Hi all,
as a learning exercise I've been having a play with an old Cisco 1801 router, I have a little test setup at home and the plan is to put it behind a Cisco pix 501 and have a play with Vlans from a Cisco 2950 switch and some test domains.
So, before even attempting to do that I wanted to make sure that I could get something working. The current setup is like this:
netgear router -- 1801 router -- laptop on a static ip
192.168.1.1 -- 192.168.1.100 - 192.168.2.101 -- 192.168.2.102
Using this config below and natting, the laptop can ping the netgear router (192.168.1.1) and access the internet.
******************************************
Router#show run
Building configuration...
Current configuration : 1250 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
!
dot11 syslog
!
!
ip cef
!
!
ip name-server 192.168.1.1
!
multilink bundle-name authenticated
!
!
vtp mode transparent
!
!
archive
log config
hidekeys
!
!
vlan 2
!
!
!
!
interface FastEthernet0
ip address 192.168.1.100 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface BRI0
no ip address
encapsulation hdlc
shutdown
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
!
interface FastEthernet5
!
interface FastEthernet6
!
interface FastEthernet7
!
interface FastEthernet8
!
interface ATM0
no ip address
shutdown
no atm ilmi-keepalive
dsl operating-mode auto
!
interface Vlan1
ip address 192.168.2.101 255.255.255.0
ip nat inside
ip virtual-reassembly
!
no ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 192.168.1.1
!
!
no ip http server
no ip http secure-server
ip nat inside source list 101 interface FastEthernet0 overload
!
access-list 101 permit ip any any
!
!
!
!
!
!
control-plane
!
!
line con 0
line aux 0
line vty 0 4
login
!
end
********************************************
I don't want to be natting as the Pix will do this so I'm attempting to set it up like the tutorial in this link.
http://www.parkansky.com/tutorials/dmz.htm
For the life of me I can't get it working, I've all removed the natting bits on the inside/outside and the access lists above.
From the laptop 192.168.2.102 i can ping the vlan1 address 192.168.2.101 and fa0 192.168.1.100 but not the gateway of 192.168.1.1
I'm thinking that I need access-lists and i've tried lots
access-list 10 permit 192.168.2.0 0.0.0.255
access-list 10 permit any
And other various attempts on both interfaces in and out and I'm getting nothing, I have a feeling I'm missing something daft and it's doing my nut in nowdata:image/s3,"s3://crabby-images/fc608/fc608ab6e6dc2469165c10f9a8cb020731d10c69" alt="Smile :) :)"
Anyone got any ideas what's missing?
as a learning exercise I've been having a play with an old Cisco 1801 router, I have a little test setup at home and the plan is to put it behind a Cisco pix 501 and have a play with Vlans from a Cisco 2950 switch and some test domains.
So, before even attempting to do that I wanted to make sure that I could get something working. The current setup is like this:
netgear router -- 1801 router -- laptop on a static ip
192.168.1.1 -- 192.168.1.100 - 192.168.2.101 -- 192.168.2.102
Using this config below and natting, the laptop can ping the netgear router (192.168.1.1) and access the internet.
******************************************
Router#show run
Building configuration...
Current configuration : 1250 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
!
dot11 syslog
!
!
ip cef
!
!
ip name-server 192.168.1.1
!
multilink bundle-name authenticated
!
!
vtp mode transparent
!
!
archive
log config
hidekeys
!
!
vlan 2
!
!
!
!
interface FastEthernet0
ip address 192.168.1.100 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface BRI0
no ip address
encapsulation hdlc
shutdown
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
!
interface FastEthernet5
!
interface FastEthernet6
!
interface FastEthernet7
!
interface FastEthernet8
!
interface ATM0
no ip address
shutdown
no atm ilmi-keepalive
dsl operating-mode auto
!
interface Vlan1
ip address 192.168.2.101 255.255.255.0
ip nat inside
ip virtual-reassembly
!
no ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 192.168.1.1
!
!
no ip http server
no ip http secure-server
ip nat inside source list 101 interface FastEthernet0 overload
!
access-list 101 permit ip any any
!
!
!
!
!
!
control-plane
!
!
line con 0
line aux 0
line vty 0 4
login
!
end
********************************************
I don't want to be natting as the Pix will do this so I'm attempting to set it up like the tutorial in this link.
http://www.parkansky.com/tutorials/dmz.htm
For the life of me I can't get it working, I've all removed the natting bits on the inside/outside and the access lists above.
From the laptop 192.168.2.102 i can ping the vlan1 address 192.168.2.101 and fa0 192.168.1.100 but not the gateway of 192.168.1.1
I'm thinking that I need access-lists and i've tried lots
access-list 10 permit 192.168.2.0 0.0.0.255
access-list 10 permit any
And other various attempts on both interfaces in and out and I'm getting nothing, I have a feeling I'm missing something daft and it's doing my nut in now
data:image/s3,"s3://crabby-images/fc608/fc608ab6e6dc2469165c10f9a8cb020731d10c69" alt="Smile :) :)"
Anyone got any ideas what's missing?
Last edited: