Lammle.com
  • Instructor-Led Training
    • Browse by Course
      • All Courses
      • CompTIA Courses
      • CiscoŽ Courses
      • Microsoft Courses
      • Wireless Courses
      • IT & Security Courses
      • Attend Online
    • Browse by Date
    • Browse by City
    • Deals and Discounts
      • Spring Specials
      • From CCENT to CCNA in 2 Weeks
      • From CCNA to CCNP in 3 Weeks
      • Corporate Solutions
      • Government Solutions
        • Government Solutions
        • GSA Pricing
      • Recent Newsletters
    • Corporate Solutions
    • Government Solutions
      • Government Solutions
      • GSA Pricing
    • Testimonials
    • Internetworking Salary Survey
  • Locations
    • Atlanta
    • Austin
    • Chicago
    • Dallas/Fort Worth
    • Denver
    • Durham
    • Glendale
    • Houston
    • Live Online Only
    • Los Angeles
    • New Hampshire
    • New York
    • Orlando
    • Raleigh
    • San Diego
    • San Francisco
    • Santa Rosa
    • Washington D.C.
    • England
    • Germany
    Locations
  • Self-Paced Learning
    • Online Live Training
    • E-Learning
    • Online CCNA Video Training
    • Practice Questions
    • DVD and Audio (Lammle Press)
    • Books
  • Blog
  • Forum
  • GlobalNet Consulting
    • Overview
    • Experience
    • Our Team
    • Methodology
    • Projects
    • Contact Us
  • About
    • About Todd Lammle
    • About GlobalNet Training & Consulting
      • About GlobalNet Consulting
    • Student Complaint Policy
    • Terms of Service
      • Privacy Policy
      • Why was my account disabled?
  • Contact
    • Feedback Form
    • Site Map
Home Forum

Official Lammle User Forum


Go Back   Lammle Forum > Cisco® CCNA > Network Address Translation
Reload this Page NAT practice
Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 03-05-2009, 10:07 AM
Tigerprawn Tigerprawn is offline
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default NAT practice

Can someone pose a NAT problem for me? I need practice. Thanks!
Reply With Quote
Tigerprawn
View Public Profile
Send a private message to Tigerprawn
Find all posts by Tigerprawn
  #2  
Old 03-06-2009, 10:17 AM
Fuzz Fuzz is offline
Cisco Veteran
 
Join Date: Nov 2008
Location: Birmingham, UK
Posts: 1,236
Default

Get packet tracer if you don't already have it and try this, 2nd post.

http://www.lammle.com/discussion/showthread.php?t=1212
__________________
Comptia: Network+, Server+; Cisco: CCENT, CCNA, CCNP; Microsoft: 70-291
Currently studying: CCNA Security
Follow my CCNP progress with study notes on my blog: http://beyondccna.blogspot.co.uk/
Reply With Quote
Fuzz
View Public Profile
Send a private message to Fuzz
Find all posts by Fuzz
  #3  
Old 03-06-2009, 04:29 PM
Tigerprawn Tigerprawn is offline
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default

Thanks, Fuzz.

PacketTracer said the .pkt file wasn't a valid file. Maybe I have an old version of PacketTracer. I have 4.1.

So, I made myself a similar scenario that I can do with Dynamips. I couldn't figure out any way to test HTTP, so I said the server is a TFTP server (because I can cause a router or switch to be a TFTP server.) So, here's what I tried.

Topology:


Core Router--Fa0/0 Network 10.1.1.0/24 with 10.1.1.1 TFTP server
S1/0
|
|
S1/0
RouterA--Fa0/0 Network 10.2.2.0/24
S1/1
|
|
S1/1
RouterB--Fa0/0 Network 10.3.3.0/24


Challenge:

1) Deny all except 10.3.3.11/24 telnet/ssh into routers

2) Deny traffic from network 10.3.3.0/24 accessing network 10.2.2.0/24

3) Permit 10.3.3.11/24 full IP access to 10.1.1.1/24 TFTP server

4) Deny all except TFTP traffic access to TFTP server

5) Use NAT overload for all addresses on the Fast Ethernet LAN on Router A going out s1/0.


Anyone want to take a stab at it? You could dry lab it (write the config statements) if you don't have access to routers.

I dry labbed it first and then tried it on Dynamips and got everything right!

I'll post my solution later...

Thanks again Fuzz!
Reply With Quote
Tigerprawn
View Public Profile
Send a private message to Tigerprawn
Find all posts by Tigerprawn
  #4  
Old 03-07-2009, 08:28 PM
Tigerprawn Tigerprawn is offline
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default

Here are my answers!

1) Deny all except 10.3.3.11/24 telnet/ssh into routers
On all routers:
access-list 1 permit 10.3.3.11 0.0.0.0
line vty 0 4
login local
transport input telnet ssh
access-class 1 in

2) Deny traffic from network 10.3.3.0/24 accessing network 10.2.2.0/24
RouterA
access-list 101 deny ip 10.3.3.0 0.0.0.255 10.2.2.0 0.0.0.255
access-list 101 permit ip any any
int s1/1
ip access-group 101 in

3) Permit 10.3.3.11/24 full IP access to 10.1.1.1/24 tftp server
CoreRouter
access-list 101 permit ip 10.3.3.11 0.0.0.0 10.1.1.1 0.0.0.0
int fa0/0
ip access-group 101 out

4) Deny all except tftp traffic access to tftp server
CoreRouter
access-list 101 permit udp any 10.1.1.1 0.0.0.0 eq tftp

5) Use NAT overload for all addresses on the Fast Ethernet LAN on Router A going out s1/0.
int fa0/0
ip nat inside
int s1/0
ip nat outside
access-list 1 permit 10.2.2.0 0.0.0.255
ip nat inside source list 1 interface s1/0 overload


Thoughts, comments? Thanks.
Reply With Quote
Tigerprawn
View Public Profile
Send a private message to Tigerprawn
Find all posts by Tigerprawn
Reply

Bookmarks
  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Rules
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with NAT overload (PAT) eduardo Network Address Translation 0 08-11-2011 01:22 AM
Help me with NAT bjgodby Network Address Translation 3 11-28-2009 08:32 PM
NAT practice Xfilers Network Address Translation 2 05-03-2009 01:23 PM
Dynamic NAT config: Difficulty in viewing results of the command - 'sh ip nat trans' v4net Network Address Translation 0 04-21-2009 07:15 PM
Question on Lab Practice Scenario for Configuring NAT gauthierda General Questions (Any Chapter) 0 04-03-2009 01:15 PM


All times are GMT -5. The time now is 03:39 AM.

Contact Us - Lammle.com - Archive - Top

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.

CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. All other trademarks mentioned in this document or Web site are the property of their respective owners. The content of this website is the copyrighted property of Lammle.com.
© 2013 Lammle.comPrivacy Policy