Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

NAT with a Cisco Firewall

This thread has been viewed 2 times
  • 1.  NAT with a Cisco Firewall

    Posted Mar 14, 2016 05:09 PM

    I am New to Aruba appliances. I need help accessing a host computer behind a RAP from a public IP address using a cisco firewall NAT. I have a public IP address NATed on the Cisco Firewall to the Aruba Controller and that works. I then wanted to port forward the port 50080 to the host computer. I can access the specified host computer from anywhere on the internal network using 10.208.58.x but not externally.

     

    The public ip address of 173.165.x.x NAT’s to 10.208.48.x on the Cisco Firewall. This allows me to the aruba controller externally.(https://173.165.x.x:4343)

     

    On the Aruba Controller I set up the policy session IPv4 any host 10.208.48.x tcp 50080 dst-nat ip 10.208.58.x 80

     

    I applied the Policy to the port firewall policy session

     

    I get a timeout saying the server stopped responding.(https://173.165.x.x:50080 and http://173.165.x.x:50080)



  • 2.  RE: NAT with a Cisco Firewall

    EMPLOYEE
    Posted Mar 14, 2016 06:30 PM

    Unfortunately, you cannot do a static inbounds NAT to a device behind a RAP.

     



  • 3.  RE: NAT with a Cisco Firewall

    EMPLOYEE
    Posted Mar 15, 2016 03:54 AM

    Though the RAP will not allow inbound NAT, you can probably access that computer via the controller. Through the controller, you have full access to the clients behind the RAP (The RAP connection is layer 2 transparent), and it might be a solution in your case to create that inbound NAT entry in the data center where the controller lives, and then just route the traffic through the controller to the computer behind the RAP.

     

    If you have multiple RAPs, this even simplifies the solution as you can keep the NAT and firewalling central.

     

    Would that work?