Wireless Access

last person joined: 11 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

NAT and dual external links

This thread has been viewed 4 times
  • 1.  NAT and dual external links

    Posted May 30, 2014 08:25 AM

    Hi all,   can someone help with this ?

     

    3400 controller.  Vlan 100 assigned with a public address assigned to a port going off to a wan connection with a corresponding public address.  Straight out to internet.

     

    Another vlan configured for guest DHCP adresses, lets say vlan 200, 192.168.5.0/24. Guests authenticate via captive portal. I need to forward guests to the internet, using nat, what is the easiest way to achieve this ? Do i need a nat pool ? or can i just use a single rule src-natting any 192.168.5.x addresses to the public IP ?

     

    Also is it possible to connect an adsl internet line to another port and have an additional SSID use this connection ? For instance GUEST2 ssid ? Cant see how I will configure default gateways for this scenario.

     

    Any help appreciated.

     

    Thanks


    #3400


  • 2.  RE: NAT and dual external links

    Posted May 30, 2014 08:51 AM

    You can configure NAT on a per rule basis (with NAT pools), or you can NAT an entire vlan with the "ip nat inside" command for the VLAN interface.

     

    You are correct in your assumption about the 2nd Internet.   The default gateway could be an issue.  If your ADSL router can act as the gateway (and NAT) for those clients, then it could work.



  • 3.  RE: NAT and dual external links

    Posted May 30, 2014 09:02 AM

    Clembo, cheers for that. As it is at the moment the controller is connected to the ADSL router and that is doing the natting. As for the IP nat inside, say I do this on vlan 100, 192.168.5.x but want to nat to the new public ip on vlan 200, for instance 217.16.188.11 will this work ?



  • 4.  RE: NAT and dual external links

    Posted May 31, 2014 07:13 AM

    if you enable source NAT at the VLAN, it will NAT to the controller's IP.  If that happens to be VLAN 200, than yes.



  • 5.  RE: NAT and dual external links

    Posted May 31, 2014 07:18 AM

    By 'controllers IP' doyoumean the loopback ??



  • 6.  RE: NAT and dual external links
    Best Answer

    Posted May 31, 2014 07:21 AM

    The controller-IP can be any IP (including loopback).  You can check/change this on the Configuraton --> Controller --> System Settings tab under Controller IP Details; or from CLI:

     

    show controller-ip

     

    to set:

     

    controller-ip vlan XX



  • 7.  RE: NAT and dual external links
    Best Answer

    Posted May 31, 2014 07:31 AM

    Clembo, your a gent, thanks.