v6, nat64
v6v4, show nat64 aliases, show nat64 limits,
show nat64 logging, show nat64 mappings
dynamic, show nat64 mappings static, show
nat64 services, show nat64 pools, show
nat64 prefix stateful, show nat64 statistics,
show nat64 timeouts, and show nat64
translations.
Glossary
ALG—application-layer gateway or application-level gateway.
FP—Forward Processor.
IPv4-converted address—IPv6 addresses used to represent the IPv4 hosts. These have an explicit mapping
relationship to the IPv4 addresses. This relationship is self-described by mapping the IPv4 address in the IPv6
address. Both stateless and stateful translators use IPv4-converted IPv6 addresses to represent the IPv4 hosts.
IPv6-converted address—IPv6 addresses that are assigned to the IPv6 hosts for the stateless translator. These
IPv6-converted addresses have an explicit mapping relationship to the IPv4 addresses. This relationship is
self-described by mapping the IPv4 address in the IPv6 address. The stateless translator uses the corresponding
IPv4 addresses to represent the IPv6 hosts. The stateful translator does not use IPv6-converted addresses,
because the IPv6 hosts are represented by the IPv4 address pool in the translator via dynamic states.
NAT—Network Address Translation.
RP—Route Processor.
stateful translation—In stateful translation a per-flow state is created when the first packet in a flow is
received. A translation algorithm is said to be stateful if the transmission or reception of a packet creates or
modifies a data structure in the relevant network element. Stateful translation allows the use of multiple
translators interchangeably and also some level of scalability. Stateful translation is defined to enable the IPv6
clients and peers without mapped IPv4 addresses to connect to the IPv4-only servers and peers.
stateless translation—A translation algorithm that is not stateful is called stateless. A stateless translation
requires configuring a static translation table, or may derive information algorithmically from the messages
it is translating. Stateless translation requires less computational overhead than stateful translation. It also
requires less memory to maintain the state, because the translation tables and the associated methods and
processes exist in a stateful algorithm and do not exist in a stateless one. Stateless translation enables the
IPv4-only clients and peers to initiate connections to the IPv6-only servers or peers that are equipped with
IPv4-embedded IPv6 addresses. It also enables scalable coordination of IPv4-only stub networks or ISP
IPv6-only networks. Because the source port in an IPv6-to-IPv4 translation may have to be changed to provide
adequate flow identification, the source port in the IPv4-to-IPv6 direction need not be changed.
The pairs of redundant interfaces are configured with the same unique ID number known as the redundant
interface identifier (RII).
The status of redundancy group members is determined through the use of hello messages sent over the control
link. The software considers either device not responding to a hello message within a configurable amount
of time to be a failure and initiates a switchover. For the software to detect a failure in milliseconds, control
links run the failover protocol that is integrated with the Bidirectional Forwarding Detection (BFD) protocol.
You can configure the following parameters for hello messages:
• Hello time—Interval at which hello messages are sent.
• Hold time—Amount of time before which the active or standby device is declared to be down.
The hello time defaults to 3 seconds to align with the Hot Standby Router Protocol (HSRP), and the hold time
defaults to 10 seconds. You can also configure these timers in milliseconds by using the timers hellotime
msec command.
To determine the pairs of interfaces that are affected by the switchover, you must configure a unique ID for
each pair of redundant interfaces. This ID is known as the RII that is associated with the interface.
A switchover to the standby device can occur when the priority setting that is configured on each device
changes. The device with the highest priority value acts as the active device. If a fault occurs on either the
active or standby device, the priority of the device is decremented by a configurable amount known as the
weight. If the priority of the active device falls below the priority of the standby device, a switchover occurs
and the standby device becomes the active device. This default behavior can be overridden by disabling the
preemption attribute for the RG. You can also configure each interface to decrease the priority when the Layer
1 state of the interface goes down. The priority that is configured overrides the default priority of an RG.
Each failure event that causes a modification of an RG priority generates a syslog entry that contains a time
stamp, the RG that was affected, the previous priority, the new priority, and a description of the failure event
cause.
A switchover also can occur when the priority of a device or interface falls below a configurable threshold
level.
A switchover to the standby device occurs under the following circumstances:
• Power loss or a reload occurs on the active device (including reloads).
• The run-time priority of the active device goes below that of the standby device (with preempt configured).
• The run-time priority of the active device goes below that of the configured threshold.
• The redundancy group on the active device is reloaded manually. Use the redundancy application
reload group rg-number command for a manual reload.
Active/Active Failover
In an active/active failover configuration, both devices can process network traffic. Active/active failover
generates virtual MAC (VMAC) addresses for interfaces in each redundancy group (RG).
One device in an active/active failover pair is designated as the primary (active) device, and the other is
designated as the secondary (standby) device. Unlike with active/standby failover, this designation does not
indicate which device becomes active when both devices start simultaneously. Instead, the primary/secondary
designation determines the following:
• The device that provides the running configuration to the failover pair when they start simultaneously.
• The device on which the failover RG appears in the active state when devices start simultaneously. Each
failover RG in the configuration is configured with a primary or secondary device preference. You can
configure both failover RGs to be in the active state on a single device and the standby failover RGs to
be on the other device. You can also configure one failover RG to be in the active state and the other
RG to be in the standby state on a single device.
Active/Standby Failover
Active/standby failover enables you to use a standby device to take over the functionality of a failed device.
A failed active device changes to the standby state, and the standby device changes to the active state. The
device that is now in the active state takes over IP addresses and MAC addresses of the failed device and
starts processing traffic. The device that is now in the standby state takes over standby IP addresses and MAC
addresses. Because network devices do not see any change in the MAC-to-IP address pairing, Address
Resolution Protocol (ARP) entries do not change or time out anywhere on the network.
In an active/standby scenario, the main difference between two devices in a failover pair depends on which
device is active and which device is a standby, namely which IP addresses to use and which device actively
passes the traffic. The active device always becomes the active device if both devices start up at the same
time (and are of equal operational health). MAC addresses of the active device are always paired with active
IP addresses.
LAN-LAN Topology
In a LAN-LAN topology, all participating devices are connected to each other through LAN interfaces on
both the inside and the outside. In this scenario, the traffic is often directed to the correct firewall if static
routing is configured on the upstream or downstream devices to an appropriate virtual IP address. The dynamic
routing configuration supported on LAN-facing interfaces must not introduce a dependency on routing protocol
convergence; otherwise, fast failover requirements will not be met. The figure below shows a LAN-LAN
topology.
Translation Filtering
RFC 4787 provides translation filtering behaviors for Network Address Translation (NAT). The following
options are used by NAT to filter packets that originate from specific external endpoints:
• Endpoint-independent filtering—Filters out packets that are not destined to an internal IP address and
port regardless of the external IP address and port source.
• Address-dependent filtering—Filters out packets that are not destined to an internal IP address. NAT
also filters out packets that are destined for an internal endpoint.
• Address- and port-dependent filtering—Filters out packets that are not destined to an internal IP address.
NAT also filters out packets that are destined for an internal endpoint if packets were not sent to the
endpoint previously.
Note The FTP64 ALG does not support IPv4-compatible IPv6 addresses.
Based on IPv6-to-IPv4 translation FTP considerations draft-ietf-behave-ftp64-02 and RFC 2228, the FTP64
ALG must switch to transparent mode (a device in a transparent mode is invisible in the network; however,
this device can act as a bridge and inspect or filter packets), when commands and responses flow between the
FTP client and the FTP server. When a client issues the FTP AUTH command, the FTP64 ALG transparently
forwards all data on the control channel in both (ingress and egress) directions, until the end of the control
channel session. Similarly, during an AUTH negotiation, the ALG must be in transparent mode, whether the
negotiation is successful or not.
Based on RFC 6384, the behavior of the FTP64 ALG during a client-server communication is different. During
an IPv6-to-IPv4 translation, the FTP64 ALG must transparently copy data transmitted over the control channel
so that the transport layer security (TLS) session works correctly. However, the client commands and server
responses are hidden from the FTP64 ALG. To ensure a consistent behavior, as soon as the initial FTP AUTH
command is issued by a client, the FTP64 ALG must stop translating commands and responses and start
transparently copying TCP data that is sent by the server to the client and vice versa. The FTP64 ALG must
ignore the AUTH command and not go into transparent mode if the server response is in the 4xx or 5xx ranges,
which comprise FTP error/warning messages.
Prior to CSCtu37975, when an IPv6 FTP client issues an FTP AUTH command, irrespective of whether the
IPv4 FTP server accepts or rejects that authorization negotiation, the FTP64 ALG moves the AUTH session
to transparent mode (or bypass mode). When a session is in transparent mode, NAT cannot perform translation
on the packets within the session. With CSCtu37975, during a client-server communication, the FTP64 ALG’s
behavior is compliant with RFC 6384.
1. enable
2. configure terminal
3. redundancy
4. application redundancy
5. protocol id
6. name group-name
7. Repeat Steps 3 to 6 to configure a redundancy group protocol on another device.
8. timers hellotime seconds holdtime seconds
9. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Example:
Device(config-red-app-prtcl)# name RG1
1. enable
2. configure terminal
3. redundancy
4. application redundancy
5. group id
6. name group-name
7. control interface-type interface-number protocol id
8. data interface-type interface-number
9. Repeat Steps 3 to 8 to configure another redundancy group.
10. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Step 6 name group-name Configures a name for the redundancy application group.
Example:
Device(config-red-app-grp)# name RG1
Step 7 control interface-type interface-number protocol id Configures a control interface type and number for the
redundancy application group.
Example:
Device(config-red-app-grp)# control
gigabitethernet 0/0/1 protocol 1
Step 8 data interface-type interface-number Configures a data interface type and number for the
redundancy application group.
Example:
Device(config-red-app-grp)# data
gigabitethernet 0/2/2
SUMMARY STEPS
1. enable
2. configure terminal
3. redundancy
4. application redundancy
5. group id
6. name group-name
7. priority value [failover-threshold value]
8. control interface-type interface-number protocol id
9. data interface-type interface-number
10. end
11. configure terminal
12. redundancy
13. application redundancy
14. group id
15. name group-name
16. priority value [failover-threshold value]
17. control interface-type interface-number protocol id
18. data interface-type interface-number
19. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Step 6 name group-name Configures a name for the redundancy application group.
Example:
Device(config-red-app-grp)# name RG1
Step 7 priority value [failover-threshold value] Specifies a group priority and failover threshold value for
the redundancy group.
Example:
Device(config-red-app-grp)# priority 195
failover-threshold 190
Step 8 control interface-type interface-number protocol id Configures a control interface type and number for the
redundancy application group.
