inhouse testing - computer acting as router


I am wanting to test our server setup inhouse before colocation deployment.

This is the configuration:

Cisco CSS 11150 (WebNS 6.1) (IP: Subnet: connects to two servers (IPs: & Subnet: and two DNS servers (IPs: & Subnet:

When deployed the Cisco CSS will connect to the ISPs router on the same subnet ie. Router IP: Subnet:

Before deployment, I would like to test this configuration and the Cisco CSS functionality. I have connected a spare computer directly to the CSS (in the place of the router) and put in the same network settings as the router (ie. Router IP: Subnet:

Currently the configuration does not work ie. from the spare computer that is acting as the ISPs router I can not ping any other the servers or the DNS machines.

Am I missing something? Is this possible?

Thanks in advance.

Who is Participating?
complexymetronConnect With a Mentor Commented:
When I understand you correctly you want this setup:

       Spare PC (as subsitute for your ISP)  
     Cisco CSS  .38
             I  211.77.91.??
             I       []
    I          I            I                I
 DNS1   DNS2    Server1     Server2
  .17      .18         .19            .20

You didn't mention the IP of the Cisco CSS on your internal network. I'd suggest .30

I'd first try to check each network segment by pinging each station from Cisco and vice versa. Same with your spare PC and the Cisco. Just to check basic installation and then move on to the router config.
hit4063Commented: - 20 are not valid with the Mask! With such a mask you can use the IPs - So give your servers IPs inside of that range.
Which device makes the routing between the Cisco and the servers? Does the Cisco have a second IP Address inside the server range?
Which default gateway did you configure?

That's not correct.
The .240 subnet mask allows Subnets with 16 IP adresses each (14 Hosts + 2 reserved IPs for net and broadcast). The following subnets are perfectly correct:    (1-14)  (17-30)  (31-46)  (49-62)  (65-78)
and so on
SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

hit4063 does not seem to understand subnet masks, and is quite incorrect

I agree with complexymetron's analysis and advice...  Please keep us informed.

complexymetron  and The--Captain are right. I made a big mistake in my post, sorry for the inconvenience i caused. (we had a similar case at work with someone using ip's 1 - 20 and the same subnet mask as you and somehow my brain made a shortcut. sorry again)

traceroute can also help you check your config. so after doing the ping-checks complexymetron mentioned, try traceroutes from your stations to the spare pc and vice versa.
rot299Author Commented:
Thanks complexymetron! (and The--Captain and hit4063)

I was intending to set the internal network IP on the Cisco CSS at (but I do not know if this is a usage IP) and how do I set the internal IP for the CSS?

I received this from my ISP:

Your new allocation is:

This means that your useable ip's are through to

The bridging IP's (ie between your CSS and our router) is:

This means that our router is and your CSS should sit on You should point all your traffic to

Hope this helps. Thanks in advance.
The--CaptainConnect With a Mentor Commented:
>I was intending to set the internal network IP on the Cisco CSS at (but I do not know if this is a usage IP)

.16 is not a usable IP - IMO, you should use 17 or .30 (as Complexymetron suggests), since your gateway IP is easier to remember if it's the first or last IP in your block.

>and how do I set the internal IP for the CSS?

Not sure - I'd have to go to and read the documentation

>Currently the configuration does not work ie. from the spare computer that is acting as the ISPs router I can not ping any other
>the servers or the DNS machines.

Your ISPs router (which are are currently impersonating with your PC) will certainly have a route to through - have you added such a route with the "route" command (or similar mechanisms)?  Or at least have you added a default route (in other words, defined your gateway) on the "router" PC through

This ( should give you an idea how to set the ip for the internal interface.

As The--Capatin mentioned, .16 isn't available for a /28-net. The explanation is: all host-bits are set to 0, which would address the network, not a host. The address with all bits set to 1 is also prohibited, because that would address all hosts in that network, so .31 isn't available either, making the useable addresses span from .17 to .30

If your internal interface of the CSS isn't set up properly, things won't work. So check that first. Saying again: pings have to be possible from the CSS to your servers and vice versa.
Can your spare PC reach (i.e. ping) the router?
rot299Author Commented:
Hi - Thanks again for your comments.

To make it easier, I have uploaded a powerpoint file of the network. You can download a copy at:

The diagram includes features that I didn't mention in the first post - sorry!

The DRAC cards are remote management cards with real IPs. The internal Cisco CSS IP is:

Does the diagram look correct to you? Ask any questions if you like. Do I have to setup the computer that I am setting up in the position of the "ISP Cisco Router" any differently (ie. apart from changing the network settings)?

Thanks in advance.
First: are you able to ping the attached devices directly to ensure proper network installation? E.g. ISP <-> CSS, CSS <-> your servers

The computer you want to be your ISPs router doesn't have to be configured special - just the network settings have to be right:
He has to know where to reach The command for windows would be:
"route -p add mask"
(The "-p" stands for permanent, meaning windows won't forget that route after reboot)

I don't have a very good feeling about using the same gigabit switch for the DRAC-cards. Unless you're using a VLAN for them I'd prefer an extra switch for those cards. Since they seem to be used from the outside (therfore the connection to the gigabit switch), even a 10MBit hub would be sufficient.

I don't know the CSS very well, you're able to attach 5 devices directly to it? Or is there a switch between them, too?
rot299Author Commented:

I have worked it out... thanks for your assistance. CSS works finially! Was a real bastard.
All Courses

From novice to tech pro — start learning today.