<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot connect to router via public IP address in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312498#M222367</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest changing your address translation. Try using something like this and tell us if it makes a difference&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface GigabitEthernet0/0 overload&lt;/P&gt;&lt;P&gt;access-list 1 permit ip 192.168.1.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Oct 2013 14:27:35 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2013-10-11T14:27:35Z</dc:date>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312494#M222363</link>
      <description>&lt;P&gt;Forgive me, I'm pretty much brand new to Cisco networking.&amp;nbsp; I've just set up a Cisco 3825 router to practice on, and I cannot connect to the router via my public IP address (http(s), telnet, ssh, etc), and I'm not quite sure as to where I've gone wrong.&amp;nbsp; I'm not having any issues connecting to the router from behind the network, and there are no issues with anything behind the network accessing the internet.&amp;nbsp; Where might I start looking to troublehsoot this issue?&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 05:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312494#M222363</guid>
      <dc:creator>Joshua Smick</dc:creator>
      <dc:date>2019-03-05T05:17:13Z</dc:date>
    </item>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312495#M222364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post your config and tell us from where you are trying to access the router with its public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 06:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312495#M222364</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-10-11T06:24:46Z</dc:date>
    </item>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312496#M222365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alain, I just wiped my original configuration and rebuilt it because I thought I had too many mistakes in the old one.&amp;nbsp; This is what I have now:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Router&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret 4 L3yDU5muhsZ/hpwNZQ1owTr51gJKqTKSL0o7ewMUVJs&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 syslog&lt;/P&gt;&lt;P&gt;ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool TARDIS_CLIENTS&lt;/P&gt;&lt;P&gt; import all&lt;/P&gt;&lt;P&gt; network 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; default-router 192.168.1.1 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ipv6 cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;voice-card 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki token default removal timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint TP-self-signed-2013182566&lt;/P&gt;&lt;P&gt; enrollment selfsigned&lt;/P&gt;&lt;P&gt; subject-name cn=IOS-Self-Signed-Certificate-2013182566&lt;/P&gt;&lt;P&gt; revocation-check none&lt;/P&gt;&lt;P&gt; rsakeypair TP-self-signed-2013182566&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki certificate chain TP-self-signed-2013182566&lt;/P&gt;&lt;P&gt; certificate self-signed 01&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 69666963 6174652D 32303133 31383235 3636301E 170D3133 31303131 30373437 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 30355A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30313331 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 38323536 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 8100B56B E21BB94D EAF82B97 8DD74544 37CB065C 4167BCE8 07919F9E A40ECB10 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 52E01F20 0C99DBA6 575488F5 471F5D44 F22008D9 EB8A43A2 04543B98 2DE93479 &lt;/P&gt;&lt;P&gt;&amp;nbsp; FCD433D4 99413B0C A46DE6DE 9E7702B7 D3AD3C72 D0C30F65 6461870E B55ADA2A &lt;/P&gt;&lt;P&gt;&amp;nbsp; E8EC6AB5 477F2163 909EC85C 5432C5B6 6C57C95A EF9389AC AF9AE269 0A2A48A1 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 823D0203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 551D2304 18301680 14B4B90E 6B3A34C7 4BF07C00 53CA4C07 466BFBD5 C3301D06 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 03551D0E 04160414 B4B90E6B 3A34C74B F07C0053 CA4C0746 6BFBD5C3 300D0609 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 2A864886 F70D0101 05050003 8181009C 3947D807 D136FE11 E394F131 B9DFCE81 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 68EE60F4 C53C8D4E 3E6D98E5 A9F64DC4 B6B31D6D DDCC34BD DD732735 77CBBB84 &lt;/P&gt;&lt;P&gt;&amp;nbsp; EDA5A708 324CFEB4 2D42374B E0751E80 D526D9AB 662BD3F9 3DF8F952 3BF042E7 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 6BB3B1EB 30763DFC 010DEC50 13451155 422ADC5D 6A70A370 31DA33F2 1BA5173F &lt;/P&gt;&lt;P&gt;&amp;nbsp; 176269F9 39919D01 0D393B55 3815FC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;quit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO3825 sn FTX1002C11E&lt;/P&gt;&lt;P&gt;username josh privilege 15 secret 4 L3yDU5muhsZ/hpwNZQ1owTr51gJKqTKSL0o7ewMUVJs&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;redundancy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; ip address dhcp&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; media-type rj45&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; media-type rj45&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http authentication local&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source list 101 interface GigabitEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 192.168.1.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mgcp profile default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; privilege level 15&lt;/P&gt;&lt;P&gt; password 7 0023120A0D550A5457711C0F&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt; transport input telnet ssh&lt;/P&gt;&lt;P&gt; transport output telnet ssh&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; privilege level 15&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt; transport input telnet ssh&lt;/P&gt;&lt;P&gt; transport output telnet ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;scheduler allocate 20000 1000&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 08:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312496#M222365</guid>
      <dc:creator>Joshua Smick</dc:creator>
      <dc:date>2013-10-11T08:02:04Z</dc:date>
    </item>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312497#M222366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st do this:&lt;/P&gt;&lt;P&gt;no ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0&amp;nbsp; dhcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And tell us what is connected out g0/0, I suppose it is an xdsl modem/router, if so you should make&amp;nbsp; a manual reservation on it for the IP address of g0/0 and port forward the necessary services you want to access on the router.&lt;/P&gt;&lt;P&gt;do this on the router to facilitate the reservation on the modem/router:&lt;/P&gt;&lt;P&gt;int g0/0&lt;/P&gt;&lt;P&gt;ip dhcp client client-id interface g0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and take note of the MAC of g0/0 interface with do show int g0/0 | i bia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 09:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312497#M222366</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-10-11T09:27:58Z</dc:date>
    </item>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312498#M222367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest changing your address translation. Try using something like this and tell us if it makes a difference&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface GigabitEthernet0/0 overload&lt;/P&gt;&lt;P&gt;access-list 1 permit ip 192.168.1.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 14:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312498#M222367</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-10-11T14:27:35Z</dc:date>
    </item>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312499#M222368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alain, that absolutely fixed it.&amp;nbsp; Thank you so much!&amp;nbsp; Richard, if Alain's suggestion worked, should I try adding yours as well?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp; &lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Oct 2013 03:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312499#M222368</guid>
      <dc:creator>Joshua Smick</dc:creator>
      <dc:date>2013-10-12T03:33:22Z</dc:date>
    </item>
    <item>
      <title>Cannot connect to router via public IP address</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312500#M222369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Josh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad that the suggestion from Alain fixed your problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The standard access list that I suggest has the same effect as the extended access list that you were using, since your extended access list was checking only the source address and not the destination address. I still believe that a standard access list is better than an extended access list for your address translation (especially since your extended access list 101 was only checking the source address - and I have seen some situations where extended access lists with permit any destination caused some issues). But if your router is working fine with the extended access list then maybe it is good enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Oct 2013 16:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-connect-to-router-via-public-ip-address/m-p/2312500#M222369</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-10-12T16:44:50Z</dc:date>
    </item>
  </channel>
</rss>

