It’s all working except that ARP isn’t working on the public side. If I temporarily add an IP address to the router for a translated address the router will respond to the arp request and it will work until the arp cache times out on the upstream device. Does anyone know how to get this working?
The upstream router at 10.2.0.254 will not obtain responses to arp requests for devices on the 10.1.0.0/16 network unless I alias the address onto the outside interface of the nat device e.g.