Example:
Device(config-red-app-grp)# control
gigabitethernet 0/0/1 protocol 1
Step 9 data interface-type interface-number Configures a data interface type and number for the
redundancy application group.
Example:
Device(config-red-app-grp)# data
gigabitethernet 0/2/2
Example:
Device# configure terminal
Example:
Device(config)# redundancy
Step 15 name group-name Configures a name for the redundancy application group.
Example:
Device(config-red-app-grp)# name RG2
Step 16 priority value [failover-threshold value] Specifies a group priority and failover threshold value for
the redundancy group.
Example:
Device(config-red-app-grp)# priority 205
failover-threshold 200
Step 17 control interface-type interface-number protocol id Configures a control interface type and number for the
redundancy application group.
Example:
Device(config-red-app-grp)# control
gigabitethernet 0/0/1 protocol 2
Step 18 data interface-type interface-number Configures a data interface type and number for the
redundancy application group.
Example:
Device(config-red-app-grp)# data
gigabitethernet 0/2/2
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. redundancy rii id
5. redundancy group group-id ipv6 ipv6-prefix/prefix-length exclusive decrement value
6. exit
7. interface type number
8. redundancy rii id
9. redundancy group group-id ipv6 ipv6-prefix/prefix-length exclusive decrement value
10. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config-if)# redundancy group 1 ipv6
2001:DB8:1::1:100/64 exclusive decrement 50
Example:
Device(config-if)# redundancy group 1 ipv6
2001:DB8:2::1:100/64 exclusive decrement 50
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. ipv6 enable
6. ipv6 address ipv6-address/prefix-length
7. nat64 enable
8. exit
9. Repeat Steps 3 to 8 to configure NAT64 on another interface.
10. nat64 prefix stateful ipv6-prefix/length
11. nat64 v6v4 static ipv6-address ipv6-address [redundancy group-id mapping-id id]
12. nat64 v6v4 tcp ipv6-address ipv6-port ipv4-address ipv4-port [redundancy group-id mapping-id id]
13. end
14. show nat64 translations protocol tcp
15. show nat64 translations redundancy group-id
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ipv6 unicast-routing
Step 4 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/1
Example:
Device(config-if)# ipv6 enable
Example:
Device(config-if)# nat64 enable
Step 11 nat64 v6v4 static ipv6-address ipv6-address [redundancy Enables NAT64 IPv6-to-IPv4 static address mapping
group-id mapping-id id] and interchassis redundancy.
Example:
Device(config)# nat64 v6v4 static
2001:DB8:1::FFFE [Link] redundancy 1
mapping-id 30
Step 12 nat64 v6v4 tcp ipv6-address ipv6-port ipv4-address Applies static mapping to TCP protocol packets and
ipv4-port [redundancy group-id mapping-id id] enables interchassis redundancy.
Example:
Device(config)# nat64 v6v4 tcp 2001:DB8:1::1
redundancy 1 mapping-id 1
Step 14 show nat64 translations protocol tcp Displays information about NAT 64 protocol translations.
Example:
Device# show nat64 translations protocol tcp
Example:
The following is sample output from the show nat64 translations protocol tcp command:
Device# show nat64 translations protocol tcp
[Link]:21 [2001:DB8:1::103]:32847
Additional References
Related Documents
Standards/RFCs
Standard/RFC Title
RFC 4787 Network Address Translation (NAT) Behavioral Requirements for Unicast
UDP
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 20: Feature Information for Stateful Network Address Translation 64 Interchassis Redundancy
• In Cisco IOS XE Denali 16.2 release, the support for MAP-T domains were extended to 10000 domains.
For releases prior to Cisco IOS XE Denali 16.2, a maximum of 128 MAP-T domains are supported.
• Forwarding mapping rule (FMR) is not supported.
A MAP-T configuration has one basic mapping rule (BMR), one default mapping rule (DMR), and one or
more forwarding mapping rules (FMRs) for each MAP-T domain. You must configure the DMR before
configuring the BMR for a MAP-T domain.
The three types of mapping rules are described below:
• A BMR configures the MAP IPv6 address or prefix. The basic mapping rule is configured for the source
address prefix. You can configure only one basic mapping rule per IPv6 prefix. The basic mapping rule
is used by the MAP-T CE to configure itself with an IPv4 address, an IPv4 prefix, or a shared IPv4
address from an IPv6 prefix. The basic mapping rule can also be used for forwarding packets, where an
IPv4 destination address and a destination port are mapped into an IPv6 address/prefix. Every MAP-T
node (a CE device is a MAP-T node) must be provisioned with a basic mapping rule. You can use the
port-parameters command to configure port parameters for the MAP-T BMR.
• A DMR is a mandatory rule that is used for mapping IPv4 information to IPv6 addresses for destinations
outside a MAP-T domain. A [Link]/0 entry is automatically configured in the MAP rule table (MRT)
for this rule.
• An FMR is used for forwarding packets. Each FMR results in an entry in the MRT for the rule IPv4
prefix. FMR is an optional rule for mapping IPv4 and IPv6 destinations within a MAP-T domain.
Note FMR is not supported by the Mapping of Address and Port Using Translation feature.
Note Forwarding mapping rule (FMR) is not supported by the Mapping of Address and Port Using Translation
feature.
The figure below shows the mapped CE address format as defined in MAP-T configuration. This address
format is used in basic mapping rule (BMR) and FMR operations.
The figure below shows the address format used by the MAP-T default mapping rule (DMR), an IPv4-translated
address that is specific to MAP-T configuration.
Note The Mapping of Address and Port Using Translation feature does not support the MAP-T customer edge
(CE) functionality. The CE functionality is provided by third-party devices.
on the IPv4 packet, and the IPv4 packet is forwarded to the IPv4 egress interface for processing and
transmission.
SUMMARY STEPS
1. enable
2. configure terminal
3. nat64 map-t domain number
4. default-mapping-rule ipv6-prefix/prefix-length
5. basic-mapping-rule
6. ipv6-prefix prefix/length
7. ipv4-prefix prefix/length
8. port-parameters share-ratio ratio [start-port port-number]
9. end
10. show nat64 map-t domain number
DETAILED STEPS
Example:
Device# configure terminal
Step 4 default-mapping-rule ipv6-prefix/prefix-length Configures the default domain mapping rule for the
MAP-T domain.
Example:
Device(config-nat64-mapt)# default-mapping-rule
2001:DA8:B001:FFFF::/64
Step 5 basic-mapping-rule Configures the basic mapping rule (BMR) for the MAP-T
domain and enters NAT64 MAP-T BMR configuration
Example: mode.
Device(config-nat64-mapt)# basic-mapping-rule
Step 6 ipv6-prefix prefix/length Configures an IPv6 address and prefix for the MAP-T
BMR.
Example:
Device(config-nat64-mapt-bmr)# ipv6-prefix
2001:DA8:B001::/56
Step 7 ipv4-prefix prefix/length Configures an IPv4 address and prefix for the MAP-T
BMR.
Example:
Device(config-nat64-mapt-bmr)# ipv4-prefix
[Link]/28
Step 8 port-parameters share-ratio ratio [start-port Configures port parameters for the MAP-T BMR.
port-number]
Example:
Device(config-nat64-mapt-bmr)# port-parameters
share-ratio 16 start-port 1024
Step 10 show nat64 map-t domain number Displays MAP-T domain information.
Example:
Device# show nat64 map-t domain 1
Example:
The following is sample output from the show nat64 map-t domain command:
Device# show nat64 map-t domain 1
MAP-T Domain 1
Mode MAP-T
Default-mapping-rule
Ip-v6-prefix 2001:DA8:B001:FFFF::/64
Basic-mapping-rule
Ip-v6-prefix 2001:DA8:B001::/56
Ip-v4-prefix [Link]/28
Port-parameters
Share-ratio 16 Contiguous-ports 64 Start-port 1024
Share-ratio-bits 4 Contiguous-ports-bits 6 Port-offset-bits 6
Standard/RFC Title
MAP Mapping of Address and Port (MAP)
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 21: Feature Information for Mapping of Address and Port Using Translation
Table 22: Feature Information for Mapping of Address and Port Using Translation
Glossary
EA bits—Embedded address bits. The IPv4 EA bits in the IPv6 address identify an IPv4 prefix/address (or
part thereof) or a shared IPv4 address (or part thereof) and a port-set identifier.
IP fragmentation—The process of breaking a datagram into a number of pieces that can be reassembled
later. The IP source, destination, identification, total length, and fragment offset fields, along with the More
fragments and Don't Fragment (DF) flags in the IP header, are used for IP fragmentation and reassembly. A
DF bit is a bit within the IP header that determines whether a device is allowed to fragment a packet.
IPv4-translatable address—IPv6 addresses that are used to represent IPv4 hosts. These addresses have an
explicit mapping relationship to IPv6 addresses. This relationship is self-described by mapping the IPv4
address in the IPv6 address. Both stateless and stateful translators use IPv4-translatable (also called
IPv4-converted) IPv6 addresses to represent IPv4 hosts.
IPv6-translatable address—IPv6 addresses that are assigned to IPv6 hosts for stateless translation. These
IPv6-translatable addresses (also called IPv6-converted addresses) have an explicit mapping relationship to
IPv4 addresses. This relationship is self-described by mapping the IPv4 address in the IPv6 address. The
stateless translator uses corresponding IPv4 addresses to represent IPv6 hosts. The stateful translator does not
use IPv6-translatable addresses because IPv6 hosts are represented by the IPv4 address pool in the translator
via dynamic states.
MAP rule—A set of parameters that define the mapping between an IPv4 prefix, an IPv4 address or a shared
IPv4 address, and an IPv6 prefix or address. Each MAP domain uses a different mapping rule set.
MAP-T border router—A mapping of address and port using translation (MAP-T)-enabled router or translator
at the edge of a MAP domain that provides connectivity to the MAP-T domain. A border relay router has at
least one IPv6-enabled interface and one IPv4 interface connected to the native IPv4 network, and this router
can serve multiple MAP-T domains.
MAP-T CE—A device that functions as a customer edge (CE) router in a MAP-T deployment. A typical
MAP-T CE device that adopts MAP rules serves a residential site with one WAN-side interface and one or
more LAN-side interfaces. A MAP-T CE device can also be referred to as a “CE” within the context of a
MAP-T domain.
MAP-T domain—Mapping of address and port using translation (MAP-T) domain. One or more customer
edge (CE) devices and a border router, all connected to the same IPv6 network. A service provider may deploy
a single MAP-T domain or use multiple MAP domains.
