Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

871 New Vlan with no firewall

Hello, I have a 871 router and I am looking to create a second VLan that will not have firewall protection and be separate from the main VLan.  The purpose of this is to have laptops connect to this vlan and let tem VPN into other sites.  If anyone can give me insight or send me to page that has the configuration that would be great.

Thank you all in advance.

Everyone's tags (3)

Re: 871 New Vlan with no firewall


This thread may help for a sample VPN configuration.;jsessionid=31A7B6E1A5F31FB97749915C9F808EBD.node0

A few examples of configuring VPN can also be found here. It depends on the client you are using and if GRE is configured as to the option you choose.

It may not be a good idea to leave certain parts of your network unprotected by a firewall. These holes can be easily exploited by hackers.

New Member

Re: 871 New Vlan with no firewall

I am not too sure if that will work.  Here is what is happening.  I am behind a C871

and I am trying to connect to another network with the Cisco VPN client to a PIX 515e, I can connect ok pit I am unable to ping any hosts on the other side.  When I turn off the fire wall then connect to the other network I can ping and see all the hosts.

Hope this help give you an insight as to why I am looking to do another VLan.

Re: 871 New Vlan with no firewall

It seems the ios fw / CBAC is blocking some traffic.

You need to configure inspect the particular protocol (icmp, TCP, etc)

and also allow the traffic in the interface ACL for the Cisco client vpn to work.

If you can post the sanitized config of the 871 then it would give a better idea.

New Member

Re: 871 New Vlan with no firewall

Here is the config.

Thanks in advance.

Re: 871 New Vlan with no firewall

interface f?

switchport mode access

switchport access vlan ?

CreatePlease login to create content