Comments are available to members only. Sign up or Log in to view these comments.
Main Topics
Browse All TopicsTo begin let me explain my setup. I have three entities with which I am working.
(substitude 192.168. for a routable address of course)
1. My ISP's Router
ip address 192.168.226.233 255.255.255.252 secondary
ip address 192.168.239.49 255.255.255.248
2. My new Router (Cisco 1605)
ip address 192.168.226.234 255.255.255.252 (E1)
ip address 192.168.239.51 255.255.255.248 (E2)
3. My Firewall:
192.168.239.50
255.255.255.248
GW 192.168.239.51
Normally my firewall has the default gateway of 192.168.239.49 which is the primary IP address of my ISP's router. When I place the my new router in between the two and assign my Firewall the Gateway of 192.168.239.51 I can not get anywhere from my network.
I can ping my firewall from the router.
I can ping my router from the firewall.
I can ping the secondary address of my ISP's router from the firewall without the new router in place.
I can not ping the secondary address of my ISP's router from my new router when I place it in between the firewall and the ISP router, and no traffic makes it past the new router from the inside network. My router config is as follows:
hostname router
!
ip subnet-zero
no ip source-route
no ip routing
no ip finger
no ip bootp server
no ip domain-lookup
!
!
interface Ethernet0
ip address 192.168.239.51 255.255.255.248
no ip redirects
no ip unreachables
no ip directed-broadcast
no ip proxy-arp
no ip route-cache
no cdp enable
!
interface Ethernet1
ip address 192.168.226.234 255.255.255.252
ip access-group e1-in in
no ip redirects
no ip unreachables
no ip directed-broadcast
no ip proxy-arp
no ip route-cache
no cdp enable
!
no ip classless
ip route 0.0.0.0 0.0.0.0 Ethernet1
ip route 192.168.239.50 255.255.255.255
The ACL e1-in goes something like this:
ip access-list extended e1-in
permit icmp any host 192.168.239.50 packet-too-big
permit icmp any host 192.168.239.50 echo-reply
permit tcp any host 192.168.239.50 eq www
permit tcp any host 192.168.239.50 eq 443
permit tcp any host 192.168.239.50 eq smtp
permit udp any host 192.168.239.50 eq isakmp
permit esp any host 192.168.239.50
permit ahp any host 192.168.239.50
permit tcp any any established
Can anyone tell me where my problem is?
Sorry for the length, but I think each detal is important to get the total picture
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: routermaniaPosted on 2003-01-14 at 14:11:09ID: 7727956
Comments are available to members only. Sign up or Log in to view these comments.