MRT—MAP rule table. Address and port-aware data structure that supports the longest match lookups. The
MRT is used by the MAP-T forwarding function.
path MTU—Path maximum transmission unit (MTU) discovery prevents fragmentation in the path between
endpoints. Path MTU discovery is used to dynamically determine the lowest MTU along the path from a
packet’s source to its destination. Path MTU discovery is supported only by TCP and UDP. Path MTU discovery
is mandatory in IPv6, but it is optional in IPv4. IPv6 devices never fragment a packet—only the sender can
fragment packets.
stateful translation—Creates a per-flow state when the first packet in a flow is received. A translation
algorithm is said to be stateful if the transmission or reception of a packet creates or modifies a data structure
in the relevant network element. Stateful translation allows the use of multiple translators interchangeably
and also some level of scalability. Stateful translation enables IPv6 clients and peers without mapped IPv4
addresses to connect to IPv4-only servers and peers.
stateless translation—A translation algorithm that is not stateful. A stateless translation requires configuring
a static translation table or may derive information algorithmically from the messages that it is translating.
Stateless translation requires less computational overhead than stateful translation. It also requires less memory
to maintain the state because the translation tables and the associated methods and processes exist in a stateful
algorithm and do not exist in a stateless one. Stateless translation enables IPv4-only clients and peers to initiate
connections to IPv6-only servers or peers that are equipped with IPv4-embedded IPv6 addresses. It also
enables scalable coordination of IPv4-only stub networks or ISP IPv6-only networks. Because the source port
in an IPv6-to-IPv4 translation may have to be changed to provide adequate flow identification, the source
port in the IPv4-to-IPv6 direction need not be changed.
Note Disabling flow cache entries results in lesser performance as this functionality does multiple database
searches to find the most specific translation to use.
This module describes the feature and explains how to configure it.
Note NAT, NAT64 (stateful and stateless), and carrier-grade NAT (CGN) translations support the disabling of
flow cache entries.
When flow cache entry is enabled and a user has 100 sessions, 1 bind and 100 session are created. However,
when flow cache entry is disabled, only one single bind is created for these sessions. Disabling flow cache
entries for dynamic and static translations saves memory usage and provides more scalability for your dynamic
or static translations.
Note Disabling flow cache entries will result in lesser performance as this functionality performs multiple
database searches to find the most specific translation to use.
• If the packet is a non-ALG packet, a temporary session is created and this session is sent for
translation. The packet is sent to Layer 3 or Layer 4 if your configuration is NAT or to Layer 4 or
Layer 7 if your configuration is NAT64 (stateful or stateless).
Note Port Address Translation (PAT) or interface overload configuration, which is a type of dynamic NAT,
requires flow cache entries. You cannot disable flow cache entries for PAT configurations.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
4. access-list access-list-number permit source source-wildcard
5. ip nat inside source list access-list-number pool name
6. no ip nat create flow-entries
7. interface type number
8. ip address ip-address mask
9. ip nat inside
10. exit
11. interface type number
12. ip address ip-address mask
13. ip nat outside
14. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} needed.
Example:
Device(config)# ip nat pool net-208 [Link]
[Link] prefix-length 28
Step 4 access-list access-list-number permit source Defines a standard access list that permits IP addresses
source-wildcard that are to be translated.
Example:
Device(config)# access-list 1 permit [Link]
[Link]
Step 5 ip nat inside source list access-list-number pool name Establishes a dynamic source translation by specifying
the pool and the access list specified in Steps 3 and 4,
Example: respectively.
Device(config)# ip nat inside source list 1 pool
net-208
Step 6 no ip nat create flow-entries Disables the creation of flow cache entries.
Example:
Device(config)# no ip nat create flow-entries
Step 7 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/1
Step 8 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 9 ip nat inside Connects the interface to the inside network, which is
subject to NAT.
Example:
Device(config-if)# ip nat inside
Step 11 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/1/1
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
SUMMARY STEPS
1. enable
2. configure terminal
3. ipv6 unicast-routing
4. interface type number
5. description string
6. ipv6 enable
7. ipv6 address {ipv6-address/prefix-length | prefix-name sub-bits/prefix-length}
8. nat64 enable
9. exit
10. interface type number
11. description string
12. ip address ip-address mask
13. nat64 enable
14. exit
15. nat64 prefix stateful ipv6-prefix/length
16. nat64 v6v4 static ipv6-address ipv4-address
17. nat64 settings flow-entries disable
18. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ipv6 unicast-routing
Step 4 interface type number Specifies an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 0/0/0
Example:
Device(config-if)# description interface facing
ipv6
Example:
Device(config-if)# ipv6 enable
Step 7 ipv6 address {ipv6-address/prefix-length | prefix-name Configures an IPv6 address based on an IPv6 general
sub-bits/prefix-length} prefix and enables IPv6 processing on an interface.
Example:
Device(config-if)# ipv6 address 2001:DB8:1::1/96
Example:
Device(config-if)# nat64 enable
Step 10 interface type number Specifies an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 1/2/0
Example:
Device(config-if)# description interface facing
ipv4
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# nat64 enable
Step 15 nat64 prefix stateful ipv6-prefix/length Defines the stateful NAT64 prefix to be added to IPv4
hosts to translate the IPv4 address into an IPv6 address.
Example: • The stateful NAT64 prefix can be configured in
Device(config)# nat64 prefix stateful
2001:DB8:1::1/96 global configuration mode or in interface mode.
Step 16 nat64 v6v4 static ipv6-address ipv4-address Enables NAT64 IPv6-to-IPv4 static address mapping.
Example:
Device(config)# nat64 v6v4 static
2001:DB8:1::FFFE [Link]
Step 17 nat64 settings flow-entries disable Disables flow cache entries in the NAT64 configuration.
Example:
Device(config)# nat64 settings flow-entries
disable
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat settings mode cgn
4. ip nat inside source static local-ip global-ip
5. no ip nat create flow-entries
6. interface virtual-template number
7. ip nat inside
8. exit
9. interface type number
10. ip nat outside
11. end
DETAILED STEPS
Example:
Device# configure terminal
Example:
Device(config)# ip nat settings mode cgn
Step 4 ip nat inside source static local-ip global-ip Enables static CGN of the inside source address.
Example:
Device(config)# ip nat inside source static
[Link] [Link]
Step 5 no ip nat create flow-entries Disables flow cache entries in static CGN mode.
Example:
Device(config)# no ip nat create flow-entries
Step 6 interface virtual-template number Creates a virtual template interface that can be configured
and applied dynamically when creating virtual access
Example: interfaces and enters interface configuration mode.
Device(config)# interface virtual-template 1
Step 9 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 2/1/1
Example:
Device(config-if)# ip nat outside
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Table 23: Feature Information for Disabling Flow Cache Entries in NAT and NAT64
Note If you change the Network Address Translation (NAT) configuration mode to paired-address-pooling
configuration mode and vice versa, all existing NAT sessions are removed.
To configure NAT paired-address-pooling mode, use the ip nat settings pap command. To remove it, use
the no ip nat settings pap command.
After you configure paired-address-pooling mode, all pool-overload mappings will act in the
paired-address-pooling manner.
Based on your NAT configuration, you can use NAT static or dynamic rules.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat settings pap [limit {1000 | 120 | 250 | 30 | 500 | 60}]
4. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
5. access-list access-list-number permit source [source-wildcard]
6. ip nat inside source list access-list-number pool name overload
7. interface type number
8. ip address ip-address mask
9. ip nat inside
10. exit
11. interface type number
12. ip address ip-address mask
13. ip nat outside
14. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat settings pap [limit {1000 | 120 | 250 | 30 | 500 | Configures NAT paired address pooling configuration
60}] mode.
• Use the limit keyword to limit of the number of
Example: local addresses you can use per global address. The
Device(config)# ip nat settings pap
default is 120.
Step 4 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} needed.
Example:
Device(config)# ip nat pool net-208
[Link] [Link] netmask
[Link]
Step 5 access-list access-list-number permit source Defines a standard access list permitting addresses that
[source-wildcard] are to be translated.
Example:
Device(config)# access-list 1 permit [Link]
[Link]
Step 6 ip nat inside source list access-list-number pool name Establishes dynamic Port Address Translation (PAT) or
overload NAT overload and specifies the access list and the IP
address pool defined in Step 4 and Step 5.
Example:
Device(config)# ip nat inside source list 1 pool
net-208 overload
Step 7 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/1
Step 8 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Step 9 ip nat inside Connects the interface to the inside network, which is
subject to NAT.
Example:
Device(config-if)# ip nat inside
Step 12 ip address ip-address mask Sets a primary IP address for the interface.
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# ip nat outside
Note If you change the Network Address Translation (NAT) configuration mode to paired-address-pooling
configuration mode and vice versa, all existing NAT sessions are removed.
To configure PAP for a NAT pool, use the ip nat settings pap pool command. To remove it, use the no ip
nat settings pap pool command.
After you configure paired-address-pooling mode, all pool-overload mappings will act in the
paired-address-pooling manner.
Based on your NAT configuration, you can use NAT static or dynamic rules.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat settings pap [limit {1000 | 120 | 250 | 30 | 500 | 60}][pool]
4. ip nat pool name start-ip end-ip {netmask netmask | }
5. ip nat inside
6. exit
7. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat settings pap [limit {1000 | 120 | 250 | 30 | 500 Configures NAT paired address pooling configuration mode.
| 60}][pool]
• Use the limit keyword to limit of the number of local
addresses you can use per global address. The default
Example: is 120.
Device(config)# ip nat settings pap pool
Step 4 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as needed.
}
Example:
Device(config)# ip nat nat_pool net-208
[Link] [Link] netmask
[Link]
Step 5 ip nat inside Connects the interface to the inside network, which is subject
to NAT.
Example:
Device(config-if)# ip nat inside
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
You must enable NAT paired-address pooling support for this feature to work. This feature also supports
Point-to-Point Tunneling Protocol (PPTP).
Note This feature is supported only in carrier-grade NAT (CGN) mode; therefore only source information is
logged when this feature is configured. Destination information is not logged. For more information about
CGN, see the “Carrier-Grade Network Address Translation" module in IP Addressing: NAT Configuration
Guide.
Paired-Address Pooling Limit Default Bulk-Port Allocation Port Maximum Port Step Size
Size
120 512 ports 8
30 2048 ports 2
60 1024 ports 4
1000 64 ports 16
Messages are usually logged when a session is created and destroyed. In bulk port allocation, messages are
logged when a port set is allocated or freed.
The following table provides information about HSL fields, their format and value:
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. ip nat inside
5. exit
6. interface type number
7. ip nat outside
8. exit
9. ip nat settings mode cgn
10. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
11. access-list access-list-number permit source [source-wildcard]
12. ip nat inside source list access-list-number pool name
13. ip nat settings pap bpa set-size 512 step-size 8
14. ip nat log translations flow-export v9 udp destination addr port
15. end
16. show ip nat translations
DETAILED STEPS
Example:
Device# configure terminal
Step 4 ip nat inside Connects the interface to the inside network, which is
subject to Network Address Translation (NAT).
Example:
Device(config-if)# ip nat inside
Example:
Device(config-if)# ip nat outside
Example:
Device(config)# ip nat settings mode cgn
Step 10 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} needed.
Example:
Device(config)# ip nat pool net-208 [Link]
[Link] prefix-length 24
Step 11 access-list access-list-number permit source Defines a standard access list that permits addresses
[source-wildcard] that are to be translated.
Example:
Device(config)# access-list 1 permit source
[Link] [Link]
Step 12 ip nat inside source list access-list-number pool name Establishes dynamic NAT by specifying the access
list and the IP address pool defined in Step 10 and Step
Example: 11.
Device(config)# ip nat inside source list 1 pool
net-208
Step 13 ip nat settings pap bpa set-size 512 step-size 8 Configures bulk-port allocation.
Example:
Device(config)# ip nat settings pap bpa set-size
512 step-size 8
Step 14 ip nat log translations flow-export v9 udp destination Enables the high-speed logging (HSL) of all NAT
addr port translations.
Example:
Device(config)# ip nat log translations flow-export
v9 udp destination [Link] 2055
Example:
Device# show ip nat translations
DETAILED STEPS
Example:
Device# show ip nat bpa
Displays Network Address Translation (NAT) bulk logging and port-block allocation settings.
The following is sample output from the show ip nat bpa command:
Device# show ip nat bpa
Example:
Device# show ip nat pool name pool1
Displays NAT pool and port statistics.
The following is sample output from the show ip nat pool name pool1 command:
Device# show ip nat pool name pool1
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Table 27: Feature Information for Bulk Logging and Port Block Allocation
• Prerequisites for MSRPC ALG Support for Firewall and NAT, page 295
• Restrictions for MSRPC ALG Support for Firewall and NAT, page 296
• Information About MSRPC ALG Support for Firewall and NAT, page 296
• How to Configure MSRPC ALG Support for Firewall and NAT, page 298
• Configuration Examples for MSRPC ALG Support for Firewall and NAT, page 304
• Additional References for MSRPC ALG Support for Firewall and NAT, page 304
• Feature Information for MSRPC ALG Support for Firewall and NAT, page 305
Note MSRPC ALG is automatically enabled if traffic is sent to TCP port 135 by either Cisco IOS XE firewall
or NAT, or both.
Application-Level Gateways
An application-level gateway (ALG), also known as an application-layer gateway, is an application that
translates the IP address information inside the payload of an application packet. An ALG is used to interpret
the application-layer protocol and perform firewall and Network Address Translation (NAT) actions. These
actions can be one or more of the following depending on your configuration of the firewall and NAT:
• Allow client applications to use dynamic TCP or UDP ports to communicate with the server application.
• Recognize application-specific commands and offer granular security control over them.
• Synchronize multiple streams or sessions of data between two hosts that are exchanging data.
• Translate the network-layer address information that is available in the application payload.
The firewall opens a pinhole, and NAT performs translation service on any TCP or UDP traffic that does not
carry the source and destination IP addresses in the application-layer data stream. Specific protocols or
applications that embed IP address information require the support of an ALG.
MSRPC
MSRPC is a framework that developers use to publish a set of applications and services for servers and
enterprises. RPC is an interprocess communication technique that allows the client and server software to
communicate over the network. MSRPC is an application-layer protocol that is used by a wide array of
Microsoft applications. MSRPC supports both connection-oriented (CO) and connectionless (CL) Distributed
Computing Environment (DCE) RPC modes over a wide variety of transport protocols. All services of MSRPC
establish an initial session that is referred to as the primary connection. A secondary session over a port range
between 1024 to 65535 as the destination port is established by some services of MSRPC.
For MSRPC to work when firewall and NAT are enabled, in addition to inspecting MSRPC packets, the ALG
is required to handle MSRPC specific issues like establishing dynamic firewall sessions and fixing the packet
content after the NAT.
By applying MSRPC protocol inspection, most MSRPC services are supported, eliminating the need for Layer
7 policy filters.
Note By default, MSRPC ALG is automatically enabled when NAT is enabled. There is no need to explicitly
enable MSRPC ALG in the NAT-only configuration. You can use the no ip nat service msrpc command
to disable MSRPC ALG on NAT.
1. enable
2. configure terminal
3. class-map type inspect match-any class-map-name
4. match protocol protocol-name
5. exit
6. policy-map type inspect policy-map-name
7. class type inspect class-map-name
8. inspect
9. end
DETAILED STEPS
Example:
Router# configure terminal
Step 3 class-map type inspect match-any class-map-name Creates an inspect type class map for the traffic class and
enters QoS class-map configuration mode.
Example:
Router(config)# class-map type inspect
match-any msrpc-cmap
Step 4 match protocol protocol-name Configures the match criteria for a class map on the basis of
a specified protocol.
Example: • Only Cisco IOS XE stateful packet inspection-supported
Router(config-cmap)# match protocol msrpc
protocols can be used as match criteria in inspect type
class maps.
Step 5 exit Exits QoS class-map configuration mode and enters global
configuration mode.
Example:
Router(config-cmap)# exit
Step 6 policy-map type inspect policy-map-name Creates a Layer 3 or Layer 4 inspect type policy map and
enters QoS policy-map configuration mode.
Example:
Router(config)# policy-map type inspect
msrpc-pmap
Step 7 class type inspect class-map-name Specifies the traffic (class) on which an action is to be
performed and enters QoS policy-map class configuration
Example: mode.
Router(config-pmap)# class type inspect
msrpc-class-map
Example:
Router(config-pmap-c)# inspect
1. enable
2. configure terminal
3. zone security security-zone-name
4. exit
5. zone security security-zone-name
6. exit
7. zone-pair security zone-pair-name [source source-zone destination [destination-zone]]
8. service-policy type inspect policy-map-name
9. end
DETAILED STEPS
Example:
Rotuer# configure terminal
Step 3 zone security security-zone-name Creates a security zone to which interfaces can be assigned
and enters security zone configuration mode.
Example:
Router(config)# zone security in-zone
Step 5 zone security security-zone-name Creates a security zone to which interfaces can be assigned
and enters security zone configuration mode.
Example:
Router(config)# zone security out-zone
Step 6 exit Exits security zone configuration mode and enters global
configuration mode.
Example:
Router(config-sec-zone)# exit
Step 7 zone-pair security zone-pair-name [source source-zone Creates a zone pair and enters security zone pair
destination [destination-zone]] configuration mode.
Note To apply a policy, you must configure a zone
Example: pair.
Router(config)# zone-pair security in-out
source in-zone destination out-zone
Step 8 service-policy type inspect policy-map-name Attaches a firewall policy map to the destination zone pair.
Note If a policy is not configured between a pair of zones,
Example: traffic is dropped by default.
Router(config-sec-zone-pair)# service-policy
type inspect msrpc-pmap
Step 9 end Exits security zone pair configuration mode and enters
privileged EXEC mode.
Example:
Router(config-sec-zone-pair)# end
1. enable
2. configure terminal
3. alg vtcp service msrpc
4. exit
5. set platform hardware qfp active feature alg msrpc tolerance on
DETAILED STEPS
Example:
Router# configure terminal
Step 3 alg vtcp service msrpc Enables vTCP functionality for MSRPC ALG.
Note By default, MSRPC ALG supports
Example: vTCP.
Rotuer(config)# alg vtcp service msrpc
Step 5 set platform hardware qfp active feature alg msrpc Enables MSRPC unknown message tolerance.
tolerance on Note By default, the tolerance is switched
off.
Example:
Rotuer# set platform hardware qfp active feature
alg msrpc tolerance on
1. enable
2. configure terminal
3. no alg vtcp service msrpc
4. end
DETAILED STEPS
Example:
Router# configure terminal
Step 3 no alg vtcp service msrpc Disables vTCP functionality for MSRPC ALG.
Example:
Rotuer(config)# no alg vtcp service msrpc
Security commands
• Cisco IOS Security Command Reference:
Commands A to C
• Cisco IOS Security Command Reference:
Commands D to L
• Cisco IOS Security Command Reference:
Commands M to R
• Cisco IOS Security Command Reference:
Commands S to Z
ALG support NAT and Firewall ALG Support on Cisco ASR 1000
Series Routers
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 29: Feature Information for MSRPC ALG Support for Firewall and NAT
MSRPC ALG Inspection Cisco IOS XE Release 3.14S The MSRPC ALG Inspection
Improvements for Zone-based Improvements for Zone-based
Firewall and NAT Firewall and NAT feature supports
Virtual Transport Control Protocol
(vTCP) functionality which
provides a framework for various
ALG protocols to appropriately
handle the TCP segmentation and
parse the segments in the Cisco
firewall, Network Address
Translation (NAT) and other
applications.
The following command was
introduced: alg vtcp service
msrpc.
Restrictions for Sun RPC ALG Support for Firewalls and NAT
• Depending on your release, the following configuration will not work on Cisco ASR 1000 Aggregation
Services Routers. If you configure the inspect action for Layer 4 or Layer 7 class maps, packets that
match the Port Mapper Protocol well-known port (111) pass through the firewall without the Layer 7
inspection. Without the Layer 7 inspection, firewall pinholes are not open for traffic flow, and the Sun
remote-procedure call (RPC) is blocked by the firewall. As a workaround, configure the match
program-number command for Sun RPC program numbers.
• Only Port Mapper Protocol Version 2 is supported; none of the other versions are supported.
• Only RPC Version 2 is supported.
Information About Sun RPC ALG Support for Firewalls and NAT
Application-Level Gateways
An application-level gateway (ALG), also known as an application-layer gateway, is an application that
translates the IP address information inside the payload of an application packet. An ALG is used to interpret
the application-layer protocol and perform firewall and Network Address Translation (NAT) actions. These
actions can be one or more of the following depending on your configuration of the firewall and NAT:
• Allow client applications to use dynamic TCP or UDP ports to communicate with the server application.
• Recognize application-specific commands and offer granular security control over them.
• Synchronize multiple streams or sessions of data between two hosts that are exchanging data.
• Translate the network-layer address information that is available in the application payload.
