?
Solved

Not connection through Cisco 857 Router

Posted on 2006-11-16
11
Medium Priority
?
468 Views
Last Modified: 2010-04-17
We have a Cisco 857 configured to log onto our ISP and provied straight through access to our network.  An ISA Server is the only internal connection to the router.

The problem we have, is that we get no external access at all.  The router is connecting to our ISP as after monitoring the connection through the console, we are connecting to their gateway and we are recieving our IP Address from our ISP.  The router is saying that a route has been established to the ISP's gateway.

But, when we check our SDM it is saying that our WAN Connection is down whilst when we check through a terminal session to the router it is saying it is up.

This is starting to drive me mad as, not being a cisco person, cannot figure our why it's not working, even after looking through all the troubleshooting tips from Cisco.

Our Running Config is:


Building configuration...

Current configuration : 2687 bytes
!
version 12.3
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
service sequence-numbers
!
hostname Router
!
boot-start-marker
boot-end-marker
!
logging buffered 4096 debugging
enable secret 5 $XXXXXXXXXXXXXXXXXXXXXXX.
!
username ************ privilege 15 secret 5 XXXXXXXXXXXXXXXXX.
clock timezone PCTime 0
clock summer-time PCTime date Mar 30 2003 1:00 Oct 26 2003 2:00
no aaa new-model
ip subnet-zero
no ip source-route
!
!
ip cef
ip tcp synwait-time 10
no ip bootp server
no ip domain lookup
ip domain name yourdomain.com
ip ssh time-out 60
ip ssh authentication-retries 2
no ftp-server write-enable
!
!
!
!
!
!
!
interface ATM0
 no ip address
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip route-cache flow
 no atm ilmi-keepalive
 dsl operating-mode auto
!
interface ATM0.1 point-to-point
 pvc 0/38
  encapsulation aal5mux ppp dialer
  dialer pool-member 1
 !
!
interface FastEthernet0
 no ip address
 no cdp enable
!
interface FastEthernet1
 no ip address
 no cdp enable
!
interface FastEthernet2
 no ip address
 no cdp enable
!
interface FastEthernet3
 no ip address
 no cdp enable
!
interface Vlan1
 description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
 ip address 192.168.1.1 255.255.255.0
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip nat inside
 ip virtual-reassembly
 ip route-cache flow
!
interface Dialer0
 ip address negotiated
 ip nat outside
 ip virtual-reassembly
 encapsulation ppp
 dialer pool 1
 dialer-group 1
 no cdp enable
 ppp authentication chap pap callin
 ppp chap hostname *********************
 ppp chap password 7 XXXXXXXXXXXXXX
 ppp pap sent-username *************** password 7 XXXXXXXXXXXXXX
!
ip classless
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 5 life 86400 requests 10000
!
ip access-list extended PERMITNAT101
 remark SDM_ACL Category=2
 permit tcp any any
 permit udp any any
 permit icmp any any
 permit ip any any
!
logging trap debugging
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
banner login ^CAuthorized access only!
 Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
 login local
 no modem enable
 transport preferred all
 transport output telnet
line aux 0
 login local
 transport preferred all
 transport output telnet
line vty 0 4
 privilege level 15
 login local
 transport preferred all
 transport input telnet ssh
 transport output all
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end

Any help would be appreciated
0
Comment
Question by:CaptainGiblets
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
11 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 17955104
Try adding a default route

ip route 0.0.0.0 0.0.0.0 dialer0
0
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 1000 total points
ID: 17955134
Assuming that the dialer interface is up, I don't see any NAT configuration. Such as:

ip nat inside source list 1 interface dialer0
access-list 1 permit any
0
 
LVL 6

Author Comment

by:CaptainGiblets
ID: 17955208
To lrmoore:

Ah, yes please. forgot about them.

I'll try those config options out and report back if anything else crops us.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 6

Author Comment

by:CaptainGiblets
ID: 17955793
Thats great guys, we can now get external access.

Thanks for that, i'll divvy the points up between you both.

From one problem to another.  We also host an exchange server with Webmail, Active sync and Blackberry enterprise server.

Connecting via active sync is horrifically slow and the other two just time out.  is there a way to speed up access to these services without compromising the security of the router?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 1000 total points
ID: 17959801
I would expect to see some static nat statements to nat outside public IP to an inside host, all the required ports..
I don't see anything like that in the config that you've posted.

something like this:
 ip nat inside source static tcp 192.168.1.100 25 1.2.3.4 25
 ip nat inside source static tcp 192.168.1.100 80 1.2.3.4 80

I'm not sure what ports Blackberry and Active sync require....
0
 
LVL 6

Author Comment

by:CaptainGiblets
ID: 17963583
Lrmoore,

Would the command be something like:

IP nat inside source static tcp [External adderss] 25 [internal address] 25?

Is that the correct syntax for the command?
0
 
LVL 6

Author Comment

by:CaptainGiblets
ID: 17963734
Can I use the command in the following form:

ip nat inside source static tcp 192.168.1.2 25 interface dialer 0 25

or will I have to use IP address to create the NAT between them?
0
 
LVL 6

Author Comment

by:CaptainGiblets
ID: 17965685
I have done the commands to no joy.  This time I can't even get a response from the router via an external connection.

I should've added to the previous comment, our set up is as follows:

Cisco 857 --> ISA 2004 ---> Exchange Server.

The ISA is the gateway for the network and has 2 static addresses of 192.168.1.10 for external and 192.168.0.1 for internal.

192.168.0.1 is the gateway IP address.

The routers internal IP is 192.168.1.1 and we have a static IP address for our wan connection.

the command, ip nat inside source static tcp 192.168.1.2 80 x.x.x.x 80 doesn't seem to work.

Am I missing something?  My config hasn't changed since I introduced the above command for external access.

0
 
LVL 6

Author Comment

by:CaptainGiblets
ID: 17985856
Problem solved.  my Dialer0 wasn't being used as the primary external connection for allowing traffic to come from outside to inside.

How can I divvy the points up between two people?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 17986635
Use the Split Points link right above the comment box

Glad you've figured it out!
0

Featured Post

Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question