NAT: address not stolen for

I'm having some trouble with a small vlan and nat setup. Only one of my vlans are being nat'd out to the internet. With the other vlan, I can ping the WAN interface but nothing gets nat'd past it. some of the nat debug messages have the following:

02:33:25: NAT: failed to allocate address for 172.16.96.2, list/map 3

and

02:33:25: NAT: address not stolen for 172.16.96.2, proto 1 port 512

Do you have to a seperate WAN public IP address to overload on for each nat pool or can you overload multiple vlans on the same WAN IP?

Here are relevant parts of the config:

interface FastEthernet0/0.2 description PCG Administration and OPS encapsulation dot1Q 2 ip address 192.168.96.1 255.255.255.128 no ip directed-broadcast ip nat inside no ip route-cache no ip mroute-cache ! interface FastEthernet0/0.3 description PCG CONFERENCE ROOMS encapsulation dot1Q 3 ip address 172.16.96.1 255.255.255.128 no ip directed-broadcast ip nat inside no ip route-cache no ip mroute-cache ! ip nat pool PCC 68.223.124.183 68.223.124.183 prefix-length 25 ip nat inside source list 2 pool PCC overload ip nat inside source list 3 pool PCC overload ! access-list 2 permit 192.168.96.0 0.0.0.255 access-list 3 permit 172.16.96.0 0.0.0.255

Any help would greatly be appreciated.

Thanks,

Scott

Reply to
biscotti.macdonald
Loading thread data ...

snipped-for-privacy@gmail.com wrote: [snip: nat problems]

Why did you turn of route-cache out of curiosity?

Did you try using one list and using it in your pool?

access-list 2 permit 192.168.96.0 0.0.0.255 access-list 2 permit 172.16.96.0 0.0.0.255

Reply to
Hansang Bae

Hey there,

Yea I'm not sure about the route cache statement actually. I believe it was there from the last admin that had configured the router for something else and I just hadn't taken it out. I'll go ahead and remove that. But I think you may be right about combining the access-lists. I was thinking the same thing last night after staring at the config for an hour straight. I'll try that today and post the results. Thanks for the time.

Scott

Hansang Bae wrote:

Reply to
biscotti.macdonald

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.