The firewall opens a pinhole, and NAT performs translation service on any TCP or UDP traffic that does not
carry the source and destination IP addresses in the application-layer data stream. Specific protocols or
applications that embed IP address information require the support of an ALG.
Sun RPC
The Sun remote-procedure call (RPC) application-level gateway (ALG) performs a deep packet inspection
of the Sun RPC protocol. The Sun RPC ALG works with a provisioning system that allows network
administrators to configure match filters. Each match filter define a match criterion that is searched in a Sun
RPC packet, thereby permitting only packets that match the criterion.
In an RPC, a client program calls procedures in a server program. The RPC library packages the procedure
arguments into a network message and sends the message to the server. The server, in turn, uses the RPC
library and takes the procedure arguments from the network message and calls the specified server procedure.
When the server procedure returns to the RPC, return values are packaged into a network message and sent
back to the client.
For a detailed description of the Sun RPC protocol, see RFC 1057, RPC: Remote Procedure Call Protocol
Specification Version 2.
When you configure a Sun RPC Layer 4 class map without configuring a Layer 7 firewall policy, the traffic
returned by the Sun RPC passes through the firewall, but sessions are not inspected at Layer 7. Because
sessions are not inspected, the subsequent RPC call is blocked by the firewall. Configuring a Sun RPC Layer
4 class map and a Layer 7 policy allows Layer 7 inspection. You can configure an empty Layer 7 firewall
policy, that is, a policy without any match filters.
How to Configure Sun RPC ALG Support for Firewalls and NAT
For Sun RPC to work when the firewall and NAT are enabled, the ALG must inspect Sun RPC packets. The
ALG also handles Sun RPC-specific issues such as establishing dynamic firewall sessions and fixing the
packet content after NAT translation.
SUMMARY STEPS
1. enable
2. configure terminal
3. class-map type inspect {match-any | match-all} class-map-name
4. match protocol protocol-name
5. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 class-map type inspect {match-any | match-all} Creates a Layer 4 inspect type class map and enters QoS
class-map-name class-map configuration mode.
Example:
Device(config)# class-map type inspect match-any
sunrpc-l4-cmap
Step 4 match protocol protocol-name Configures a match criterion for a class map on the basis
of the specified protocol.
Example:
Device(config-cmap)# match protocol sunrpc
SUMMARY STEPS
1. enable
2. configure terminal
3. class-map type inspect protocol-name {match-any | match-all} class-map-name
4. match program-number program-number
5. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 class-map type inspect protocol-name {match-any | Creates a Layer 7 (application-specific) inspect type class
match-all} class-map-name map and enters QoS class-map configuration mode.
Example:
Device(config)# class-map type inspect sunrpc
match-any sunrpc-l7-cmap
Step 4 match program-number program-number Specifies the allowed RPC protocol program number as
a match criterion.
Example:
Device(config-cmap)# match program-number 100005
SUMMARY STEPS
1. enable
2. configure terminal
3. policy-map type inspect protocol-name policy-map-name
4. class type inspect protocol-name class-map-name
5. allow
6. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 policy-map type inspect protocol-name Creates a Layer 7 (protocol-specific) inspect type policy
policy-map-name map and enters QoS policy-map configuration mode.
Example:
Device(config)# policy-map type inspect sunrpc
sunrpc-l7-pmap
Step 4 class type inspect protocol-name class-map-name Specifies the traffic class on which an action is to be
performed and enters QoS policy-map class configuration
Example: mode.
Device(config-pmap)# class type inspect sunrpc
sunrpc-l7-cmap
Example:
Device(config-pmap-c)# allow
Step 6 end Exits QoS policy-map class configuration mode and returns
to privileged EXEC mode.
Example:
Device(config-pmap-c)# end
SUMMARY STEPS
1. enable
2. configure terminal
3. policy-map type inspect policy-map-name
4. class {class-map-name | class-default}
5. inspect [parameter-map-name]
6. service-policy protocol-name policy-map-name
7. exit
8. class class-default
9. drop
10. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 policy-map type inspect policy-map-name Creates a Layer 4 inspect type policy map and enters QoS
policy-map configuration mode.
Example:
Device(config)# policy-map type inspect
sunrpc-l4-pmap
Step 4 class {class-map-name | class-default} Associates (class) on which an action is to be performed and
enters QoS policy-map class configuration mode.
Example:
Device(config-pmap)# class sunrpc-l4-cmap
Example:
Device(config-pmap-c)# inspect
Step 7 exit Exits QoS policy-map class configuration mode and returns
to QoS policy-map configuration mode.
Example:
Device(config-pmap-c)# exit
Step 8 class class-default Specifies the default class (commonly known as the
class-default class) before you configure its policy and enters
Example: QoS policy-map class configuration mode.
Device(config-pmap)# class class-default
Step 10 end Exits QoS policy-map class configuration mode and returns
to privileged EXEC mode.
Example:
Device(config-pmap-c)# end
Creating Security Zones and Zone Pairs and Attaching a Policy Map to a Zone Pair
You need two security zones to create a zone pair. However, you can create only one security zone and the
second one can be the system-defined security zone. To create the system-defined security zone or self zone,
configure the zone-pair security command with the self keyword.
Note If you select a self zone, you cannot configure the inspect action.
SUMMARY STEPS
1. enable
2. configure terminal
3. zone security {zone-name | default}
4. exit
5. zone security {zone-name | default}
6. exit
7. zone-pair security zone-pair-name source source-zone-name destination destination-zone-name
8. service-policy type inspect policy-map-name
9. exit
10. interface type number
11. ip address ip-address mask [secondary [vrf vrf-name]]
12. zone-member security zone-name
13. exit
14. interface type number
15. ip address ip-address mask [secondary [vrf vrf-name]]
16. zone-member security zone-name
17. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 zone security {zone-name | default} Creates a security zone and enters security zone
configuration mode.
Example: • Your configuration must have two security zones to
Device(config)# zone security z-client
create a zone pair: a source zone and a destination
zone.
• In a zone pair, you can use the default zone or self
zone as either the source or destination zone.
Step 5 zone security {zone-name | default} Creates a security zone and enters security zone
configuration mode.
Example: • Your configuration must have two security zones to
Device(config)# zone security z-server
create a zone pair: a source zone and a destination
zone.
• In a zone pair, you can use the default zone as either
the source or destination zone.
Step 6 exit Exits security zone configuration mode and returns to global
configuration mode.
Example:
Device(config-sec-zone)# exit
Step 7 zone-pair security zone-pair-name source Creates a zone pair and enters security zone-pair
source-zone-name destination destination-zone-name configuration mode.
Example:
Device(config)# zone-pair security clt2srv
source z-client destination z-server
Step 8 service-policy type inspect policy-map-name Attaches a firewall policy map to a zone pair.
Example:
Device(config-sec-zone-pair)# service-policy
type inspect sunrpc-l4-pmap
Step 10 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 2/0/0
Step 11 ip address ip-address mask [secondary [vrf Sets a primary or secondary IP address for an interface.
vrf-name]]
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# zone-member security
z-client
Step 14 interface type number Configures an interface type and enters interface
configuration mode.
Example:
Device(config)# interface gigabitethernet 2/1/1
Step 15 ip address ip-address mask [secondary [vrf Sets a primary or secondary IP address for an interface.
vrf-name]]
Example:
Device(config-if)# ip address [Link]
[Link]
Example:
Device(config-if)# zone-member security
z-server
Example: Creating Security Zones and Zone Pairs and Attaching a Policy Map
to a Zone Pair
Device# configure terminal
Device(config)# zone security z-client
Device(config-sec-zone)# exit
Device(config)# zone security z-server
Device(config-sec-zone)# exit
Device(config)# zone-pair security clt2srv source z-client destination z-server
Device(config-sec-zone-pair)# service-policy type inspect sunrpc-l4-pmap
Device(config-sec-zone-pair)# exit
Device(config)# interface gigabitethernet 2/0/0
Device(config-if)# ip address [Link] [Link]
Device(config-if)# zone-member security z-client
Device(config-if)# exit
Device(config)# interface gigabitethernet 2/1/1
Device(config-if)# ip address [Link] [Link]
Device(config-if)# zone-member security z-server
Device(config-if)# end
Security commands
• Security Command Reference: Commands A to C
• Security Command Reference: Commands D to L
• Security Command Reference: Commands M to R
• Security Command Reference: Commands S to Z
Standard/RFC Title
RFC 1057 RPC: Remote Procedure Call Protocol Specification Version
2
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Feature Information for Sun RPC ALG Support for Firewalls and
NAT
The following table provides release information about the feature or features described in this module. This
table lists only the software release that introduced support for a given feature in a given software release
train. Unless noted otherwise, subsequent releases of that software release train also support that feature.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to [Link]/go/cfn. An account on [Link] is not required.
Table 30: Feature Information for Sun RPC ALG Support for Firewalls and NAT
SUMMARY STEPS
1. enable
2. configure terminal
3. class-map type inspect match-any class-map-name
4. match protocol protocol-name
5. exit
6. policy-map type inspect policy-map-name
7. class type inspect class-map-name
8. inspect
9. class class-default
10. exit
11. exit
12. zone security zone-name1
13. exit
14. zone security zone-name2
15. exit
16. zone-pair security zone-pair-name source source-zone-name destination destination-zone-name
17. service-policy type inspect policy-map-name
18. exit
19. interface type number
20. zone-member security zone-name1
21. exit
22. interface type number
23. zone-member security zone-name
24. end
DETAILED STEPS
Example:
Router# configure terminal
Example:
Router(config)# class-map type inspect
match-any rtsp_class1
Step 4 match protocol protocol-name Configures the match criteria for a class map on the basis of the
named protocol.
Example: • Use DNS in place of RTSP to configure DNS as the match
Router(config-cmap)# match protocol rtsp protocol.
Example:
Router(config-cmap)# exit
Step 6 policy-map type inspect policy-map-name Creates an inspect type policy map and enters policy-map
configuration mode.
Example:
Router(config)# policy-map type inspect
rtsp_policy
Step 7 class type inspect class-map-name Specifies the class on which the action is performed and enters
policy-map-class configuration mode.
Example:
Router(config-pmap)# class type inspect
rtsp_class1
Example:
Router(config-pmap-c)# inspect
Step 9 class class-default Specifies that these policy map settings apply to the predefined
default class. If traffic does not match any of the match criteria
Example: in the configured class maps, it is directed to the predefined
default class.
Router(config-pmap-c)# class class-default
Example:
Router(config-pmap-c)# exit
Example:
Router(config-pmap)# exit
Step 12 zone security zone-name1 Creates a security zone to which interfaces can be assigned and
enters security-zone configuration mode.
