11-18-2008 05:44 AM - edited 03-04-2019 12:23 AM
Cisco 871 - on static DSL
Router can ping gateway and Internet. LAN hosts can ping router LAN interface (gateway for LAN) and router WAN interface, but not DSL gateway or Internet. Router config attached
11-18-2008 06:08 AM
Hello ILITCH,
in order to have NAT working I would add:
int vlan1
ip nat inside
int fas4
ip nat outside
to verify nat operation use:
sh ip nat translations
Hope to help
Giuseppe
11-18-2008 07:39 AM
OK - did that. Still not working
interface FastEthernet4
description $ETH-WAN$
ip address x.x.x.x 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly
ip route-cache flow
duplex auto
speed auto
!
interface Vlan1
description $FW_INSIDE$
ip address 192.168.17.1 255.255.255.0
ip access-group 103 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
zone-member security in-zone
ip route-cache flow
ip tcp adjust-mss 1412
11-18-2008 09:30 AM
Hello,
you aren't usind Dialer0 anymore
remove the following
no ip nat inside source route-map Nonat interface Dialer0 overload
then to make ip inspect to work correctly you need
int fas4
zone-member security out-zone
this because the following is applied by you of by SDM in behalf of you:
zone-pair security sdm-zp-self-out source self destination out-zone
service-policy type inspect sdm-permit-icmpreply
zone-pair security sdm-zp-out-self source out-zone destination self
service-policy type inspect sdm-permit
zone-pair security sdm-zp-in-out source in-zone destination out-zone
service-policy type inspect sdm-inspect
zone-pair security OUT-to-IN source out-zone destination in-zone
service-policy type inspect VPN_TRAFFIC
!
Hope to help
Giuseppe
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: