Solved

Trying to route between ports on the same subnet

Posted on 2007-11-14
5
373 Views
Last Modified: 2011-10-03
I'm trying to a Cisco 1801 to provide a firewall for my public facing servers. I'm also trying to split the switchports into vlans, 4 ports for public servers, and 4 ports for natted devices on a local lan. The physical setup goes like this

fa0 -> speedtouch dsl modem

switchports
fa1 -> web server
fa2 -> mail server
fa3 -> vpn server
fa4
fa5-8 -> natted pc's on a local lan

I'm not using the atm interface for dsl, because my line is too unstable to support a cisco, the atm resets every 5 seconds or so. So i'm using a speedtouch dsl router to route the public ip's through to the cisco so that i can still utilise access lists etc.

I've configured fa0 with a public ip address, and this can get out to the internet no problem. When i configure a server with a public ip and plug it into vlan1 (fa1-4) it fails to even ping fa0.

Anybody got any thoughts on how to configure this and allow natted devices on vlan2 (fa5-8)?

Cheers
Paul
0
Comment
Question by:beplas
  • 3
5 Comments
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 20280686
Is your specific vlan routed?
0
 

Author Comment

by:beplas
ID: 20280790
no, both vlan 1 and fa0 are on the same subnet
0
 

Author Comment

by:beplas
ID: 20281309
VLAN1
I think i may need vlan1 un-numbered to fa0, but when i try it i get the error
point-to-point (non-multi-access) interfaces only

VLAN2
i have this line in the config
ip nat inside source list 1 interface Vlan3 overload

but when i enter 'ip nat outside' on fa0 i am unable to ping any public ip's
0
 
LVL 10

Accepted Solution

by:
cstosgale earned 500 total points
ID: 20293460
The easiest solution would be to use a seperate  internal ip range for  the server vlan and use one to one nat from the external interface to vlan 1.

Therefore if you  have public IPs 82.138.231.2 - 7, use say 192.168.1.0 for your servers.

hen use .2 for the fa0 interface, and do a static one to one nat between 82.138.231.3 and 192.168.1.1 for example.

This will give you the same functionality as having public ips for your servers but simplify the routing between internal subnets.

The nat statement above is incorrect as the interface needs to be the outside interface ont the inside interface i.e. ip nat inside source list 1 interface fa0 overload

In addition, for nat to work, you need ip nat inside on any inside interfaces. This would include vlan 1.
In order to prevent the wrong traffic from being natted, make sure source list 1 only contains rules for the workstation subnet. You may find that you will need to use a route map for this as apposed to an access list.
0
 

Author Closing Comment

by:beplas
ID: 31409182
Worked perfectly, don't know why i didn't think of that myself (that's why YOU are the expert! :))
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Edgemax OS VPN, to Barracuda Link Balancer 7 157
Wireless network monitoring 8 54
Getting locked out and can't access Cisco via the web 18 39
Viber-Only Restriction 6 26
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now