Solved

How do I configer cisco router ipvpn to my network?

Posted on 2009-05-09
16
435 Views
Last Modified: 2012-05-06
I have 2 office first one called DMAM (head office) 172.16.X.X and second one is RATA (store office) 172.28.X.X with IPVPN so I call one company provide the IPVPN and that company they arrange the media in both side they give me a UTP cable and they say to me you should have router Cisco 2801 for etch office and they give me the conf. for the routers I already purchase the routers, before 2 days they send Email that say the link is live  
 
DMAM Circuit
---------------- CODE ---------------------
interface Ethernet0/0.208
encapsulation dot1Q 208
ip address 172.31.106.206 255.255.255.252
no shutdown
!
router bgp 65360
neighbor 172.31.106.205 remote-as 65000
no auto-summary
----------------------------------------------
RATA Circuit
---------------- CODE ---------------------
interface Ethernet0/0
ip address 172.31.106.130 255.255.255.252
no shutdown
!
router bgp 65360
neighbor 172.31.106.129 remote-as 65000
no auto-summary
----------------------------------------------
I add the command exactly then I found many problems.
DMAM Circuit what the configuration for interface Ethernet0/1?
I try to configure interface Ethernet0/1 like that

interface Ethernet0/1
ip address 172.16.5.1 255.255.0.0
no shutdown

but when I connect interface Ethernet0/1 to my network I cannot ping interface Ethernet0/1 or interface Ethernet0/0
0
Comment
Question by:AymanDasa
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 4
  • 2
  • +1
16 Comments
 
LVL 5

Expert Comment

by:DTAHARLEV
ID: 24344561
well, start by getting the interface connected to the network and be able to ping it; once you have that, just add "ip routing" and add both networks (network 172.16.106.130 and network 172.16.106.206)
0
 

Author Comment

by:AymanDasa
ID: 24344601
Dear DTAHARLEV

what is the command ?
0
 
LVL 5

Accepted Solution

by:
DTAHARLEV earned 150 total points
ID: 24344685
DMAM:

(config)#ip routing
(config)#ip route 172.31.106.128 255.255.255.252 172.31.106.205
(config)#router rip
(config-router)#network 172.31.106.128
(config-router)#network 172.16.5.0
(config-router)#exit

And the same thing on the other side. I don't have the subnets written in front of me, so i may have some typos there, but the general idea is:

configure DMAM to have a static route to the RATA network (172.16.5.0)
configure RATA to have a static route to the DMAM network.
enable routing (you can just use RIP)
add all three subnets (DMAM, RATA, internal RATA.)

But perhaps you can send a show run printout? I think i have this a bit mixed up.
0
Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

 

Author Comment

by:AymanDasa
ID: 24344843

DMAM10-DMAM10-IP127#show run
Building configuration...
 
Current configuration : 825 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname DMAM10-DMAM10-IP127
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip cef
!
!
!
!
multilink bundle-name authenticated
!
!
!         
archive   
 log config
  hidekeys
!         
!         
!         
!         
!         
interface FastEthernet0/0
 no ip address
 duplex auto
 speed auto
!         
interface FastEthernet0/0.208
 encapsulation dot1Q 208
 ip address 172.31.106.206 255.255.255.252
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router bgp 65360
 no synchronization
 bgp log-neighbor-changes
 neighbor 172.31.106.205 remote-as 65000
 no auto-summary
!
ip forward-protocol nd
!
!
no ip http server
!
!
!
control-plane
!         
!         
line con 0
line aux 0
line vty 0 4
 login    
!         
scheduler allocate 20000 1000
end

Open in new window

0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 150 total points
ID: 24346643
DMAM10-DMAM10-IP127>enable
Password:
DMAM10-DMAM10-IP127#
DMAM10-DMAM10-IP127#config term
DMAM10-DMAM10-IP127(config)#interface fast 0/1
DMAM10-DMAM10-IP127(config-if)#ip address 172.16.5.1 255.255.0.0
DMAM10-DMAM10-IP127(config-if)#no shutdown
DMAM10-DMAM10-IP127(config-if)#end
DMAM10-DMAM10-IP127#write mem
[OK]
DMAM10-DMAM10-IP127#sho ip interface brief
<post results>

DMAM10-DMAM10-IP127#sho ip route
<post results>

.
0
 

Author Comment

by:AymanDasa
ID: 24346936


DMAM10-DMAM10-IP127#show ip interface brief                                     
Interface                  IP-Address      OK? Method Status                Prol
FastEthernet0/0            unassigned      YES NVRAM  up                    dow 
FastEthernet0/0.208        172.31.106.206  YES NVRAM  up                    dow 
FastEthernet0/1            172.16.5.1      YES manual up                    dow 
DMAM10-DMAM10-IP127#
DMAM10-DMAM10-IP127#show ip route                                               
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP                  
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area           
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2           
       E1 - OSPF external type 1, E2 - OSPF external type 2                     
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2    
       ia - IS-IS inter area, * - candidate default, U - per-user static route  
       o - ODR, P - periodic downloaded static route                            
                                                                                
Gateway of last resort is not set     

Open in new window

0
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 199 total points
ID: 24347629
Something is not quite right here:

On the DMAM side, they're having you configure an 802.1q trunk, but only on the DMAM side and there's only one VLAN. If there's only one VLAN, there's no need for 802.1q.

