Static NAT in CGNAT

Configuration

Sample configuration for port map in CG NAT


GPON-IN-All

Networks:

100.x.x.x

Sample configuration:

service cgn cgn1
service-type nat44 nat44
inside-vrf GPON-IN-All
protocol tcp
static-forward inside

address 100.127.2.140 port 80

sh cgn nat44 nat44 inside-translation protocol tcp inside-vrf GPON-IN-All inside-address 100.127.2.140 port start 80 end 8000

or:

sh cgn nat44 nat44 inside-translation translation-type static inside-vrf GPON-IN-All inside-address 100.127.2.140

INVENTUM-IN-ALL

Networks:

172.x.x.x – Static IPs

Sample configuration:

service cgn cgn1
service-type nat44 nat44
inside-vrf INVENTUM-IN-ALL
protocol tcp
static-forward inside

address 172.16.27.2 port 80

sh cgn nat44 nat44 inside-translation protocol tcp inside-vrf INVENTUM-IN-ALL inside-address 172.16.2.4 port start 80 end 8000

or:

sh cgn nat44 nat44 inside-translation translation-type static inside-vrf INVENTUM-IN-ALL inside-address 172.17.143.6

EKMGPON-Limited

Networks:

100.125.128.0/17
100.127.216.0/22
100.127.220.0/22

Sample Configuration:

service cgn cgn1
service-type nat44 nat44
inside-vrf EKMGPON-Limited
protocol tcp
static-forward inside

address 100.127.220.21 port 80

sh cgn nat44 nat44 inside-translation protocol tcp inside-vrf EKMGPON-Limited inside-address 100.127.220.21 port start 80 end 8000

or:

sh cgn nat44 nat44 inside-translation translation-type static inside-vrf EKMGPON-Limited inside-address 100.127.220.21

COKGPON-Dynamic

Networks:

Inside ip pool: 100.120.0.0/16
(100.120.0.1 to 100.120.128.255)

Scope: EKM-GPON-NEWALL

Outside ip: 111.92.80.0/23

Sample Configuration:

service cgn cgn2
service-type nat44 natv4
inside-vrf COKGPON-Dynamic
protocol tcp
static-forward inside

address 100.120.2.235 port 80
address 100.120.2.235 port 25001

sh cgn nat44 nat44 inside-translation protocol tcp inside-vrf COKGPON-Dynamic inside-address 100.127.220.21 port start 80 end 8000

or:

sh cgn nat44 nat44 inside-translation translation-type static inside-vrf COKGPON-Dynamic inside-address 100.127.220.21

CLTGPON-Limited

Networks:

100.126.128.0/18

Sample Configuration:

service cgn cgn1
service-type nat44 nat44
inside-vrf CLTGPON-Limited
protocol tcp
static-forward inside

address 100.127.209.246 port 90

sh cgn nat44 nat44 inside-translation protocol tcp inside-vrf CLTGPON-Limited inside-address 100.127.209.246 port start 80 end 8000

or:

sh cgn nat44 nat44 inside-translation translation-type static inside-vrf CLTGPON-Limited inside-address 100.127.209.246

GPON-KLA-IN

Networks:

100.126.192.0/18

Sample Configuration:

service cgn cgn2
service-type nat44 natv4
inside-vrf GPON-KLA-IN
protocol tcp
static-forward inside

address 100.126.196.134 port 90

sh cgn nat44 natv4 inside-translation protocol tcp inside-vrf GPON-KLA-IN inside-address 100.126.196.134 port start 80 end 8000

or:

sh cgn nat44 natv4 inside-translation translation-type static inside-vrf GPON-KLA-IN inside-address 100.126.196.134

KZHDGPON-Limited

Networks:

100.xxx.x.x/x ?

202.164.136.0/23

Sample Configuration:

service cgn cgn2
service-type nat44 natv4
inside-vrf KZHDGPON-Limited
protocol tcp
static-forward inside

address 100.126.140.150 port 37777

sh cgn nat44 natv4 inside-translation protocol tcp inside-vrf KZHDGPON-Limited inside-address 100.126.140.150 port start 80 end 8000

or:

sh cgn nat44 natv4 inside-translation translation-type static inside-vrf KZHDGPON-Limited inside-address 100.126.140.150

Save


Find inside private IP of a NATed public IP.

sh cgn nat44 nat44 outside-translation translation-type static outside-vrf INVENTUM-OUT-ALL outside-address 202.83.57.55

sh cgn nat44 natv4 outside-translation translation-type static outside-vrf OUTCOKGPON-Dynamic outside-address 111.92.81.220

Find outside public IP of a NATed private IP.

sh cgn nat44 nat44 inside-translation protocol tcp inside-vrf GPON-IN-All inside-address 100.127.108.248

sh cgn nat44 natv4 inside-translation protocol tcp inside-vrf COKGPON-Dynamic inside-address 100.120.2.235