Re: ip tcp intercept + nat

From: Ovidiu Neghina (o.neghina@gmail.com)
Date: Fri May 25 2007 - 16:14:26 ART


It is ok.
Thank you all for confirming.
I was doing a lab and run in some troubles cause i was matching the outside
address in the tcp intercept access list.

Ovidiu
On 5/25/07, Vince Mashburn <cciegroupstudy@gmail.com> wrote:
>
> THat is correct. If your routing table does not contain a un-natted
> address with a destination out of your LAN interface, it will never be sent
> to the LAN interface. What kinds of problems are you having?
>
> On 5/24/07, Ovidiu Neghina <o.neghina@gmail.com> wrote:
> >
> > Hi dear all
> > Thank you for answers related to Frame Relay interface.
> > I have another question
> >
> > for this simple topology
> > ----------LAN server ------------R1------outside interface
> >
> > where we have configured on R1 static nat of LAN server to outside
> > interface in the command
> > ip tcp intercept list 199
> > 199 should reference the inside local ip address (LAN) and not inside
> > global
> > address (outside interface) because of order of operation in nat .
> > always first nat then tcp intercept.
> > please correct me if i am wrong . i am having problems with a lab .
> >
> >
> > Thank you,
> >
> > Ovidiu
> >
> > _______________________________________________________________________
> > Subscription information may be found at:
> > http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Fri Jun 01 2007 - 06:55:22 ART