?
Solved

Cisco Router NAT with DHCP on VLAN's

Posted on 2014-03-12
8
Medium Priority
?
983 Views
Last Modified: 2014-03-14
Hi All,

Hope everyone is well. I have something which im banging my head against a wall with.

I have a Linksys Router connected to my ISP. This router is configured and working. If i connect a client up to it it allocated DHCP on a 192.168.1.xxx /24 Range.

We have recently implemented VLAN's onsite and these are all sat on the Cisco Router. All this is working fine and VLAN to VLAN IP's can be pinged. Im now trying to connect the Cisco Router to the Linksys Router so all VLAN's can have internet access. Unfortunatly i cannot do PPPoE from the Cisco to the ISP as there Service Agreement will not allow me to do this for a couple of reasons.

I cannot seem to get internet access working from any of the VLAN's though. Here is my router config:-

version 12.4
no parser cache
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
no service dhcp
!
hostname ROUTER
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
no logging console
enable secret 5 1234567890
!
aaa new-model
!
!
!
!
aaa session-id common
no ip source-route
no ip routing
!
!
no ip cef
!
!
no ip bootp server
no ip domain lookup
ip domain name trustgroup.local
multilink bundle-name authenticated
!
!
!
username sysadmin privilege 15 password 7 1234567890
archive
 log config
  hidekeys
!
!
ip tcp synwait-time 10
!
!
!
interface Null0
 no ip unreachables
!
interface FastEthernet0/0
 description ** Connected to ISP **
 ip address dhcp
 ip nat outside
 ip virtual-reassembly
 no ip route-cache
 duplex auto
 speed auto
!
interface FastEthernet0/1
 description ** Connected to Local LAN **
 no ip address
 ip nat inside
 ip virtual-reassembly
 no ip route-cache
 duplex auto
 speed auto
!
interface FastEthernet0/1.101
 encapsulation dot1Q 101
 ip address 10.1.1.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 no ip route-cache
!
interface FastEthernet0/1.102
 encapsulation dot1Q 102
 ip address 10.1.2.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 no ip route-cache
!
interface FastEthernet0/1.103
 encapsulation dot1Q 103
 ip address 10.1.3.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 no ip route-cache
!
interface FastEthernet0/1.104
 encapsulation dot1Q 104
 ip address 10.1.4.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 no ip route-cache
!
interface FastEthernet0/1.110
 encapsulation dot1Q 110
 ip address 10.1.110.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 no ip route-cache
!
!
!
ip http server
ip nat inside source list 101 interface FastEthernet0/0 overload
!
access-list 101 permit ip 192.168.1.0 0.0.0.255 any
!
!
control-plane
!
!
line con 0
 password 7 046F19131C351D1C5A5D41
 logging synchronous
line aux 0
line vty 0 4
 password 7 053F141A32581F5B4A4153
line vty 5 15
 password 7 15261919173E7A767B7771
!
scheduler max-task-time 5000
scheduler allocate 20000 1000
ntp master
!
end

Could anybody Help?

Cheers
TME
0
Comment
Question by:TrustGroup-UAE
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 9

Expert Comment

by:ffleisma
ID: 39924375
you NAT ACL does not include your VLAN subnets

access-list 101 permit ip 192.168.1.0 0.0.0.255 any

consider adding the following:

access-list 101 permit ip 10.1.0.0 0.0.255.255 any

hope this helps
0
 
LVL 1

Author Comment

by:TrustGroup-UAE
ID: 39925754
Hi there,

I have added the above but still no joy.

I can ping all 10.1.xxx.xxx from the client no problems but cannot get anothing out on the internet. From the router i can Ping Internet Addresses.

Cheers
Si
0
 
LVL 26

Expert Comment

by:Soulja
ID: 39926514
Is the port on the switch that connects to the router configured as a trunk with dot1q encapsulation?

