Wireless Access

Reply
Frequent Contributor II
Posts: 127
Registered: ‎12-19-2012

NAT and dual external links

Hi all,   can someone help with this ?

 

3400 controller.  Vlan 100 assigned with a public address assigned to a port going off to a wan connection with a corresponding public address.  Straight out to internet.

 

Another vlan configured for guest DHCP adresses, lets say vlan 200, 192.168.5.0/24. Guests authenticate via captive portal. I need to forward guests to the internet, using nat, what is the easiest way to achieve this ? Do i need a nat pool ? or can i just use a single rule src-natting any 192.168.5.x addresses to the public IP ?

 

Also is it possible to connect an adsl internet line to another port and have an additional SSID use this connection ? For instance GUEST2 ssid ? Cant see how I will configure default gateways for this scenario.

 

Any help appreciated.

 

Thanks

ACMA/ACMP
Aruba
Posts: 1,644
Registered: ‎04-13-2009

Re: NAT and dual external links

[ Edited ]

You can configure NAT on a per rule basis (with NAT pools), or you can NAT an entire vlan with the "ip nat inside" command for the VLAN interface.

 

You are correct in your assumption about the 2nd Internet.   The default gateway could be an issue.  If your ADSL router can act as the gateway (and NAT) for those clients, then it could work.

------------------------------------------------
Systems Engineer, Northeast USA
ACCX | ACDX | ACMX

Frequent Contributor II
Posts: 127
Registered: ‎12-19-2012

Re: NAT and dual external links

Clembo, cheers for that. As it is at the moment the controller is connected to the ADSL router and that is doing the natting. As for the IP nat inside, say I do this on vlan 100, 192.168.5.x but want to nat to the new public ip on vlan 200, for instance 217.16.188.11 will this work ?

ACMA/ACMP
Aruba
Posts: 1,644
Registered: ‎04-13-2009

Re: NAT and dual external links

if you enable source NAT at the VLAN, it will NAT to the controller's IP.  If that happens to be VLAN 200, than yes.

------------------------------------------------
Systems Engineer, Northeast USA
ACCX | ACDX | ACMX

Frequent Contributor II
Posts: 127
Registered: ‎12-19-2012

Re: NAT and dual external links

By 'controllers IP' doyoumean the loopback ??

ACMA/ACMP
Aruba
Posts: 1,644
Registered: ‎04-13-2009

Re: NAT and dual external links

The controller-IP can be any IP (including loopback).  You can check/change this on the Configuraton --> Controller --> System Settings tab under Controller IP Details; or from CLI:

 

show controller-ip

 

to set:

 

controller-ip vlan XX

------------------------------------------------
Systems Engineer, Northeast USA
ACCX | ACDX | ACMX

Frequent Contributor II
Posts: 127
Registered: ‎12-19-2012

Re: NAT and dual external links

Clembo, your a gent, thanks.

 

 

ACMA/ACMP
Search Airheads
Showing results for 
Search instead for 
Did you mean: