Solved

Cisco Router Config Question

Posted on 2015-01-30
15
59 Views
Last Modified: 2015-02-18
Hello Experts

Can someone please take a look at the configuration and let me know why I can ping google on 8.8.8.8 from WAN interface GE0/1 but not from LAN Interface GE0/0?

I have default route but still can't ping from source 192.168.30.1

Regards

Carlton
0
Comment
Question by:cpatte7372
  • 7
  • 4
  • 3
  • +1
15 Comments
 
LVL 6

Expert Comment

by:Matt
Comment Utility
Can you ping from internal LAN to router's VLAN interface?
0
 
LVL 26

Expert Comment

by:Predrag Jovic
Comment Utility
Probably you don't have NAT configured (or NAT is misconfigured), but paste configuration.
:)
0
 

Author Comment

by:cpatte7372
Comment Utility
I can ping 192.168.30.1 from within the router (if that's what you mean)?
0
 

Author Comment

by:cpatte7372
Comment Utility
Pred

I don't think NAT is required
0
 
LVL 26

Expert Comment

by:Predrag Jovic
Comment Utility
Oh, yes it is... you can't ping from private address space to internet directly. :)
You must ping from public IP address. NAT translates your private IP address to public IP address.
0
 

Author Comment

by:cpatte7372
Comment Utility
so will the following work

ip nat pool guargon 59.x.x.1 59..1 netmask 255.255.255.252
ip nat inside source list 1 pool guargon overload
0
 
LVL 26

Expert Comment

by:Predrag Jovic
Comment Utility
access-list 1 permit 192.168.30.0 0.0.0.255

ip nat pool guargon 59.x.x.1 59.x.x.x netmask 255.255.255.252

ip nat inside source list 1 pool guargon overload
(or simply without IP pool for WAN, if you don't need one
ip nat inside source list 1 interface GE0/1 overload)

interface GE0/1
  ip nat outside

interface GE0/0
  ip nat inside
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:cpatte7372
Comment Utility
Pred,

It didn't work. Please see my attachment with your suggestions
output2.txt
0
 
LVL 28

Expert Comment

by:mikebernhardt
Comment Utility
First, you need to move "ip nat outside" to interface GigabitEthernet0/1.3861 because that's where the IP address is.

2nd, get rid of the ip nat pool and simply do:
ip nat inside source list 1 interface GigabitEthernet0/1.3861 overload

The nat pool statement you used is attempting to nat your inside addresses to the address of your ISP and that wouldn't work anyway. The above will make everything look like it's coming from your router interface.
0
 

Accepted Solution

by:
cpatte7372 earned 0 total points
Comment Utility
Hi Pred,

I will try your suggestion
0
 
LVL 28

Expert Comment

by:mikebernhardt
Comment Utility
You mean Mike, not Pred...
0
 

Author Comment

by:cpatte7372
Comment Utility
Sorry Mike,

Anyway, it didn't work.. please check out configs
18-48-19--jmeu-gurgaon.txt
0
 
LVL 28

Expert Comment

by:mikebernhardt
Comment Utility
Your inbound access list "Permitted-Inbound-Internet" doesn't really permit anything to come back to you. I don't know how you're testing but can you ping 59.xx.xx.11 from the LAN?

You're also missing a default route:
ip route 0.0.0.0 0.0.0.0 59.xx.xx.11
0
 
LVL 26

Expert Comment

by:Predrag Jovic
Comment Utility
Is this mean that you are going to internet through distant location?
(Private IP  DNS  servers - out of IP pool on this router - point into this direction)

I don't see default route here, so I can only presume that you get internet through tunnel and default route from eigrp.
In that case you might not need NAT, NAT can be done on another router.

What is output from
#show ip route

Is this all relevant info in config, or there are some other missing puzzle pieces? :)
(Looks like they do, since this time there is no IP DHCP pool in configuration.)

If there is a default route in routing table remove NAT completely and issue
#traceroute 8.8.8.8
0
 

Author Closing Comment

by:cpatte7372
Comment Utility
Cheers
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now