cannot ping to internal lan ip from cisco router

i have  a cisco router 2811 and we have lease line on this router. we are using internet perfectly. but  when ping to internal lan ip in the series of 192.168.11.0 its cannot ping. i attach my router configuration. some of the commands as below :-

ip nat pool ovrld 220.XXX.XXX.117 XXX.XXX.159.117 netmask 255.255.255.252
ip nat inside source list 7 pool ovrld overload
access-list 7 permit 192.168.11.0 0.0.0.255

Router#ping 192.168.11.100

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.11.100, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Router#

Router#show ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route

Gateway of last resort is 220.XXX.XXX.118 to network 0.0.0.0

     115.0.0.0/27 is subnetted, 1 subnets
C       115.XXX.XXX.96 is directly connected, FastEthernet0/1
     172.16.0.0/30 is subnetted, 1 subnets
C       172.16.0.0 is directly connected, FastEthernet0/1
C    192.168.11.0/24 is directly connected, FastEthernet0/1
     220.XXX.XXX.0/30 is subnetted, 1 subnets
C       220.XXX.XXX.116 is directly connected, FastEthernet0/0
S*   0.0.0.0/0 [1/0] via 220.XXX.XXX.118

Router#show ip int brief
Interface                  IP-Address      OK? Method Status                Prot
ocol
FastEthernet0/0            220.XXX.XXX.117 YES NVRAM  up                    up

FastEthernet0/1            115.XXX.XXX.97  YES NVRAM  up                    up

NVI0                       220.XXX.XXX.117 YES unset  up                    up

please tell how to ping internal lan ip from router .

thanks
cisco-router-2811.txt
ManojtanwarAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

MiftaulCommented:
what is the default Gateway address on the client machines.
0
JustInCaseCommented:
Try extended ping command

#ping

Protocol [ip]:
Target IP address: 192.168.11.100
Repeat count [5]:
Datagram size [100]:
Timeout in seconds [2]:
Extended commands [n]: y
Source address or interface: 192.168.11.10
Set DF bit in IP header? [no]:
Validate reply data? [no]:
Data pattern [0xABCD]:
Loose, Strict, Record, Timestamp, Verbose[none]:
Sweep range of sizes [n]:

if that does not work .. there is some other problem (ACL, firewall etc)

You need to enter bold values, for the rest just press enter.
And does ping fail for all hosts or just this one?
0
ManojtanwarAuthor Commented:
i try result is given below i cannot ping

router#ping
Protocol [ip]: ip
Target IP address: 192.168.11.100
Repeat count [5]: 5
Datagram size [100]: 100
Timeout in seconds [2]: 2
Extended commands [n]: n
Sweep range of sizes [n]: n
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.11.100, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)

if possibe please look at my router configuration and sugges me acl permission command

 thanks
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

JustInCaseCommented:
Try with
Extended commands [n]: Y

And if some acl is blocking ping - it is not on this router, it is set on some other device.
0
ManojtanwarAuthor Commented:
i do it
rotocol [ip]: ip
Target IP address: 192.168.11.100
Repeat count [5]: 5
Datagram size [100]: 100
Timeout in seconds [2]: 2
Extended commands [n]: y
Source address or interface: fa0/1
% Invalid source. Must use IP address or full interface name without spaces (e.g
. Serial0/1)
Source address or interface: 192.168.11.10
Type of service [0]: 0
Set DF bit in IP header? [no]: no
Validate reply data? [no]: no
Data pattern [0xABCD]: 0xABCD
Loose, Strict, Record, Timestamp, Verbose[none]: NONE
% No such option - "NONE"Loose, Strict, Record, Timestamp, Verbose[none]:
Sweep range of sizes [n]: N
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.11.100, timeout is 2 seconds:
Packet sent with a source address of 192.168.11.10
.....
Success rate is 0 percent (0/5)
0
JustInCaseCommented:
Can you ping 192.168.11.10 from host with ip address 192.168.11.100?
0
ManojtanwarAuthor Commented:
yes i can do

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved

C:\Users\DHBVN>ping 192.168.11.10

Pinging 192.168.11.10 with 32 bytes of data:
Reply from 192.168.11.10: bytes=32 time=1ms TTL=255
Reply from 192.168.11.10: bytes=32 time=1ms TTL=255
Reply from 192.168.11.10: bytes=32 time=2ms TTL=255
Reply from 192.168.11.10: bytes=32 time=1ms TTL=255

Ping statistics for 192.168.11.10:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 1ms, Maximum = 2ms, Average = 1ms

C:\Users\DHBVN>
0
JustInCaseCommented:
Check ACL configured on VLAN for 192.168.11.0/24 network.
0
ManojtanwarAuthor Commented:
ip http server
ip http authentication local
ip nat pool ovrld 220.xxx.xxx.117 220.xxx.xxx.117 netmask 255.255.255.252
ip nat inside source list 7 pool ovrld overload
ip nat inside source static tcp 192.168.11.20 8080 115.xxx.xxx.106 8080 extendab
le
ip nat inside source static udp 192.168.11.20 8080 115.xxx.xxx.106 8080 extendab
le
ip nat inside source static tcp 192.168.11.22 8081 115.xxx.xxx.106 8081 extendab
le
ip nat inside source static udp 192.168.11.22 8081 115.xxx.xxx.106 8081 extendab
le
!
access-list 7 permit 192.168.11.0 0.0.0.255
snmp-server community private RW
!
!
control-plane

this is my all command i have applied

please suggest me acl command
0
JustInCaseCommented:
Problem is not on that router.
Some other router or switch is blocking ping - check ACL on your other devices on a path to host.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ManojtanwarAuthor Commented:
thanks my antivirus firewall is blocking this thanks
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.