• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 327
  • Last Modified:

T1 installation

I am setting up a T1 and was provided with a diagram with the information. I was wondering if anyone had a config that I could use as an example. It includes S0/0, FA0/0, and modem interface. I am unsure how to setup the modem part. Also I am unsure as to why my FA0/0 interface would get a 12.x.x.x network for local LAN instead of a normal 192.x.x.x network.
  • 4
  • 2
1 Solution
Here is a basic configuration.

You don't need to use the public range on the fa0/0 interface.  You can use a private range and use the public range for NAT.

To connect the modem to the router, use the specified cable and connect to the console port on the router.  No configuration is necessary on the router.

enable secret <password>

interface FastEthernet0/0
 ip address
 ip nat inside

interface Serial0/0/0
 ip address
 encapsulation ppp
 ip nat outside

ip nat pool nat-pool netmask
ip nat inside source list nat pool nat-pool overload
ip access-list standard nat

ip access-list standard 1

line vty 0 15
password <password>
access-class 1 in    <--restrict telnet to inside network
Sorry, forgot default route:

ip route
occs07Author Commented:
another question: if I wanted to block everything and only allow HTTP and HTTPS what would I have as my access-list? My thoughts are this:

access-list 100 deny any any
access-list 100 permit any any eq www
access-list 100 permit any any eq https
SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

If outbound, do this to allow DNS (required) and HTTP/HTTPS.

ip access-list ext 150
permit udp any any eq 53
permit tcp any any eq 80
permit tcp any any eq 443
deny ip any any

int fa0/0
ip access-group 150 in
occs07Author Commented:
I am trying to block people from accessing anything but HTTP/HTTPS, i.e. I only want them to be able to use the internet on the network. So wouldnt I need this inbound and outbound? If so how?
The access-list I posted blocks everything but HTTP/HTTPS (DNS) outbound meaning anyone sitting on the fa0/0 LAN can only connect to the Internet using HTTP/HTTPS.  Is that what you want?  Nobody on the Internet can connect to anything on your LAN as it stands because you have no inbound NAT configured.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

  • 4
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now