>sh run interfeysov, acl i kasaemo nata pokazhi...
На С0 (где все работает)
interface Loopback0
ip address 192.168.10.1 255.255.255.0
ip route-cache policy
ip route-cache flow
!
interface FastEthernet0/0
ip address 10.x.x.130 255.255.255.0
ip nat inside
ip route-cache policy
ip route-cache flow
duplex auto
speed auto
!
interface Serial0/0
ip address 195.x.x.226 255.255.255.248
ip nat outside
ip route-cache policy
ip route-cache flow
ip policy route-map MAP
!
ip nat pool NFHRnet 195.x.x.235 195.x.x.239 netmask 255.255.255.248
ip nat inside source list 1 pool NFHRnet overload
!
access-list 1 permit 10.x.x.0 0.0.0.255
access-list 108 permit ip any 10.x.x.0 0.255.255.255
route-map MAP permit 10
match ip address 108
set interface Loopback0 FastEthernet0/0
На С1:
interface Loopback0
ip address 192.168.56.1 255.255.255.0
no ip directed-broadcast
ip route-cache policy
ip route-cache flow
!
interface Ethernet0/0
ip address 195.x.x.66 255.255.255.252
no ip directed-broadcast
ip nat outside
ip route-cache policy
ip route-cache flow
ip policy route-map MAP
!
interface Ethernet0/1
ip address 192.168.x.100 255.255.255.0 secondary
ip address 195.x.x.33 255.255.255.224
ip access-group zdravnicafw in
no ip directed-broadcast
no ip proxy-arp
ip nat inside
ip route-cache policy
ip route-cache flow
no arp arpa
!
ip nat pool zdrv-pool 195.x.x.129 195.x.x.134 netmask 255.255.255.248
ip nat inside source list 1 pool zdrv-pool
ip flow-export destination 195.x.x.55 9800
ip flow-export source Ethernet0/0
ip flow-export version 5
!
access-list 1 deny 192.168.x.23
access-list 1 deny 192.168.x.21 - это АТА-186, они не транслируются
access-list 1 permit 192.168.x.0 0.0.0.255
access-list 108 permit ip any 192.168.x.0 0.0.0.255
route-map MAP permit 10
match ip address 108
set interface Loopback0 Ethernet0/1
Если это имеет значение, то на C1 отключен arp и ведется статическая arp таблица