Solved

Changing ISP so need to change Cisco 861 Config from DSL PPPOE to Cable connection and VPN tunnel

Posted on 2015-02-11
5
646 Views
Last Modified: 2015-02-17
I am working on a project to improve our internet connection to a satellite office we have.  Currently this office has a 1.5mb DSL connection with a Cisco 861 router configured for a site to site vpn tunnel back to our HQ.  I have ordered a cable internet connection for this office and need to go visit and install.  My question has to do with how to reconfigure the router for the new cable internet connection.  I am not a cisco expert so I just want to run it by my favorite group of experts before I do it.  I am thinking I remove the dialer part of the config and reconfig the WAN port with the ip address of the new cable internet IP address which will be static.  

crypto map ChiOffice 1 ipsec-isakmp
 description Tunnel to Chicago
 set peer xxx.xxx.xxx.xxx (chicgo office public IP)
 set transform-set ChiOffice
 set pfs group5
 match address 101
!
!
!
!
!
interface FastEthernet0
 switchport access vlan 10
 spanning-tree portfast
!
interface FastEthernet1
 switchport access vlan 10
 spanning-tree portfast
!
interface FastEthernet2
 switchport access vlan 10
 spanning-tree portfast
!
interface FastEthernet3
 switchport access vlan 10
!
interface FastEthernet4
 description WAN interface
 no ip address
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 duplex auto
 speed auto
 pppoe-client dial-pool-number 1
 no cdp enable
!
interface Vlan1
 no ip address
!
interface Vlan10
 description Internal Network
 ip address 192.168.145.1 255.255.255.0
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip nbar protocol-discovery
 ip flow ingress
 ip nat inside
 ip virtual-reassembly
!
interface Dialer1
 description DSL PPPOE Dialier
 ip address xxx.xxx.xxx.xxx 255.255.255.248
 no ip unreachables
 ip mtu 1492
 ip nbar protocol-discovery
 ip flow egress
 ip nat outside
 ip virtual-reassembly
 encapsulation ppp
 ip tcp adjust-mss 1452
 dialer pool 1
 dialer-group 1
 ppp authentication pap callin
 ppp pap sent-username xxxxxxxxxxxxxxx password 7 xxxxxxxxxxxxxx
 ppp ipcp dns request accept
 ppp ipcp address accept
 no cdp enable
 crypto map ChiOffice
!
no ip forward-protocol nd
no ip http server
no ip http secure-server
ip flow-export source Vlan10
ip flow-export version 5
ip flow-export destination 192.168.5.10 9996
!
ip nat inside source list 110 interface Dialer1 overload
ip route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx

Thanks in advance for any help, I surely do appreciate EE and all the experts!!!!
0
Comment
Question by:Timothy Kashin
  • 2
  • 2
5 Comments
 
LVL 6

Accepted Solution

by:
Daniel Sheppard earned 500 total points
ID: 40604453
This should be all you need:

interface FastEthernet4
 no pppoe-client dial-pool-number 1
 ip address iad.iad.iad.iad snm.snm.snm.snm
 ip nat outside
 ip flow egress
 ip virtual-reassembly
 crypto map ChiOffice

interface Dialer1
 no crypto map ChiOffice

no ip nat inside source list 110 interface Dialer1 overload
ip nat inside source list 110 interface FastEthernet4 overload
no ip route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx
ip route 0.0.0.0 0.0.0.0 dgw.dgw.dgw.dgw




Also, I would recommend doing the following:

copy running-config startup-config-precableswitch (or something else)

That way, if something happens, you just:
copy startup-config-precableswitch running-config (or startup-config)

Also, handy:
reload in 10  (will reload the router in 10 minutes without saving the running config)
reload cancel (cancels a reload)

Don't save the running until you actually confirm that everything works
0
 
LVL 29

Expert Comment

by:Predrag Jovic
ID: 40604991
To add IP address on port eth 4 probably need to be issued command under interface configuration mode
#no switchport
or in case that command is not supported and port can't be converted to routed interface, IP address need to be added to interface VLAN 1, Eth4 belongs to switching module.

To avoid over sized packets under Eth4 should be
 ip mtu 1492
 ip tcp adjust-mss 1452

 ip nbar protocol-discovery (is optional)
0
 
LVL 6

Expert Comment

by:Daniel Sheppard
ID: 40606428
Predrag,

The FA4 interface on the 800 series routers is a routed interface, it does not need switchport/vlan/etc.
0
 
LVL 29

Expert Comment

by:Predrag Jovic
ID: 40606457
Sorry, my mistake.
:)
I thought that Fa 4 belongs to switch, not to router.
0
 
LVL 3

Author Comment

by:Timothy Kashin
ID: 40606737
Thanks!!! I've adjusted the config in a file and when the install is completed on Tuesday next week I'll let you know the results!!!!
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SolarWinds reporting 2 31
Problem to router 7 82
NAT not working on trunk 6 57
Can't access router with user and pass 10 79
This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question