Example:
Router(config)# zone security private
Example:
Router(config-sec-zone)# exit
Step 14 zone security zone-name2 Creates a security zone to which interfaces can be assigned and
enters security-zone configuration mode.
Example:
Router(config)# zone security public
Example:
Router(config-sec-zone)# exit
Step 16 zone-pair security zone-pair-name source Creates a pair of security zones and enters security-zone-pair
source-zone-name destination configuration mode.
destination-zone-name
• To apply a policy, you must configure a zone pair.
Example:
Router(config)# zone-pair security pair-two
source private destination public
Step 17 service-policy type inspect policy-map-name Attaches a firewall policy map to the destination zone pair.
• If a policy is not configured between a pair of zones, traffic
Example: is dropped by default.
Router(config-sec-zone-pair)#
service-policy rtsp_policy
Example:
Router(config-sec-zone-pair)# exit
Example:
Router(config-if)# exit
Example:
Router(config-if)# end
Troubleshooting Tips
The following commands can be used to troubleshoot your RTSP-enabled configuration:
• clear zone-pair
Cisco Firewall--SIP Enhancements: ALG Security Configuration Guide: Securing the Data
Plane
Standard/RFC Title
RFC 793 Transport Control Protocol
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to [Link]/go/cfn. An account on [Link] is not required.
Application-Level Gateways
An application-level gateway (ALG), also known as an application-layer gateway, is an application that
translates the IP address information inside the payload of an application packet. An ALG is used to interpret
the application-layer protocol and perform firewall and Network Address Translation (NAT) actions. These
actions can be one or more of the following depending on your configuration of the firewall and NAT:
• Allow client applications to use dynamic TCP or UDP ports to communicate with the server application.
• Recognize application-specific commands and offer granular security control over them.
• Synchronize multiple streams or sessions of data between two hosts that are exchanging data.
• Translate the network-layer address information that is available in the application payload.
The firewall opens a pinhole, and NAT performs translation service on any TCP or UDP traffic that does not
carry the source and destination IP addresses in the application-layer data stream. Specific protocols or
applications that embed IP address information require the support of an ALG.
• H.323 Gateway—This element provides protocol conversion between H.323 terminals and other terminals
that do not support H.323.
• H.323 Gatekeeper—This element provides services like address translation, network access control, and
bandwidth management and account for H.323 terminals and gateways.
In addition to the protocols listed, the H.323 specification describes the use of various IETF protocols like
the Real Time Transport (RTP) protocol and audio (G.711, G.729, and so on) and video (H.261, H.263, and
H.264) codecs.
NAT requires a variety of ALGs to handle Layer 7 protocol-specific services such as translating embedded
IP addresses and port numbers in the packet payload and extracting new connection/session information from
control channels. The H.323 ALG performs these specific services for H.323 messages.
1. enable
2. configure terminal
3. interface type number
4. ip nat inside
5. exit
6. interface type number
7. ip nat outside
8. exit
9. ip nat pool pool-name start-ip end-ip prefix-length prefix-length
10. ip nat inside source list pool pool-name
11. access-list access-list-number permit source [source-wildcard]
12. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/1
Step 4 ip nat inside Indicates that the interface is connected to the inside
network (the network that is subject to NAT translation).
Example:
Device(config-if)# ip nat inside
Step 6 interface type number Configures an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/1/1
Step 7 ip nat outside Indicates that the interface is connected to the outside
network.
Example:
Device(config-if)# ip nat outside
Step 9 ip nat pool pool-name start-ip end-ip prefix-length Defines a pool of IP addresses for NAT.
prefix-length
Example:
Device(config)# ip nat pool pool1 [Link]
[Link] prefix-length 24
Example:
Device(config)# ip nat inside source list pool
pool1
Step 11 access-list access-list-number permit source Defines a standard IP access list and permits access to
[source-wildcard] packets if conditions are matched.
Example:
Device(config)# access-list 1 permit [Link]
[Link]
The following is sample output from the show ip nat statistics command:
Device# show ip nat statistics
Example: Configuring ALG-H.323 vTCP with High Availability Support for NAT
Device# configure terminal
Device(config)# interface gigabitethernet 0/0/1
Device(config-if)# ip nat inside
Device(config-if)# exit
Device(config)# interface gigabitethernet 0/1/1
Device(config-if)# ip nat outside
Device(config-if)# exit
Device(config)# ip nat pool pool1 [Link] [Link] prefix-length 24
Device(config)# ip nat inside source list pool pool1
Device(config)# access-list 1 permit [Link] [Link]
Device(config)# end
Firewall commands
• Security Command Reference: Commands A to C
• Security Command Reference: Commands D to L
• Security Command Reference: Commands M to R
• Security Command Reference: Commands S to Z
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Table 32: Feature Information for ALG—H.323 vTCP with High Availability Support for Firewall and NAT
The above enhancements are available by default; no additional configuration is required on NAT or firewall.
This module explains the SIP ALG enhancements and describes how to enable NAT and firewall support
for SIP.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to [Link]/go/cfn. An account on [Link] is not required.
Application-Level Gateways
An application-level gateway (ALG), also known as an application-layer gateway, is an application that
translates the IP address information inside the payload of an application packet. An ALG is used to interpret
the application-layer protocol and perform firewall and Network Address Translation (NAT) actions. These
actions can be one or more of the following depending on your configuration of the firewall and NAT:
• Allow client applications to use dynamic TCP or UDP ports to communicate with the server application.
• Recognize application-specific commands and offer granular security control over them.
• Synchronize multiple streams or sessions of data between two hosts that are exchanging data.
• Translate the network-layer address information that is available in the application payload.
The firewall opens a pinhole, and NAT performs translation service on any TCP or UDP traffic that does not
carry the source and destination IP addresses in the application-layer data stream. Specific protocols or
applications that embed IP address information require the support of an ALG.
Note Because all Layer 7 data is managed by SIP ALG by using a local database, SIP ALG never replies on
firewall and NAT to free SIP Layer 7 data; SIP ALG frees the data by itself. If you use the clear command
to clear all NAT translations and firewall sessions, the SIP Layer 7 data in the local database is not freed.
• OPTIONS
• 1XX (excluding 100,180,183)
• 2XX (excluding 200)
The existing SIP methods that are logged in SIP ALG statistics include ACK, BYE, CANCEL, INFO, INVITE,
MESSAGE, NOTIFY, REFER, REGISTER, SUBSCRIBE, and 1XX-6XX.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat service sip {tcp | udp} port port-number
4. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 ip nat service sip {tcp | udp} port port-number Enables NAT support for SIP.
Example:
Device(config)# ip nat service sip tcp port 5060
1. enable
2. configure terminal
3. class-map type inspect match-any class-map-name
4. match protocol protocol-name
5. exit
6. policy-map type inspect policy-map-name
7. class type inspect class-map-name
8. inspect
9. exit
10. class class-default
11. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 class-map type inspect match-any Creates an inspect type class map and enters class-map
class-map-name configuration mode.
Example:
Device(config)# class-map type inspect
match-any sip-class1
Step 4 match protocol protocol-name Configures the match criterion for a class map based on the
named protocol.
Example:
Device(config-cmap)# match protocol sip
Example:
Device(config-cmap)# exit
Step 7 class type inspect class-map-name Specifies the class on which the action is performed and
enters policy-map class configuration mode.
Example:
Device(config-pmap)# class type inspect
sip-class1
Example:
Device(config-pmap-c)# inspect
Step 10 class class-default Specifies that these policy map settings apply to the
predefined default class.
Example: • If traffic does not match any of the match criteria in the
Device(config-pmap)# class class-default
configured class maps, it is directed to the predefined
default class.
1. enable
2. configure terminal
3. zone security {zone-name | default}
4. exit
5. zone security {zone-name | default}
6. exit
7. zone-pair security zone-pair-name [source {source-zone-name | self | default} destination
[destination-zone-name | self | default]]
8. service-policy type inspect policy-map-name
9. exit
10. interface type number
11. zone-member security zone-name
12. exit
13. interface type number
14. zone-member security zone-name
15. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 zone security {zone-name | default} Creates a security zone to which interfaces can be assigned and
enters security zone configuration mode.
Example:
Device(config)# zone security zone1
Step 4 exit Exits security zone configuration mode and returns to global
configuration mode.
Example:
Device(config-sec-zone)# exit
Step 6 exit Exits security zone configuration mode and returns to global
configuration mode.
Example:
Device(config-sec-zone)# exit
Step 7 zone-pair security zone-pair-name [source Creates a zone pair and returns to security zone-pair
{source-zone-name | self | default} destination configuration mode.
[destination-zone-name | self | default]] Note To apply a policy, you must configure a zone
pair.
Example:
Device(config)# zone-pair security in-out
source zone1 destination zone2
Step 8 service-policy type inspect policy-map-name Attaches a firewall policy map to the destination zone pair.
Note If a policy is not configured between a pair of zones,
Example: traffic is dropped by default.
Device(config-sec-zone-pair)# service-policy
type inspect sip-policy
Step 10 interface type number Configures an interface and enters interface configuration mode.
Example:
Device(config)# interface gigabitethernet
0/0/0
Example:
Device(config)# interface gigabitethernet
0/1/1
Example:
Device(config-if)# zone-member security
zone2
!
interface gigabitethernet 0/0/0
zone security zone1
!
interface gigabitethernet 0/1/1
zone security zone2
Firewall commands
• Cisco IOS Security Command Reference: Commands A to C
• Cisco IOS Security Command Reference: Commands D to L
• Cisco IOS Security Command Reference: Commands M to R
• Cisco IOS Security Command Reference: Commands S to Z
NAT and firewall ALG support NAT and Firewall ALG and AIC Support on Cisco ASR 1000 Series
Aggregation Services Routers matrix
Standard/RFC Title
RFC 3261 SIP: Session Initiation Protocol
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Feature Information for SIP ALG Hardening for NAT and Firewall
The following table provides release information about the feature or features described in this module. This
table lists only the software release that introduced support for a given feature in a given software release
train. Unless noted otherwise, subsequent releases of that software release train also support that feature.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to [Link]/go/cfn. An account on [Link] is not required.
Table 33: Feature Information for SIP ALG Hardening for NAT and Firewall
lock limit, a dynamic blacklist, and configurable timers to prevent DoS attacks. This feature is supported by
Network Address Translation (NAT) and zone-based policy firewalls.
SIP is an application-level signaling protocol for setting up, modifying, and terminating real-time sessions
between participants over an IP data network. These sessions could include Internet telephone calls, multimedia
distribution, and multimedia conferences. SIP DoS attacks are a major threat to networks.
