networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 7 posts ] 
Author Message
PostPosted: Thu Aug 02, 2012 6:26 pm 
Offline
Member
Member
User avatar

Joined: Wed Jan 21, 2009 2:31 pm
Posts: 115
Location: Los Angeles, CA
I have the following scenario:

a) one router with two ethernet interfaces (LANs) and a serial interface. The serial interface is connected to the internet, dynamic nat is used for hosts in the two lans. A web server has a private address of 172.168.50.10 and it is being translated to the internet with serial's interface 68.32.x.x (public ip) with static nat. Clients in the internet type the public address to access the web server.

b)Problem: clients inside the LANs cannot access the web server by typing the public address, they use the server's private address instead, this create a problem with DNS static entries in the HOSTS file in the OS. It is a test server and is only available to authenticated users (lock and key ACLs), so no need to make a real DNS record. The entry in the HOSTS file points to the public address.

c)Question: how can a create a route map to change the public address in the HOST file to the private address of the test web server everytime a user in the LANs type the domain name.

I hope I'm being cleare

Thanks in advance

_________________
Angel Cool
Electronics and Computer Engineering Technology AS, CCNA.
www.angelcool.net


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 11:18 am 
Offline
Senior Member
Senior Member
User avatar

Joined: Fri Sep 25, 2009 2:28 pm
Posts: 266
Location: Upstate NY
Certs: A+, Network+, CCENT, CCNA
First note I will make is, I'm a little rusty on my (assumption of you using windows client/server environment) on windows environment. Second, If I'm wrong I'm sure someone will correct me. With that said... I don't think that a route map would be the way to go. If it was me (obviously I don't know anything about your environment) I would probably just create a batch script that would be pushed out from Active Directory when a user logs in and makes the edit in the HOST table. Once you have the batch script written, having it pushed out from AD would be easy to do. If someone else has a better way of doing it I'm sure that they will mention it and correct me if I'm wrong. I hope this helps.

-J


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 11:24 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8458
Location: Frederick MD
Certs: Instanity
split-brain DNS is what you need
or if you are running an ASA firewall, you can fixup the DNS protocol to make the translation happen automagically

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 11:27 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5150
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
Not sure DNS will help if he's using HOSTS files...

Route maps also isn't the answer I don't think. I think destination NAT is what you need here.

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 11:29 am 
Offline
Member
Member
User avatar

Joined: Wed Jan 21, 2009 2:31 pm
Posts: 115
Location: Los Angeles, CA
I belive i found the solution, NAT Virtual Interface.

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtnatvi.html

It removes inside & outside terminology, so two same interfaces(eg: before, 2 insides) can have translation.

I must say that the hosts are in one lan and the web server in the other lan. Settin up my lab to find out.

_________________
Angel Cool
Electronics and Computer Engineering Technology AS, CCNA.
www.angelcool.net


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 12:10 pm 
Offline
Member
Member
User avatar

Joined: Wed Jan 21, 2009 2:31 pm
Posts: 115
Location: Los Angeles, CA
YEAAHH! it works like a charm! :dance: :lol: :cheers: :woohoo:

i''ll go for a walk and start documenting this, i'll post my set up ltr today. :thankyou:

_________________
Angel Cool
Electronics and Computer Engineering Technology AS, CCNA.
www.angelcool.net


Top
 Profile  
 
PostPosted: Sat Aug 04, 2012 11:53 am 
Offline
Member
Member
User avatar

Joined: Wed Jan 21, 2009 2:31 pm
Posts: 115
Location: Los Angeles, CA
Here you go:

http://10-network.net/angelcool.net/sph ... 804-094135

I welcome any feedback.

Thanks. Angel

_________________
Angel Cool
Electronics and Computer Engineering Technology AS, CCNA.
www.angelcool.net


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: carfret, Exabot [Bot], Exstart, Google Feedfetcher, totaluser, xp4000 and 26 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group