I would check with your provider and confirm those settings.

On the RATA side, is the interface up/up? Can you ping 172.31.106.129?


0
 

Author Comment

by:AymanDasa
ID: 24353416
Dear donjohnston
Thanks for replay

I think its correct because the technician say that " DMAM circuit is WiMax one to many but RATA is coper circuit so its one to one " 

I already send email to provider to make shore the conf. is OK

RATA is very far location around 1490 Km in desert and there is no airport in RATA I can go only by car. so that I wont to finish DMAM site completely the I will open another question for RATA.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 24354005
All of the interfaces show up/down.
Is anything physically plugged into all the interfaces?
0
 

Author Comment

by:AymanDasa
ID: 24356226
No i just some time to test remove the cable don't wary about that
0
 

Author Comment

by:AymanDasa
ID: 24356249
Dear donjohnston

the provider they confirm that the conf. 100% correct.

 
0
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 199 total points
ID: 24356556
There's no native VLAN defined. That could create an Up/Down condition.
0
 

Author Comment

by:AymanDasa
ID: 24356703
I will connect the cable from WiMAX Provider to router the from Router to switch
Current configuration : 942 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname DMAM10-DMAM10-IP127
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip cef
!
!
!
!
no ip domain lookup
multilink bundle-name authenticated
!
!         
!         
username cisco privilege 15 secret 5 $1$nclQ$RUf4tLHyJhG7YAPyzFjKK/
archive   
 log config
  hidekeys
!         
!         
!         
!         
!         
interface FastEthernet0/0
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet0/0.208
 encapsulation dot1Q 208
 ip address 172.31.106.206 255.255.255.252
!
interface FastEthernet0/1
 ip address 172.16.5.1 255.255.0.0
 duplex auto
 speed auto
!
router bgp 65360
 no synchronization
 bgp log-neighbor-changes
 neighbor 172.31.106.205 remote-as 65000
 no auto-summary
!
ip forward-protocol nd
!
!
no ip http server
!         
!         
!         
control-plane
!         
!         
line con 0
 login local
line aux 0
line vty 0 4
 login local
!         
scheduler allocate 20000 1000
end       
DMAM10-DMAM10-IP127#show ip interface brief 
Interface                  IP-Address      OK? Method Status                Protocol
FastEthernet0/0            unassigned      YES NVRAM  up                    up      
FastEthernet0/0.208        172.31.106.206  YES NVRAM  up                    up      
FastEthernet0/1            172.16.5.1      YES NVRAM  up                    up      
DMAM10-DMAM10-IP127#show ip route C
C    172.16.0.0/16 is directly connected, FastEthernet0/1
     172.31.0.0/30 is subnetted, 1 subnets
C       172.31.1DMAM10-DMAM10-IP127#ping  172.31.106.206 so 172.16.5.1
 
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.31.106.206, timeout is 2 seconds:
Packet sent with a source address of 172.16.5.1 
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
 
DMAM10-DMAM10-IP127#ping 172.16.5.1 source 172.31.106.206
 
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.5.1, timeout is 2 seconds:
Packet sent with a source address of 172.31.106.206 
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
DMAM10-DMAM10-IP127#

Open in new window

0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 24357200
This is an improvement. :-)

Now can you ping 172.31.106.205?
0
 

Author Comment

by:AymanDasa
ID: 24361611

DMAM10-DMAM10-IP127#show ip interface brief 
Interface                  IP-Address      OK? Method Status                Protocol
FastEthernet0/0            unassigned      YES NVRAM  up                    up      
FastEthernet0/0.208        172.31.106.206  YES NVRAM  up                    up      
FastEthernet0/1            172.15.5.1      YES NVRAM  up                    up      
DMAM10-DMAM10-IP127#ping 172.31.106.205 source 172.31.106.206
 
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.31.106.205, timeout is 2 seconds:
Packet sent with a source address of 172.31.106.206 
.....
Success rate is 0 percent (0/5)

Open in new window

0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 24363164
I can't think of anything else you can do with the router. You've set it up the way the provider has specified.

The only other thing you can do check with the provider and see if there's something else that needs to be done.
0

Featured Post

How to Defend Against the WCry Ransomware Attack

On May 12, 2017, an extremely virulent ransomware variant named WCry 2.0 began to infect organizations. Within several hours, over 75,000 victims were reported in 90+ countries. Learn more from our research team about this threat & how to protect your organization!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Syslog-ng works. Now what? How to filter and manage? 8 113
Grant drive/folder change permissions to VPN user 6 40
SSH setup on ASA 5505 17 125
Access-List 15 64
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question