Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 345
  • Last Modified:

Cisco 837 Broadband Config - What I am missing? Can't get internet access

Hi we use a the cisco 837 for VPN which works fine but we have been unable configure internet access, I am sure that it it something straight forward just a bit of a newbie on the routers, any help or pointer greatly appreciated, config below



version 12.3
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
!
hostname xxxxxx
!
no logging console
enable secret xxxxxx
!
username xxxxxx privilege 15 password xxxxxx
clock timezone PCTimeZone 0
no aaa new-model
ip subnet-zero
ip tcp synwait-time 10
ip domain name xxxxxx.com
!
!
no ip bootp server
ip cef
ip audit notify log
ip audit po max-events 100
vpdn enable
!
vpdn-group 1
request-dialin
protocol pppoe
!
no ftp-server write-enable
!
!
!
!
crypto isakmp policy 1
hash md5
authentication pre-share
group 2
crypto isakmp key 0 xxxxxxxxxx address xxxxxxxxxxxxxx
!
!
crypto ipsec transform-set fire esp-des esp-md5-hmac
!
crypto map SDM_CMAP_1 1 ipsec-isakmp

description Tunnel to xxx.xxx.xxx.xxx
set peer xxx.xxx.xxx.xxx
set transform-set fire
match address 101
!
!
!
!
interface Null0
no ip unreachables
!
interface Ethernet0
description $FW_INSIDE$$ETH-LAN$
ip address 192.51.1.50 255.255.255.0
ip nat inside
ip tcp adjust-mss 1452
no cdp enable
hold-queue 100 out
!

interface ATM0
no ip address
no atm ilmi-keepalive
pvc 8/35
encapsulation aal5snap
pppoe-client dial-pool-number 1
!
dsl operating-mode auto
!
interface FastEthernet1
no ip address
duplex auto
speed auto
!
interface FastEthernet2
no ip address
duplex auto
speed auto
!
interface FastEthernet3
no ip address
duplex auto
speed auto
!
interface FastEthernet4
no ip address
duplex auto
speed auto
!
interface Dialer1
description $FW_OUTSIDE$
ip address negotiated
ip access-group 105 in
ip mtu 1452
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap callin
ppp chap hostname xxxxxx
ppp chap password 7 xxxxxxxxxxxxxxxxxxxxxx
crypto map SDM_CMAP_1
!
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1 permanent
ip http server
ip http secure-server
!
access-list 101 remark SDM_ACL
access-list 101 remark IPSec Rule
access-list 101 permit ip 192.51.1.0 0.0.0.255 192.32.64.0 0.0.0.255
access-list 105 permit udp host xxx.xxx.xxx.xx host xxx.xxx.xxx.xx eq non500-isakmp
access-list 105 permit udp host xxx.xxx.xxx.xx host xxx.xxx.xxx.xx eq isakmp
access-list 105 permit esp host xxx.xxx.xxx.xx host xxx.xxx.xxx.xx
access-list 105 permit ahp host xxx.xxx.xxx.xx hostxxx.xxx.xxx.xx
access-list 105 permit udp host xxx.xxx.xxx.xx any eq non500-isakmp
access-list 105 permit udp host xxx.xxx.xxx.xx any eq isakmp
access-list 105 permit esp host xxx.xxx.xxx.xx any
access-list 105 permit ahp host xxx.xxx.xxx.xx any
access-list 105 permit ip 192.32.64.0 0.0.0.255 192.51.1.0 0.0.0.255
access-list 105 permit tcp any any established
access-list 105 remark IPSec Rule
access-list 105 remark SDM_ACL Catagory=17
access-list 105 remark SDM_ACL Catagory=4
dialer-list 1 protocol ip permit
no cdp run

banner login CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!
!
line con 0
password 7 130346005808577E393020
login
no modem enable
stopbits 1
line aux 0
password 7 0709705E1D0D4A51050603
login
stopbits 1
line vty 0 4
password 7 130346005808577E393020
login local
!
scheduler max-task-time 5000
scheduler interval 500
!
end

 
0
SGordon
Asked:
SGordon
1 Solution
 
magicommincCommented:
You need a NAT statment for your split-tunnel, add below lines:

ip nat inside source route-map internet-traffic interface Dialer1 overload
access-list 110 deny ip 192.51.1.0 0.0.0.255 192.32.64.0 0.0.0.255
access-list 110 permit ip 192.51.1.0 0.0.0.255 any
route-map internet-traffic permit 10
 match ip address 110
0
 
SGordonAuthor Commented:
Cheers mate worked like a treat
0

Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now