Can you also post the output of:

sh ip nat translations
sh ip route
sh ip access-lists

Thanks!
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 
LVL 1

Author Comment

by:TrustGroup-UAE
ID: 39926945
Hi,

Thanks for your Response. Please see details below:-

Switch Config is:-

interface FastEthernet0/2
 description ** Service Router Uplink - FA0/1 **
 switchport mode trunk

Sh IP Nat Translation - Shows nothing

Default Gateway shows:-

Default gateway is 192.168.1.1

Host               Gateway           Last Use    Total Uses  Interface
ICMP redirect cache is empty

Show Access List shows:

Access list:-

Extended IP access list 101
    10 permit ip any any (15 matches)

I have also updated my IOS from 12.4 to 15.1. Below is the Config:

version 15.1
no parser cache
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
no service dhcp
!
hostname TMES1RT001
!
boot-start-marker
boot system flash:c2800nm-adventerprisek9-mz.151-4.M7.bin
boot-end-marker
!
!
logging buffered 51200
no logging console
!
aaa new-model
!
!
!
!
!
!
!
aaa session-id common
!
!
dot11 syslog
no ip source-route
no ip routing
!
!
no ip cef
!
!
!
no ip bootp server
no ip domain lookup
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
!
!
!
!
!
!
!
voice-card 0
!
crypto pki token default removal timeout 0
!
!
!
!
license udi pid CISCO2811
archive
 log config
  hidekeys
!
redundancy
!
!
ip tcp synwait-time 10
!
!
!
!
!
!
!
!
interface Null0
 no ip unreachables
!
interface FastEthernet0/0
 description ** Connected to Etisalat **
 ip address dhcp
 ip nat outside
 no ip virtual-reassembly in
 no ip route-cache
 duplex auto
 speed auto
!
interface FastEthernet0/1
 description ** Connected to Local LAN **
 no ip address
 ip nat outside
 ip virtual-reassembly in
 no ip route-cache
 duplex auto
 speed auto
!
interface FastEthernet0/1.101
 encapsulation dot1Q 101
 ip address 10.1.1.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
 no ip route-cache
!
interface FastEthernet0/1.102
 encapsulation dot1Q 102
 ip address 10.1.2.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
 no ip route-cache
!
interface FastEthernet0/1.103
 encapsulation dot1Q 103
 ip address 10.1.3.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
 no ip route-cache
!
interface FastEthernet0/1.104
 encapsulation dot1Q 104
 ip address 10.1.4.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
 no ip route-cache
!
interface FastEthernet0/1.110
 encapsulation dot1Q 110
 ip address 10.1.110.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
 no ip route-cache
!
ip forward-protocol nd
ip http server
no ip http secure-server
!
!
ip nat inside source list 101 interface FastEthernet0/0 overload
!
access-list 101 permit ip any any
!
!
!
!
control-plane
!
!
!
!
mgcp profile default
!
!
!
!
!
!
line con 0
 logging synchronous
line aux 0
line vty 0 4
 transport input all
line vty 5 15
 transport input all
!
scheduler max-task-time 5000
scheduler allocate 20000 1000
ntp master
end

Cheers Again for you help
TME
0
 
LVL 26

Accepted Solution

by:
Soulja earned 2000 total points
ID: 39926986
This stuck out:

no ip routing

Change to

ip routing
0
 
LVL 26

Expert Comment

by:Soulja
ID: 39926993
Also if you want the vlan to talk to one another you want to add to your NAT ACL to deny vlan to vlan traffic

i.e.
deny ip 10.1.1.0 0.0.0.255 10.1.4.0 0.0.0.255
0
 
LVL 1

Author Comment

by:TrustGroup-UAE
ID: 39928676
Excellent!

That worked a treat!

Thanks for your Help!
0
 
LVL 1

Author Closing Comment

by:TrustGroup-UAE
ID: 39928678
Awsome! Stuck with the probelm and worked to cpmletion! Full Credits!
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month13 days, 4 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question