https sites  does work on cisco 1841 in ppoe

Posted on 2009-05-10
Medium Priority
Last Modified: 2012-05-06
Dear All,

I have a cisco 1841 router which is configured in PPPOE mode  I can browse the internet  but cannot browse the https sites. Any help would  be highly appriciated.

Question by:sankoorikal
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Expert Comment

by:Ilir Mitrushi
ID: 24353979
Can you post your config?

Author Comment

ID: 24355114
HI Mitrushi,

Thanks for the reply.Please find the config.

hostname xxxxxxxx


enable secret xxxxx

mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
no aaa new-model
ip subnet-zero
ip cef

ip dhcp excluded-address

ip dhcp pool 0
   lease 25

ip ips po max-events 100

username nobby privilege 15 secret 5745619

 log config
crypto isakmp policy 1
 encr 3des
 hash md5
 authentication pre-share
 group 2
no crypto isakmp ccm

crypto isakmp client configuration group xxxxxx
 key xxxxxxx
 acl 199

crypto ipsec transform-set VITAVPN-SET esp-3des esp-md5-hmac
crypto dynamic-map VITAVPN-DYN 10
 set transform-set VITAVPN-SET

crypto map VITAVPN-MAP client authentication list userauth
crypto map VITAVPN-MAP isakmp authorization list groupauth
crypto map VITAVPN-MAP client configuration address respond
crypto map VITAVPN-MAP 10 ipsec-isakmp dynamic VITAVPN-DYN

interface FastEthernet0/0
 description -Kidanet PPPoE Account-
 no ip address
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 no ip mroute-cache
 duplex auto
 speed auto
 pppoe enable
 pppoe-client dial-pool-number 1
 no cdp enable

interface FastEthernet0/1
 description -LAN Interface-
 ip address
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip nat inside
 ip virtual-reassembly
 no ip mroute-cache
 duplex auto
 speed auto
 no cdp enable
interface Dialer0
 no ip address
 no cdp enable

interface Dialer1
 description -PPPoE Dialer-
 ip address negotiated
 no ip unreachables
 ip nat outside
 ip virtual-reassembly
 encapsulation ppp
 no ip mroute-cache
 dialer pool 1
 dialer-group 1
 no cdp enable
 ppp authentication chap callin
 ppp pap sent-username xxxxx password xxxxxx

ip local pool VITA-VPN-POOL
ip classless
ip route Dialer1

no ip http server
no ip http secure-server
ip nat inside source list 101 interface Dialer1 overload
access-list 1 permit
access-list 101 remark ### NAT'd Traffic ###
access-list 101 deny   ip
access-list 101 permit ip any
access-list 102 permit ip any any
access-list 199 remark ### Split Tunnel ###
access-list 199 permit ip
access-list 199 remark ### Split Tunnel ###
dialer-list 1 protocol ip permit
snmp-server community public RO
no cdp run


line con 0
line aux 0
line vty 0 4
 password 5745619

Accepted Solution

Ilir Mitrushi earned 2000 total points
ID: 24355580
configuration looks fine. It may be a fragmentation issue. Check the mtu on dialer 1 interface. It should be 1492. If it is not you can change it with mtu 1492 command when in interface config mode
show interface dialer 1

conf t
interface dialer 1
mtu 1492


Author Comment

ID: 24362932
Hi Mitrushi,
Thanks a ton

Expert Comment

by:Ilir Mitrushi
ID: 24363462
my pleasure!
Take care

Featured Post

The Ideal Solution for Multi-Display Applications

Check out ATEN’s VS1912 12-Port DP Video Wall Media Player at InfoComm 2017. Kerri describes how easy it is to design creative video walls in asymmetric layouts and schedule detailed playlists ahead of time with its advanced scheduling feature.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the Top 10  common Cisco VPN problems are not-matching shared keys. This is an easy one to fix, but not always easy to notice, see the case below. A simple IPsec tunnel between fast Ethernet interfaces of routers SW1 (f1/1) and R1(f0/0). …
For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question