Solved

Trying to route between ports on the same subnet

Posted on 2007-11-14
5
372 Views
Last Modified: 2011-10-03
I'm trying to a Cisco 1801 to provide a firewall for my public facing servers. I'm also trying to split the switchports into vlans, 4 ports for public servers, and 4 ports for natted devices on a local lan. The physical setup goes like this

fa0 -> speedtouch dsl modem

switchports
fa1 -> web server
fa2 -> mail server
fa3 -> vpn server
fa4
fa5-8 -> natted pc's on a local lan

I'm not using the atm interface for dsl, because my line is too unstable to support a cisco, the atm resets every 5 seconds or so. So i'm using a speedtouch dsl router to route the public ip's through to the cisco so that i can still utilise access lists etc.

I've configured fa0 with a public ip address, and this can get out to the internet no problem. When i configure a server with a public ip and plug it into vlan1 (fa1-4) it fails to even ping fa0.

Anybody got any thoughts on how to configure this and allow natted devices on vlan2 (fa5-8)?

Cheers
Paul
0
Comment
Question by:beplas
  • 3
5 Comments
 
LVL 15

Expert Comment

by:The_Warlock
ID: 20280686
Is your specific vlan routed?
0
 

Author Comment

by:beplas
ID: 20280790
no, both vlan 1 and fa0 are on the same subnet
0
 

Author Comment

by:beplas
ID: 20281309
VLAN1
I think i may need vlan1 un-numbered to fa0, but when i try it i get the error
point-to-point (non-multi-access) interfaces only

VLAN2
i have this line in the config
ip nat inside source list 1 interface Vlan3 overload

but when i enter 'ip nat outside' on fa0 i am unable to ping any public ip's
0
 
LVL 10

Accepted Solution

by:
cstosgale earned 500 total points
ID: 20293460
The easiest solution would be to use a seperate  internal ip range for  the server vlan and use one to one nat from the external interface to vlan 1.

Therefore if you  have public IPs 82.138.231.2 - 7, use say 192.168.1.0 for your servers.

hen use .2 for the fa0 interface, and do a static one to one nat between 82.138.231.3 and 192.168.1.1 for example.

This will give you the same functionality as having public ips for your servers but simplify the routing between internal subnets.

The nat statement above is incorrect as the interface needs to be the outside interface ont the inside interface i.e. ip nat inside source list 1 interface fa0 overload

In addition, for nat to work, you need ip nat inside on any inside interfaces. This would include vlan 1.
In order to prevent the wrong traffic from being natted, make sure source list 1 only contains rules for the workstation subnet. You may find that you will need to use a route map for this as apposed to an access list.
0
 

Author Closing Comment

by:beplas
ID: 31409182
Worked perfectly, don't know why i didn't think of that myself (that's why YOU are the expert! :))
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now