The following are types of SIP DoS attacks:
• SIP register flooding: A registration flood occurs when many VoIP devices try to simultaneously register
to a network. If the volume of registration messages exceeds the device capability, some messages are
lost. These devices then attempt to register again, adding more congestion. Because of the network
congestion, users may be unable to access the network for some time.
• SIP INVITE flooding: An INVITE flood occurs when many INVITE messages are sent to servers that
cannot support all these messages. If the attack rate is very high, the memory of the server is exhausted.
• SIP broken authentication and session attack: This attack occurs when an attacker presumes the identity
of a valid user, using digest authentication. When the authentication server tries to verify the identity of
the attacker, the verification is ignored and the attacker starts a new request with another session identity.
These attacks consume the memory of the server.
When the configured maximum time is reached, the SIP application layer gateway (ALG) releases resources
for this call, and future messages related to this call may not be properly parsed by the SIP ALG.
SUMMARY STEPS
1. enable
2. configure terminal
3. alg sip processor session max-backlog concurrent-processor-usage
4. alg sip processor global max-backlog concurrent-processor-usage
5. alg sip blacklist trigger-period trigger-period trigger-size minimum-events destination ip-address
6. alg sip blacklist trigger-period trigger-period trigger-size minimum-events block-time block-time
[destination ip-address]
7. alg sip timer call-proceeding-timeout time
8. alg sip timer max-call-duration seconds
9. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 alg sip processor session max-backlog Sets a per session limit for the number of backlog
concurrent-processor-usage messages waiting for shared resources.
Example:
Device(config)# alg sip processor session max-backlog
5
Step 4 alg sip processor global max-backlog Sets the maximum number of backlog messages
concurrent-processor-usage waiting for shared resources for all SIP sessions.
Example:
Device(config)# alg sip processor global max-backlog
5
Step 5 alg sip blacklist trigger-period trigger-period trigger-size Configures dynamic SIP ALG blacklist criteria for the
minimum-events destination ip-address specified destination IP address.
Example:
Device(config)# alg sip blacklist trigger-period 90
trigger-size 30 destination [Link]
Step 6 alg sip blacklist trigger-period trigger-period trigger-size Configures the time period, in seconds, when packets
minimum-events block-time block-time [destination from a source are blocked if the configured limit is
ip-address] exceeded.
Example:
Device(config)# alg sip blacklist trigger-period 90
trigger-size 30 block-time 30
Step 7 alg sip timer call-proceeding-timeout time Sets the maximum time interval, in seconds, to end
SIP calls that do not receive a response.
Example:
Device(config)# alg sip timer call-proceeding-timeout
35
Step 8 alg sip timer max-call-duration seconds Sets the maximum call duration, in seconds, for a
successful SIP call.
Example:
Device(config)# alg sip timer max-call-duration 90
SUMMARY STEPS
1. enable
2. show alg sip
3. show platform hardware qfp {active | standby} feature alg statistics sip
4. show platform hardware qfp {active | standby} feature alg statistics sip dbl
5. show platform hardware qfp {active | standby} feature alg statistics sip dblcfg
6. show platform hardware qfp {active | standby} feature alg statistics sip processor
7. show platform hardware qfp {active | standby} feature alg statistics sip timer
8. debug alg {all | info | trace | warn}
DETAILED STEPS
Step 1 enable
Example:
Device> enable
Enables privileged EXEC mode.
• Enter your password if prompted.
Example:
Device# show alg sip
Example:
Device# show platform hardware qfp active feature alg statistics sip
Events
...
Cr dbl entry: 10 Del dbl entry: 10
Cr dbl cfg entry: 8 Del dbl cfg entry: 4
start dbl trig tmr: 10 restart dbl trig tmr: 1014
stop dbl trig tmr: 10 dbl trig timeout: 1014
start dbl blk tmr: 0 restart dbl blk tmr: 0
stop dbl blk tmr: 0 dbl blk tmr timeout: 0
start dbl idle tmr: 10 restart dbl idle tmr: 361
stop dbl idle tmr: 1 dbl idle tmr timeout: 9
DoS Errors
Dbl Retmem Failed: 0 Dbl Malloc Failed: 0
DblCfg Retm Failed: 0 DblCfg Malloc Failed: 0
Session wlock ovflw: 0 Global wlock ovflw: 0
Blacklisted: 561
Step 4 show platform hardware qfp {active | standby} feature alg statistics sip dbl
Displays brief information about all SIP blacklist data.
Example:
Device# show platform hardware qfp active feature alg statistics sip dbl
Step 5 show platform hardware qfp {active | standby} feature alg statistics sip dblcfg
Displays all SIP blacklist settings.
Example:
Device# show platform hardware qfp active feature alg statistics sip dblcfg
Step 6 show platform hardware qfp {active | standby} feature alg statistics sip processor
Displays SIP processor settings.
Example:
Device# show platform hardware qfp active feature alg statistics sip processor
Step 7 show platform hardware qfp {active | standby} feature alg statistics sip timer
Displays SIP timer settings.
Example:
Device# show platform hardware qfp active feature alg statistics sip timer
Example:
Device# debug alg warn
Firewall commands
• Cisco IOS Security Command Reference: Commands
A to C
• Cisco IOS Security Command Reference: Commands
D to L
• Cisco IOS Security Command Reference: Commands
M to R
• Cisco IOS Security Command Reference: Commands
S to Z
Standard/RFC Title
RFC 4028 Session Timers in the Session Initiation Protocol (SIP)
MIBs
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Table 34: Feature Information for SIP ALG Resilience to DoS Attacks
Note All NAT commands that support VRF support the match-in-vrf keyword. Because NAT outside rules
(ip nat outside source command) support the match-in-VRF functionality by default, the match-in-vrf
keyword is not supported by NAT outside rules.
In VRF-aware NAT, the IP alias and Address Resolution Protocol (ARP) entries for inside global addresses
are configured in the global domain. For intra-VPN NAT, the IP alias and ARP entries for inside global
addresses are configured in the VRF through which the translation happens. In intra-VPN NAT, configuration
of the match-in-vrf keyword implies that at least one NAT outside interface is configured in the same VRF.
The ARP entry in that VRF replies to the ARP request from the outside host.
If inside addresses are configured, the match-in-VRF is determined through inside mappings during the address
translation of VRF traffic. If you have configured only outside mapping of IP addresses for address translations,
the match-in-VRF will work. When a translation entry is created with both inside and outside mappings, the
match-in-vrf keyword is determined by the inside mapping.
The Match-in-VRF Support for NAT feature supports the configuration of multiple dynamic mappings with
the same IP address pool.
The following table provides you information about VRF support for NAT:
MPLS IP VRF
Note You must use the match-in-vrf keyword in
the configuration to indicate that
communication is occurring within the VRF.
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source static local-ip global-ip [vrf vrf-name [match-in-vrf]]
4. interface type number
5. ip address ip-address mask [secondary]
6. ip nat inside
7. ip vrf forwarding vrf-name
8. exit
9. interface type number
10. ip address ip-address mask
11. ip nat outside
12. ip vrf forwarding vrf-name
13. end
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat inside source static local-ip global-ip [vrf Establishes static translation between an inside local
vrf-name [match-in-vrf]] address and an inside global address.
• The match-in-vrf keyword enables NAT inside and
Example: outside traffic in the same VRF.
Router(config)# ip nat inside source static
[Link] [Link] vrf vrf1 match-in-vrf
Step 4 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Router(config)# interface gigabitethernet 0/0/1
Step 5 ip address ip-address mask [secondary] Sets a primary IP address for an interface.
Example:
Router(config-if)# ip address [Link]
[Link]
Example:
Router(config-if)# ip nat inside
Example:
Router(config-if)# ip vrf forwarding vrf1
Step 9 interface type number Specifies a different interface and enters interface
configuration mode.
Example:
Router(config)# interface gigabitethernet 0/0/0
Example:
Router(config-if)# ip address [Link]
[Link]
Example:
Router(config-if)# ip vrf forwarding vrf1
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat inside source list access-list-number pool pool-name [vrf vrf-name [match-in-vrf]]
4. access-list access-list-number permit source [source-wildcard]
5. ip nat inside source list access-list-number pool pool-name vrf vrf-name [match-in-vrf]
6. interface type number
7. ip address ip-address mask
8. ip nat inside
9. ip vrf forwarding vrf-name
10. exit
11. interface type number
12. ip address ip-address mask
13. ip nat outside
14. ip vrf forwarding vrf-name
15. end
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat inside source list access-list-number pool Enables multiple dynamic mappings to be configured
pool-name [vrf vrf-name [match-in-vrf]] with the same address pool.
• The match-in-vrf keyword enables NAT inside
Example: and outside traffic in the same VRF.
Router(config)# ip nat inside source list 1 pool
shared-pool vrf vrf1 match-in-vrf
Step 4 access-list access-list-number permit source Defines a standard access list permitting those addresses
[source-wildcard] that are to be translated.
Example:
Router(config)# access-list 1 permit [Link]
[Link]
Example:
Router(config)# ip nat inside source list 1 pool
shared-pool vrf vpn1
Step 6 interface type number Specifies an interface and enters interface configuration
mode.
Example:
Router(config)# interface gigabitethernet 0/0/1
Example:
Router(config-if)# ip address [Link]
[Link]
Example:
Router(config-if)# ip nat inside
Example:
Router(config-if)# ip vrf forwarding vpn1
Step 11 interface type number Specifies a different interface and enters interface
configuration mode.
Example:
Router(config)# interface gigabitethernet 0/0/0
Example:
Router(config-if)# ip address [Link]
[Link]
Example:
Router(config-if)# ip vrf forwarding vpn1
NAT commands: complete command syntax, Cisco IOS IP Addressing Services Command
command mode, command history, usage guidelines, Reference
and examples
Using NAT with MPLS VPNs “Integrating NAT with MPLS VPNs” module
Standard/RFC Title
RFC 903 Reverse Address Resolution Protocol
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
Uses of NAT
NAT can be used for the following applications:
• When you want to connect to the Internet, but not all of your hosts have globally unique IP addresses.
NAT enables private IP internetworks that use nonregistered IP addresses to connect to the Internet.
NAT is configured on the router at the border of a stub domain (referred to as the inside network) and
a public network such as the Internet (referred to as the outside network). NAT translates internal local
addresses to globally unique IP addresses before sending packets to the outside network. As a solution
to the connectivity problem, NAT is practical only when relatively few hosts in a stub domain
communicate outside of the domain at the same time. When this is the case, only a small subset of the
IP addresses in the domain must be translated into globally unique IP addresses when outside
communication is necessary, and these addresses can be reused when they are no longer in use.
