Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Routing Question - What Am I Missing

Hello All:

Have a 3660 with 3 T1 multilink line. Presently, have one internal subnet using this router for internet.

Have FA0/1 with IP nat inside routing out 153.x.x.x

This is 2x segment gateway

This is working fine.

What I am trying to do is add another subnet 3x and firewall to use this router as well.

3660 - FA1/2 65.x.x.1 attached to WAN port on Firewall 65.x.x.2.

Firewall LAN - gateway for 3x

I can get out from inside to internet but I cannot run any services behind firewall such as DNS and have them accessible from internet, despite correct rules on firewall.

I can ping from the firewall (65.x.x.2) to FA1/1 (65.x.x.1) on the router but cannot ping from FA1/1 to firewall.

Any ideas as to why this is. If I sh arp on router, it sees the FW interface 65.x.x.2

ANy help would be appreciated.

New Member

Re: Routing Question - What Am I Missing

You should be able to ping the firewall ipaddress from the router. Can you share the specific rules of your firewall related to Inbound traffic from the router and rules related to DNS.

CreatePlease login to create content