Article Directory :: Computers & Technology Articles

PPTP and HTTP Port Forwarding with Static NAT on a Cisco Router

Copyright © 2012 Don R. Crawley

Subscribe to Don R. Crawley's RSS feed using any feed reader!

Republish: EasyPublish
Published: 18Feb2008
Word count: 456
Viewed: 1249 time(s)
Bookmark this article using any bookmark manager!
Get Free Content For Your Site

Recently, a student at one of our seminars asked about port forwarding on a router. She wanted to allow PPTP clients to connect from the outside to a VPN server on the inside. In this article, I'll explain how to do it along with a quick look at using static NAT to forward packets to a web server.

Port Forwarding on a Cisco Router

Sometimes we have internal resources that need to be Internet-accessible such as Web servers, mail servers, or VPN servers. Generally, I recommend isolating those resources in a DMZ to protect your office LAN from the bad guys, but regardless of how you choose to design it, the process involves forwarding desired packets from the router's outside interface to an internal host. It's really a fairly simple process. Here's the configuration on a Cisco 2611 router:

interface Ethernet0/1
ip address 12.1.2.3 255.255.255.0
ip nat outside
!
interface Ethernet0/0
ip address 192.168.101.1 255.255.255.0
ip nat inside
!
ip nat inside source list 101 interface Ethernet0/1 overload
ip nat inside source static tcp 192.168.101.2 1723 interface Ethernet0/1 1723
!
access-list 101 permit ip any any

In the above configuration, Ethernet 0/1 is connected to the public Internet with a static address of 12.1.2.3 and Ethernet 0/0 is connected to the inside network with a static address of 192.168.101.1. NAT outside is configured on E0/1 and NAT inside is configured on E0/0. Access-list 101 works in conjunction with the "ip nat inside source list 101 interface Ethernet0/1 overload" statement to permit all inside hosts to use E0/1 to connect to the Internet sharing whatever IP address is assigned to interface Ethernet E0/1.

The "overload" statement implements PAT (Port Address Translation) which makes that possible. (PAT allows multiple internal hosts to share single address on an external interface by appending different port numbers to each connection.)

The statement "ip nat inside source static tcp 192.168.101.2 1723 interface Ethernet0/1 1723" takes incoming port 1723 (PPTP) requests on Ethernet0/1 and forwards them to the VPN server located at 192.168.101.2.

You could do something similar with a Web server by changing port 1723 to port 80 or port 443. Here's what that would look like:

interface Ethernet0/1
ip address 12.1.2.3 255.255.255.0
ip nat outside
!
interface Ethernet0/0
ip address 192.168.101.1 255.255.255.0
ip nat inside
!
ip nat inside source list 101 interface Ethernet0/1 overload
ip nat inside source static tcp 192.168.101.2 80 interface Ethernet0/1 80
!
access-list 101 permit ip any any

In this example, the web server is located at 192.168.101.2 and instead of forwarding PPTP (port 1723) traffic, we're forwarding HTTP (port 80) traffic.

Obviously, you can configure your Cisco router in a similar manner to forward nearly any type of traffic from an outside interface to an internal host.

Don R. Crawley, CCNA-certified, is president and chief technologist at soundtraining.net, the Seattle training firm specializing in business skills and technical training programs for IT professionals. He works with IT pros to enhance their work, lives, and careers. Click here for a free subscription to soundbytes, the 60-second e-zine for IT pros with musings, rants, and how-to guides on things I.T.

Bookmark this article using any bookmark manager! Subscribe to Don R. Crawley's RSS feed using any feed reader!

EasyPublish™ this article - publishers click here

More articles by Don R. Crawley

Free Report!
Ten Essential Secrets Of Article Marketing ... Grab Your Free
Copy
Now:




We respect your privacy.


Need Content?
Regular Top Quality Content for your Blog, Ezine or Website ...
Delivered Direct,
For Free!

Click For Details



Arts & Entertainment
Automotive
Business - General
Computers & Technology
Finance & Investment
Food & Drink
Health & Fitness
Home & Family
Internet Marketing/Online Business
Legal
Pets & Animals
Politics & Government
Reference & Education
Religion & Faith
Self-Improvement/Motivation
Social
Sports & Recreation
Travel & Leisure
Writing & Speaking

More computing articles:

  • The True Measure of Deliverability (John Bollinger)
    An article discussing the concept of "deliverability" or "email deliverability" for email marketers today and the variety of factors that go into determining its effectiveness.

  • Learning More About the Best Place To Register A Domain Name (Hanson Raider)
    Many people have one basic question in mind; where do I register a domain name and how I do it. A lot of people think about which is the best place where they can get their domain registered; they have a lot of questions in mind such as whether they should register their domain with a company or a domain registrar that offers cheap services is a better choice for registering a domain name.

  • Top Cloud Hosting Is The New Choice For Every Business (Hanson Raider)
    Although cloud hosting is a recent phenomenon but all the companies are looking out for best cloud hosting service providers for the amount of benefits it has in store for everybody. The major reason for so many clients being attracted towards cloud hosting of top quality is its cheap cost.

  • Useful Things To Know About Bluehost Hosting (Hanson Raider)
    Before selecting any web hosting provider, there are a number of things you should keep in mind. Firstly, it would be good if you know about the company. Bluehost web hosting is one of the most well celebrated company in the field of web hosting. It is also one of the oldest web hosting companies. In recent times, Bluehost's packages have gone through major changes.

  • Why Shared Hosting Is Perfect For Beginners (Hanson Raider)
    Beginners will find the right hosting when they start looking at different shared hosting reviews of top companies. This allows the beginner to take advantage of lower prices while getting the necesssary hosting for their needs. You can take advantage of discounts from JustHost or another hosting company offering shared hosting if you look in the right places.

  • Where Did I Leave My Web Host (Hanson Raider)
    In this fast paced web surfing world we are left with little to be desired because of all of the many different web sites available to us for research, business, entertainment and even pleasure in some cases. These many varied web sites have become staples in our daily lives and without them most of us would be completely lost.

  • Why Choose Top Green Web Hosting Companies And Not Regular Hosts? (Hanson Raider)
    The concept of green hosting has evolved overtime and an increasing number of people are now opting green web hosts to provide services to their websites. Since there has been an increasing preference of users for green web hosts, there are many top green hosting providers that have emerged overtime.

We Automatically Distribute Articles
To Thousands Of Publishers And Web Sites:

Submit Article
All content is viewed and used by you at your own risk and we do not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributing authors and not necessarily those of this web site, or its owner, Takanomi Limited.
 
Copyright © 2012 Takanomi Ltd. Company no. 5629683. All rights reserved. | Privacy | Legal | Contact Information