Solved

Is this a NAT issue?

Posted on 2007-03-23
4
349 Views
Last Modified: 2010-03-18
I know there's someone here that can help me with this. I have a problem with a lab I'm trying to set up. Here's how I have it set up:

I have a Cisco 2600 router as my WAN router (connected to my ISP through a cable modem). The cable modem is connected to the fastethernet 0/0 port on my router.

The fastethernet 0/1 port on the router is connected to a pair of trunked Cisco 3512 switches. All ports on both switches are running on VLAN 2. There are 2 PCs and 1 server connected to ports on either of the 3512 switches.

The 2600 router has full connectivity to every device in my LAN and to the ISP default gateway. There's nothing this router can't ping on my LAN. I've also successfully pinged a few different DNS servers just to make sure my router can reach the internet. So the problem I'm having is definitely with the 2600 router.

My LAN IP scheme is 10.2.2.x 255.255.255.240. I have a static route on my router and is the following:
ip route 0.0.0.0 0.0.0.0 f0/0
(so I'm telling my router to forward packets with any IP and mask to f0/0 which takes them to the internet.)

I also put a static route in (which I'm not sure is necessary), which was:
ip route 10.2.2.0 255.255.255.240 f0/1

The PC I'm on to test the network is connected to one of the 3500 switches. The PC I'm on can also ping all devices on my LAN. The PC can also ping the WAN interface (f0/0) on the 2600 router.

Problem is, I can't ping my ISP default gateway from my PC!! As a result, I have no internet access from my PCs. The ONLY device that can communicate with the internet is my 2600 router.

I believe the problem has something to do with NAT. I was not able to find any NAT settings on my 2600 router. A few questions:
-Is my 2600 router capable of acting as my edge router? How can I determine this?
-Do I need to configure NAT to get this setup to work?
-If the solution is not NAT, what could be the problem?
0
Comment
Question by:COE-IT
  • 3
4 Comments
 
LVL 6

Expert Comment

by:brasslan
ID: 18783303
Yes, most likely, your 10.2.2.0 IP's will not flow accross your cable ISP.
Your ISP probably has a public IP address that you need to assign to the outside of your router, or you need your router to obtain this IP thrugh DHCP.  Then you need to nat the inside network to this IP address.
0
 
LVL 6

Expert Comment

by:brasslan
ID: 18783383
If you need router commands you might try these.  To be honest, I'm much better NATing with a pix and don't really know the router Nat commands.

Router>en
Router#conf t
Router(config)#int f0/1
Router(config-if)#ip nat inside   //this is to your trusted network - LAN
Router(config-if)#int f0/0
Router(config-if)#ip nat out       //this is to untrusted network - WAN
Router(config-if)#exit
Router(config)#access-list 1 permit 192.xxx.xxx.xxx 0.0.0.255
Router(config)#ip nat inside source list 1 interface fast0/0 overload

Hope this helps
0
 
LVL 1

Author Comment

by:COE-IT
ID: 18785606
Thanks, I don't think my router supports NAT but I'll try these commands
0
 
LVL 6

Accepted Solution

by:
brasslan earned 125 total points
ID: 18786319
I don't know of a Cisco router that doesn't support nat.

If those nat commands don't help, and if no one else posts for a day or two, I would post another question asking how to setup nat on your router.  Also include your IOS version, and if you post your router config someone will give you the commands that you need for your situation.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
EXSi 6.x hosts on vCenter 5.5 7 78
gns3 with layer 3 switch 6 32
Need a cheap RFID setup 10 43
HSRP needed? 4 31
Security is one of the biggest concerns when moving and migrating your data from your on-premise location to the Public Cloud.  Where is your data? Who can access it? Will it be safe from accidental deletion?  All of these questions and more are imp…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now