Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Problem with cisco2691 FastEthernet interface

I bought Cisco2691( IOS12.2(8), IDS,FW,MEM256 ) days before, and after five hours I set it up, it refused to work.

The configuration image is as follow:

eth0 192.168.2.1/24

eth1 192.168.3.1/24

Access-list is permit any with two interface ( in ).

Two clients are:

client0 192.168.2.2

client1 192.168.3.2

The problem is :

I can ping from 192.168.3.2 to 192.168.2.1 , but not 192.168.2.2

I can not ping from 192.168.2.2 to 192.168.2.1 too

with show arp , i can found client0's mac address in router's arp table,

but I can not found eth0's mac address in client0's arp table.

With show interface fastethernet0/0, not any errors,

With test interface fastethernet0/0, not any errors too.

I changed the client0 and the cable connected to eth0, but not worked.

Anyone can tell me what' the problem?

2 REPLIES
New Member

Re: Problem with cisco2691 FastEthernet interface

The problem looks like it is at the 192.168.2.2 end. Is the interface up? Is line protocol up? I'm sure the interface is up because it responds to a ping, but look anyway. Remember that an Ethernet link is four wire. It can be up at one end and down at the other. Check the IP configuration of client 192.168.2.2. (I will guess that it is a Windows client). Do winipcfg (or whatever variation is needed for your operating system). Is the TCP/IP stack loaded properly on the client ('ping localhost' from a command prompt)? Can the client ping itself (ping 192.168.2.2)? It may be an access list issue. Remove the access list and try it. Does it work without the access list?

When you can answer 'yes' to all of these questions it should work. Let us know what you find.

New Member

Re: Problem with cisco2691 FastEthernet interface

There is no problem in 192.168.2.2

With debug arp , I found 2691 sent req packet to 192.168.2.2 , but actually,

with netmonitor, 192.168.2.2 did not receive the req . But 192.168.2.1 can receive the req packet from 192.168.2.2 , and then put the mac of 192.168.2.2 to the arp table. I doubt that 192.168.2.1 did not send out any packets at all .

I changed the 192.168.2.1 with other matchine and the cable too, but the same case happened. Could be some hardware problem with eth0?

as to access-list , I used configuration as follow,

version 12.2

service timestamps debug uptime

service timestamps log uptime

service password-encryption

!

hostname route

!

enable password xxxxxxxxxxxxxxxxxxxxxxxxx

!

memory-size iomem 15

ip subnet-zero

no ip source-route

!

!

no ip domain-lookup

!

ip inspect max-incomplete high 2500

ip inspect max-incomplete low 1500

ip inspect one-minute high 1500

ip inspect one-minute low 1000

ip inspect tcp max-incomplete host 150 block-time 0

ip inspect name Ethernet_1 ftp

ip inspect name Ethernet_1 tcp

ip inspect name Ethernet_1 udp

ip inspect name Ethernet_0 ftp

ip inspect name Ethernet_0 tcp

ip inspect name Ethernet_0 udp

ip audit notify log

ip audit po max-events 100

!

!

!

interface FastEthernet0/0

description connected to internet

ip address 192.168.2.1 255.255.255.0

ip access-group 101 in

ip inspect Ethernet_0 in

duplex auto

speed auto

ntp disable

no cdp enable

!

interface FastEthernet0/1

description connected to Lan

ip address 192.168.3.1 255.255.255.0

ip access-group 100 in

ip inspect Ethernet_1 in

duplex auto

speed auto

ntp disable

no cdp enable

!

router rip

version 2

passive-interface FastEthernet0/0

network 192.168.2.0

no auto-summary

!

ip classless

ip route 0.0.0.0 0.0.0.0 FastEthernet0/0

no ip http server

ip pim bidir-enable

!

!

logging 192.168.2.254

access-list 100 permit ip any any

access-list 100 permit icmp any any

access-list 101 permit icmp any any

access-list 101 permit ip any any

no cdp run

!

line con 0

exec-timeout 0 0

password xxxxxxxxxxxxxxxxxxx

login

line aux 0

line vty 0 4

password xxxxxxxxxxxxxxxxxxxxxxxxxxxxx

login

!

end

75
Views
0
Helpful
2
Replies