In this post, we will be configuring Windows Server 2019 as a NAT router to route traffic between local lan and the internet.
Prerequisties
- Create a Windows 2019 VM
- Configure 2 network card – 1 facing internet, 1 facing internal
- Its optional to add it to domain
Step 1: My VM is created with 2 NIC’s as shown
data:image/s3,"s3://crabby-images/5b856/5b856e966ea607b55b9ae17e42be56ec9a699fa4" alt=""
Step 2: Under the Role and Features, choose Remote Access
data:image/s3,"s3://crabby-images/b5705/b5705156666823094d7db18e657d80f0774a64c2" alt=""
Step 3: Choose just the Routing checkbox to install the LAN Routing role service.
data:image/s3,"s3://crabby-images/f2cb7/f2cb719ba4fee4a19dc68f7795538f8137d1a6d4" alt=""
Step 4: Click next on Web Server role services page and click to continue
data:image/s3,"s3://crabby-images/a0019/a0019f9be1a8eeba36ddfc89c6a52959178ea110" alt=""
Step 5: Click Next to continue
data:image/s3,"s3://crabby-images/b5b62/b5b62de2088d3d12f093094297de561f634e2bce" alt=""
Step 6: Click Install and wait for install to complete
data:image/s3,"s3://crabby-images/cf630/cf6304d9d117292c14e40bcd09118159da8b1c2c" alt=""
Configure NAT on Windows Server 2019
Step 7: Open Remote and Routing Access
data:image/s3,"s3://crabby-images/26c0d/26c0d30ee7ea5182d6fa4a68f434f927de070c71" alt=""
Step 8: Right-click and then select option to configure and enable routing and remote access.
data:image/s3,"s3://crabby-images/b11e4/b11e48f86757701fb8695d9ada6dcc67f7c8f012" alt=""
Step 9: Click Next
data:image/s3,"s3://crabby-images/4e3c4/4e3c4cc913854add1ccb5d0aee33eca10e91123f" alt=""
Step 10: Click Next
data:image/s3,"s3://crabby-images/32c1d/32c1d03039b8e72074185232f6582abe76eab309" alt=""
Step 11: Choose the interface connected to the internet
data:image/s3,"s3://crabby-images/9a7bd/9a7bdc10f7225bb8b8ea4612db2ab3b865f83711" alt=""
Step 12: Click Next to continue
data:image/s3,"s3://crabby-images/13a8e/13a8e55e746847ec5c3af330bca76c8188efa5a1" alt=""
Step 13: Click Next to continue
data:image/s3,"s3://crabby-images/1bace/1bace552ed89fc8582f9b35fb0b655726cef9b89" alt=""
Step 14: Click Finish to exit the configuration wizard.
data:image/s3,"s3://crabby-images/fc53a/fc53aec7564e6632988f9f0821ac20cad878768d" alt=""
Step 15: Click Finish to exit the configuration wizard.
data:image/s3,"s3://crabby-images/45d13/45d13c745ec5bfde71161b797b1be9acb371d4fa" alt=""
Verify NAT Configuration Settings
Step 16: Click on the interface connected to Internet . Ensure Internet is enabled.
data:image/s3,"s3://crabby-images/1c013/1c013580f2f8d2709705651f9b3b0a25572e54aa" alt=""
Step 17: Click on the interface named internal and ensure its set as private interface.
data:image/s3,"s3://crabby-images/93a14/93a141f3b10c8c3e24c762742369faf9f8011167" alt=""
Step 18: On the server properties, we will now set a IP range for our NAT clients
data:image/s3,"s3://crabby-images/c3fab/c3fabe13e10362b345d6a7465f165bd500e65d26" alt=""
Step 19: Choose an IP range.
data:image/s3,"s3://crabby-images/a5f6f/a5f6f4c70c47f2d479f7950465fce87089ce6105" alt=""
Step 20: Configure our client Windows desktop on the IP’s in this range and ensure default gateway is set to the NAT’s VM IP named as Internal
data:image/s3,"s3://crabby-images/1baec/1baec13e2e116faf49570b33c3f8729df51866b1" alt=""
Step 20: Ping www.msn.com and now you should be getting responses from www.msn.com successfully so our NAT is now working properly.
data:image/s3,"s3://crabby-images/0fe1e/0fe1e3fcd838392d8ad7cc7e23e070b0593efb92" alt=""
Step 21: Back on our Windows 2019, we can see packets been translated as our client machine access the internet.
data:image/s3,"s3://crabby-images/b6432/b6432d0b197abf6aed9beb0cb296c058fa5bc2ea" alt=""