• When you must change your internal addresses. Instead of changing the internal addresses, which can
be a considerable amount of work, you can translate them by using NAT.
• When you want to do basic load sharing of TCP traffic. You can map a single global IP address to many
local IP addresses by using the TCP load distribution feature.
Similarly, the term outside refers to those networks to which the stub network connects, and which are generally
not under the control of an organization. Hosts in outside networks can also be subject to translation, and can
thus have local and global addresses. NAT uses the following definitions:
• Inside local address—An IP address that is assigned to a host on the inside network. The address is
probably not a legitimate IP address assigned by the Network Information Center (NIC) or service
provider.
• Inside global address—A legitimate IP address (assigned by the NIC or service provider) that represents
one or more inside local IP addresses to the outside world.
• Outside local address—The IP address of an outside host as it appears to the inside network. Not
necessarily a legitimate address, it is allocated from the address space that is routable on the inside.
• Outside global address—The IP address assigned to a host on the outside network by the owner of the
host. The address is allocated from a globally routable address or network space.
VRF X Global VRF (also referred to as When NAT is not configured for
non-VRF interface) Match-in-VRF support. For more
details, refer to the Match-in-VRF
support for NAT chapter.
Note When inside global or outside local addresses belong to a directly connected subnet on a NAT router, the
router will add IP aliases for them so that it can answer Address Resolution Protocol (ARP) requests.
However, a situation can arise where the router itself answers packets that are not destined for it, possibly
causing a security issue. This can happen when an incoming Internet Control Message Protocol (ICMP)
or UDP packet that is destined for one of the aliased addresses does not have a corresponding NAT
translation in the NAT table, and the router itself runs a corresponding service, for example, the Network
Time Protocol (NTP). Such a situation might cause minor security risks.
Note IP multicast dynamic translation establishes a one-to-one mapping between an inside local address and
one of the addresses from the pool of outside global addresses
SUMMARY STEPS
1. enable
2. configure terminal
3. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length} [type {match-host |
rotary}]
4. access-list access-list-number permit source-address wildcard-bits [any]
5. ip nat inside source list access-list-number pool name
6. ip multicast-routing distributed
7. interface type number
8. ip address ip-address mask
9. ip pim sparse-mode
10. ip nat inside
11. exit
12. interface type number
13. ip address ip-address mask
14. ip pim sparse-mode
15. ip nat outside
16. end
DETAILED STEPS
Example:
Router# configure terminal
Step 3 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of global addresses to be allocated as
prefix-length prefix-length} [type {match-host | rotary}] needed.
Example:
Router(config)# ip nat pool mypool [Link]
[Link] netmask [Link]
Step 4 access-list access-list-number permit source-address Defines a standard access list for the inside addresses
wildcard-bits [any] that are to be translated.
Example:
Router(config)# access-list 100 permit [Link]
[Link] any
Step 5 ip nat inside source list access-list-number pool name Establishes dynamic source translation, specifying the
access list defined in the prior step.
Example:
Router(config)# ip nat inside source list 100
pool mypool
Example:
Router(config)# ip multicast-routing distributed
Step 8 ip address ip-address mask Sets a primary or secondary IP address for an interface.
Example:
Router(config-if)# ip address [Link]
[Link]
Step 10 ip nat inside Indicates that the interface is connected to the inside
network (the network that is subject to NAT translation).
Example:
Router(config-if)# ip nat inside
Step 13 ip address ip-address mask Sets a primary or secondary IP address for an interface.
Example:
Router(config-if)# ip address [Link]
[Link]
Example:
Router(config-if)# ip pim sparse-mode
Step 15 ip nat outside Indicates that the interface is connected to the outside
network.
Example:
Router(config-if)# ip nat outside
Additional References
Related Documents
Configuring NAT for IP address conservation Configuring NAT for IP Address Conservation
module
Standard/RFC Title
None —
MIBs
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
• The PPTP ALG will not work in Carrier Grade Network Address Translation (NAT) mode, when the
NAT client and server use the same call ID.
SUMMARY STEPS
1. enable
2. configure terminal
3. interface type number
4. ip nat inside
5. exit
6. interface type number
7. ip nat outside
8. exit
9. ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length}
10. ip nat inside source list {access-list-number | access-list-name} pool name overload
11. ip access-list standard access-list-name
12. permit host-ip
13. end
DETAILED STEPS
Example:
Device# configure terminal
Step 3 interface type number Enables an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/0/1
Step 6 interface type number Enables an interface and enters interface configuration
mode.
Example:
Device(config)# interface gigabitethernet 0/1/0
Example:
Device(config-if)# ip nat outside
Step 9 ip nat pool name start-ip end-ip {netmask netmask | Defines a pool of IP addresses for NAT translations.
prefix-length prefix-length}
Example:
Device(config)# ip nat pool pptp-pool
[Link] [Link] prefix-length 24
Step 10 ip nat inside source list {access-list-number | Enables NAT of the inside source address.
access-list-name} pool name overload
• When overloading is configured, the TCP or UDP
port number of each inside host distinguishes between
Example: multiple conversations by using the same local IP
Device(config)# ip nat inside source list
pptp-acl pool pptp-pool overload address.
Step 11 ip access-list standard access-list-name Defines a standard IP access list by name to enable packet
filtering and enters standard access-list configuration mode.
Example:
Device(config)# ip access-list standard
pptp-acl
Step 12 permit host-ip Sets conditions in named IP access lists that permit packets.
Example:
Device(config-std-nacl)# permit [Link]
Standard/RFC Title
RFC 2637 Point-to-Point Tunneling Protocol (PPTP)
Technical Assistance
Description Link
The Cisco Support website provides extensive online [Link]
resources, including documentation and tools for
troubleshooting and resolving technical issues with
Cisco products and technologies.
To receive security and technical information about
your products, you can subscribe to various services,
such as the Product Alert Tool (accessed from Field
Notices), the Cisco Technical Services Newsletter,
and Really Simple Syndication (RSS) Feeds.
Access to most tools on the Cisco Support website
requires a [Link] user ID and password.
Configuring NPTv6
You can configure the inside and outside prefix for NPTv6 translation.
To configure NPTv6 support on ASR1k/CSR1k/ISR4k:
enable
configure terminal
interface GigabitEthernet0/0/0
nat66 inside
interface GigabitEthernet0/0/1
nat66 outside
nat66 prefixinside 2002:AB01::/64outside 2002:AB02::/64
end
Global Stats:
Packets translated (In -> Out)
: 7
Packets translated (Out -> In)
: 7
Use the show platform hardware qfp active feature nat66 datapath basecfg command to verify the global
stateless NPTv6 prefix in the data plane along with other base configuration information:
Device# show platform hardware qfp active feature nat66 datapath basecfg
nat66 cfg_flags 0x00000001, dbg_flags 0x00000000
nat66_prefix_hash_table_entries 2048, nat66_prefix_hash_table 0x89628400
prefix hasht 0x89628400 max 2048 chunk 0x8c392bb0 hash_salt 719885386
Use the show platform hardware qfp active feature nat66 datapath prefix command to verify the passed
interfaces stateless NPTv6 prefix configuration:
Device# show platform hardware qfp active feature nat66 datapath prefix
prefix hasht 0x89628400 max 2048 chunk 0x8c392bb0 hash_salt 719885386
NAT66 hash[1] id(1) len(64) vrf(0) in: 2002:ab01:0000:0000:0000:0000:0000:0000 out:
2002:ab02:0000:0000:0000:0000:0000:0000 in2out: 7 out2in: 7
Use the show platform hardware qfp active feature nat66 datapath statistics to verify the global NPTv6
statistics.
Device# show platform hardware qfp act feat nat66 data statistics
in2out xlated pkts 7
out2in xlated pkts 7
NAT66_DROP_SC_INVALID_PKT 0
NAT66_DROP_SC_BAD_DGLEN 0
NAT66_DROP_SC_PLU_FAIL 22786
NAT66_DROP_SC_PROCESS_V6_ERR 0
NAT66_DROP_SC_INVALID_EMBEDDED 0
NAT66_DROP_SC_SRC_RT 0
NAT66_DROP_SC_NOT_ENABLED 0
NAT66_DROP_SC_NO_GPM 0
NAT66_DROP_SC_LOOP 0
in2out_pkts 22768 out2in_pkts 22793
in2out_pkts_untrans 22761 out2in_pkts_untrans 22786
in2out_lookup_pass 7 out2in_lookup_pass 7
in2out_lookup_fail 0 out2in_lookup_fail 22786
mem_alloc_fail 0 prefix_fail 0
total prefix count 1
Troubleshooting Tips
You must make sure that the inside and outside interfaces are configured.
Use the following debug commands if you have any configuration issues:
• debug platform hardware qfp active feature nat66 datapath detailed- Provides detailed debugging
information about the data plane layer.
• debug platform hardware qfp active feature nat66 datapath all- Displays debugging information
about the data plane layer.
• debug platform condtion feature nat66 datapath submode detailed- Provides data plane layer
debugging information using buginf_cond. ACL filter can be supplied via the debug condition
infrastructure.
The figure below illustrates NPTv6 deployment in redundancy and load-sharing network.
Multihoming
In a multihomed network the NPTv6 Translators are attached to an internal network, but are connected to
different external networks. The NPTv6 Translators are configured with the same internal prefix but different
external prefixes. Since there are multiple translations, the NPTv6 Translator maps multiple external addresses
to the common internal address.
The figure below illustrates NPTv6 deployment in multihoming network.
Standard/RFC Title
RFC 6296 IPv6-to-IPv6 Network Prefix Translation
Technical Assistance
Description Link
The Cisco Support and Documentation website [Link]
provides online resources to download documentation,
software, and tools. Use these resources to install and
configure the software and to troubleshoot and resolve
technical issues with Cisco products and technologies.
Access to most tools on the Cisco Support and
Documentation website requires a [Link] user ID
and password.
The ip nat settings interface-overload block port command blocks a single port in the port range from
being used for interface overload mapping. You can use this command for a well-known port; for example,
where an application needs unrestricted access to a specific port on the NAT router. If you use this command
for a port that is already part of a range used for interface overload mapping, the existing translations for the
port are cleared.
Note If you change the range when there are already interface overload mappings configured on the router, it
results in an error. In such a situation, you can either remove all interface overload mappings and configure
them again or restart the router.
Note The ip nat settings interface-overload port range command configures the ports for all interface based
mappings—you cannot set a range of ports per interface.
udp:
5062 - 6085 (config) rfcnt 1
545 - 617 (config) rfcnt 1