Below is a diagram that I have used to deploy this lab.
data:image/s3,"s3://crabby-images/7ff37/7ff3717493be0d359942d6e8e37baa20085ad9af" alt=""
Create a new VPC.
data:image/s3,"s3://crabby-images/5497c/5497c620706f8fd94e1baff81d592f61612f0795" alt=""
data:image/s3,"s3://crabby-images/6f65a/6f65a57a84c4d7d9311fa4b7760c0041e588d555" alt=""
data:image/s3,"s3://crabby-images/95429/95429fb28dec611a6ed713fdca158ddb47bbd717" alt=""
Create and attach a new Internet gateway to your VPC.
data:image/s3,"s3://crabby-images/04630/046303cec964253b16cdff8cfeb2f5264851bad1" alt=""
data:image/s3,"s3://crabby-images/23a05/23a05e7609c1a9f80406fd883ef5816c92a9921d" alt=""
Create a new route to 0.0.0.0/0 to your Internet gateway.
data:image/s3,"s3://crabby-images/16d2e/16d2e7fe312ae3d8105b6d2ed33551364e3de55e" alt=""
Launches a new CSR instance.
data:image/s3,"s3://crabby-images/b4c28/b4c28451e0cdd79cdfc98b8408fa46913297fbc4" alt=""
data:image/s3,"s3://crabby-images/bfa7a/bfa7a97c65c0820ae46d145209a9051db2624c27" alt=""
data:image/s3,"s3://crabby-images/234ca/234caccc1281e5bb3e4cc62101c643ee0039f07a" alt=""
data:image/s3,"s3://crabby-images/ced3f/ced3f330077a09d24b3879c5f7d14614386900b7" alt=""
Enter 10.0.0.10 on Primary IP setting.
data:image/s3,"s3://crabby-images/4cc6c/4cc6c36e807aa302ac279909d638c464340f9225" alt=""
Security Group.
data:image/s3,"s3://crabby-images/34944/34944f0567c9bc8949d1568727726d576a1af473" alt=""
data:image/s3,"s3://crabby-images/c257a/c257afe22eba41b001bf66bc96cba562d8d12475" alt=""
Go to Network interfaces, and create a new network interface for Router CSR.
data:image/s3,"s3://crabby-images/2cdc4/2cdc402a80ae2328f7c25e2b4f4d81ff0de7e98d" alt=""
Then attach this network to Router CSR.
data:image/s3,"s3://crabby-images/8a5ce/8a5ce7d304127cca7d300709bebcb6b5810c32a8" alt=""
Disable “Change/source/dest check” for both Cisco CSR interfaces.
data:image/s3,"s3://crabby-images/6f92c/6f92cea479367b07ff28036dfc41d32c49e1cf3e" alt=""
Back to route tables, configure the new route to the private Cisco CSR interface.
data:image/s3,"s3://crabby-images/53398/53398061532fa85186d2c7e5f4aaa1aa419b0fa2" alt=""
data:image/s3,"s3://crabby-images/6adfa/6adfa5e75b743d8da4640467537c79f485a11e56" alt=""
SSH from putty to Cisco Router.
conf t
int g2
ip add 10.0.1.10 255.255.255.0
no shut
exit
ping 8.8.8.8
data:image/s3,"s3://crabby-images/ddca3/ddca34c354fac34cf3edbce31dd4b3ae1b02a238" alt=""
data:image/s3,"s3://crabby-images/22afe/22afe4f8e5c659194bc27e86e737af9157837c79" alt=""
data:image/s3,"s3://crabby-images/a0a9b/a0a9b4fa0780266fd19573d0e92afedb12edef6a" alt=""
Launches a new Windows 2016 machine to test RDP traffic from the Internet.
data:image/s3,"s3://crabby-images/ee90c/ee90c69fd820462cf59f104e9f5224f05aa60aaa" alt=""
data:image/s3,"s3://crabby-images/35a29/35a291d29a4d5f97f84641beeff9c0c18d751b29" alt=""
Enable SNAT and DNAT on the Router.
conf t
access-list 1 permit any
# Allow inside to outside
ip nat inside source list 1 interface g1 overload
# Allow outside to Windows server via the RDP service
ip nat inside source static tcp 10.0.1.174 3389 10.0.0.10 3389
int g1
ip nat outside
int g2
ip nat inside
data:image/s3,"s3://crabby-images/065fe/065fe50ae08b0696a858281cb78a612f5bb63f5d" alt=""
Edit Router CSR Security Group and add RDP service into this group to allow RDP traffic from the Internet.
data:image/s3,"s3://crabby-images/b0a5b/b0a5bdaefb51928418a081473cc72a4d38107143" alt=""
data:image/s3,"s3://crabby-images/9e470/9e47061a49278077840df9a4662781ee4ef86117" alt=""
RDP to Elastic IP address of CSR Router.
data:image/s3,"s3://crabby-images/883b5/883b5c3546a8e3a8785a9a4c112d375b5b6f5c60" alt=""
data:image/s3,"s3://crabby-images/70eda/70eda85ef8ee9d9ec095e884189db689a32036d3" alt=""
data:image/s3,"s3://crabby-images/a84b3/a84b3e465fbc10512fb96187471e726e65e12f89" alt=""
data:image/s3,"s3://crabby-images/fbc72/fbc72419d8df98ebe05dbe26ed21c02644a94df7" alt=""