>>ip nat inside source list 1 pool ONE overload
>
>может имеет смысл указать интерфейс loopback0 Переделал всё согласно официальной док-ции Cisco:
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080094430.shtml
Не работает!
Поменял местами ip nat outside <-> inside:
version 12.4
!
--------------------
!
interface Loopback0
ip address 192.168.140.1 255.255.255.252
ip accounting output-packets
ip nat outside
ip virtual-reassembly
no ip route-cache cef
no ip route-cache
no ip mroute-cache
!
interface FastEthernet0/1
ip address 89.X.X.26 255.255.255.240 secondary
ip address 10.X.X.1 255.255.255.0
ip nat inside
ip virtual-reassembly
no ip route-cache cef
no ip route-cache
ip policy route-map NAT
no ip mroute-cache
duplex auto
speed auto
!
ip route 0.0.0.0 0.0.0.0 89.X.X.17
!
!
no ip http server
no ip http secure-server
ip nat pool ONE 89.X.X.26 89.X.X.26 netmask 255.255.255.240
ip nat inside source list 1 pool ONE overload
!
access-list 1 permit 10.X.X.0 0.0.0.255
access-list 101 permit ip 10.X.X.0 0.0.0.255 any
access-list 177 permit icmp any any
!
!
!
route-map NAT permit 10
match ip address 101
set interface Loopback0
!
Включил
debug ip packet 177 detail
debug ip Nat
debug ip policy
Не сходится вывод:
*Sep 27 10:53:07.371: IP: tableid=0, s=10.X.X.20 (FastEthernet0/1), d=195.128.
128.1 (FastEthernet0/1), routed via FIB
*Sep 27 10:53:07.371: IP: s=10.X.X.20 (FastEthernet0/1), d=195.128.128.1, len
60, policy match
*Sep 27 10:53:07.371: ICMP type=8, code=0
*Sep 27 10:53:07.375: IP: route map NAT, item 10, permit
*Sep 27 10:53:07.375: IP: s=10.X.X.20 (FastEthernet0/1), d=195.128.128.1 (Fast
Ethernet0/1), len 60, policy rejected -- normal forwarding
*Sep 27 10:53:07.375: ICMP type=8, code=0
*Sep 27 10:53:07.375: IP: s=10.X.X.20 (FastEthernet0/1), d=195.128.128.1 (Fast
Ethernet0/1), g=89.X.X.17, len 60, forward
*Sep 27 10:53:07.375: ICMP type=8, code=0
Все идёт мимо Loopback!