<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1 in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750289#M305039</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;try and manually create Vlan 4094:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISR1100(config)#vlan 4094&lt;/P&gt;</description>
    <pubDate>Tue, 20 Nov 2018 21:00:56 GMT</pubDate>
    <dc:creator>Georg Pauwen</dc:creator>
    <dc:date>2018-11-20T21:00:56Z</dc:date>
    <item>
      <title>Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750157#M305016</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using an ISR1100 Router on a Leased Line. I'm having an issue where devices "Lan" side can communicate out to the internet via a default static route. The issue i'm experiencing is that inbound traffic to a VPN server is not getting any further than the Cisco router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following&lt;/P&gt;
&lt;P&gt;&lt;U&gt;WAN&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Sub-interface 0/0/1.4094&lt;/P&gt;
&lt;P&gt;Encapsulation dot1q 4094 (ISP use this VLAN)&lt;/P&gt;
&lt;P&gt;IP xxx.xxx.xxx.133&lt;/P&gt;
&lt;P&gt;IP route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.132&lt;/P&gt;
&lt;P&gt;Internet access works&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;LAN&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;vlan1&lt;/P&gt;
&lt;P&gt;IP Address: xxx.xxx.xxx.129&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a device connected to Physical Interface 0/1/0 with the following Public Static IP: xxx.xxx.xxx.130&lt;/P&gt;
&lt;P&gt;I'm unable to communicate with this device from the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the cisco console i can ping xxx.xxx.xxx.130&lt;/P&gt;
&lt;P&gt;From the device itself i can ping xxx.xxx.xxx.129 and xxx.xxx.xxx.133 and internet address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help with what is going on here would be greatly appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've reset the router and have gone back to basics, the config is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0/0&lt;BR /&gt; no ip address&lt;BR /&gt; shutdown&lt;BR /&gt; negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0/1&lt;BR /&gt; no ip address&lt;BR /&gt; negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0/1.4094&lt;BR /&gt; encapsulation dot1Q 4094&lt;BR /&gt; ip address xx.xxx.xxx.133 xxx.xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/1&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/2&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/3&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; ip address xxx.xxx.xxx.129 xxx.xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.132&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All port are a member of vlan1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You in advanced&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 17:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750157#M305016</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T17:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750203#M305017</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I dn't see any NAT on your router, not sure if you have omitted that on purpose. Either way, make sure the lines marked in bold are added to your config:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0/0&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0/1&lt;BR /&gt;no ip address&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0/1.4094&lt;BR /&gt;encapsulation dot1Q 4094&lt;BR /&gt;ip address xx.xxx.xxx.133 xxx.xxx.xxx.xxx&lt;BR /&gt;&lt;STRONG&gt;ip nat outside&lt;/STRONG&gt;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/1&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/2&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1/3&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;ip address xxx.xxx.xxx.129 xxx.xxx.xxx.xxx&lt;BR /&gt;&lt;STRONG&gt;ip nat inside&lt;/STRONG&gt;&lt;BR /&gt;!&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.132&lt;BR /&gt;!&lt;BR /&gt;&lt;STRONG&gt;ip nat inside source list 1 interface GigabitEthernet0/0/1.4094 overload&lt;/STRONG&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;STRONG&gt;access-list 1 permit xxx.xxx.xxx.xxx yyyy.yyyy.yyy.yyy --&amp;gt; the access list needs to specify the IP address space of Vlan1&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 18:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750203#M305017</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T18:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750215#M305018</link>
      <description>&lt;P&gt;Thanks for the reply i will try this. I was under the impression that this was a no nat setup as the server behind the router will be assigned 1 of our public IP address directly, therefore i thought that no actual translation was needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 18:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750215#M305018</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T18:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750216#M305019</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you don't need any NAT if all of your addresses are public IP addresses. Can you indicate if that is the case, that is, all VLAN 1 IP addresses are public ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 18:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750216#M305019</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T18:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750222#M305021</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes all vlan1 IP addresses are public, that's correct.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 18:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750222#M305021</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T18:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750225#M305022</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so the VPN server has a public IP address from the same subnet as Vlan 1 ? Can you ping e.g. 8.8.8.8 from the VPN server ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 18:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750225#M305022</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T18:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750229#M305024</link>
      <description>&lt;P&gt;IP on vlan1 is aaa.bbb.ccc.129&lt;/P&gt;
&lt;P&gt;IP on VPN Server is aaa.bbb.ccc.130 with GW: aaa.bbb.ccc.129&lt;/P&gt;
&lt;P&gt;The vpn server can ping 8.8.8.8 okay. It just seems to be inbound doesn't get passed from the WAN to aaa.bbb.ccc.130.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can even ping aaa.bbb.ccc.129 from any internet device but not able to ping aaa.bbb.ccc.130. If im on the cisco console i can ping aaa.bbb.ccc.130 so the device does respond to ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 19:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750229#M305024</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T19:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750235#M305026</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;post the output of 'show ip route'...&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 19:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750235#M305026</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T19:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750238#M305027</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;S* 0.0.0.0/0 [1/0] via 87.xxx.xxx.132&lt;BR /&gt; 83.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;BR /&gt;C 83.xxx.xxx128/29 is directly connected, Vlan1&lt;BR /&gt;L 83.xxx.xxx.129/32 is directly connected, Vlan1&lt;BR /&gt; 87.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;BR /&gt;C 87.xxx.xxx.132/31 is directly connected, GigabitEthernet0/0/1.4094&lt;BR /&gt;L 87.xxx.xxx.133/32 is directly connected, GigabitEthernet0/0/1.4094&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 19:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750238#M305027</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T19:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750264#M305033</link>
      <description>&lt;P&gt;When running a traceroute i can see that the traffic hits the WAN Subinterface aaa.bbb.ccc.133 but then times out at this point. Not sure if this information is helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 20:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750264#M305033</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T20:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750276#M305035</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the output of 'show vlan' ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try and add the 'native' keyword to your ISP interface config:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;encapsulation dot1Q 4094 &lt;STRONG&gt;native&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 20:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750276#M305035</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T20:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750281#M305037</link>
      <description>&lt;P&gt;Hi When adding Native to the encapsulation I can no longer communicate out to the internet. Heres the show vlan VLAN Name Status Ports&lt;/P&gt;
&lt;P&gt;1 default active Gi0/1/0, Gi0/1/1, Gi0/1/2 Gi0/1/3&lt;/P&gt;
&lt;P&gt;1002 fddi-default act/unsup&lt;/P&gt;
&lt;P&gt;1003 token-ring-default act/unsup&lt;/P&gt;
&lt;P&gt;1004 fddinet-default act/unsup&lt;/P&gt;
&lt;P&gt;1005 trnet-default act/unsup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2&lt;/P&gt;
&lt;P&gt;1 enet 100001 1500 - - - - - 0 0&lt;/P&gt;
&lt;P&gt;1002 fddi 101002 1500 - - - - - 0 0&lt;/P&gt;
&lt;P&gt;1003 tr 101003 1500 - - - - - 0 0&lt;/P&gt;
&lt;P&gt;1004 fdnet 101004 1500 - - - ieee - 0 0&lt;/P&gt;
&lt;P&gt;1005 trnet 101005 1500 - - - ibm - 0 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Primary Secondary Type Ports&lt;/P&gt;
&lt;P&gt;------- --------- ----------------- ------------------------------------------&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 20:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750281#M305037</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T20:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750289#M305039</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;try and manually create Vlan 4094:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISR1100(config)#vlan 4094&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 21:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750289#M305039</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T21:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750292#M305040</link>
      <description>&lt;P&gt;I've manually created, no difference unfortunately.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 21:13:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750292#M305040</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T21:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750296#M305041</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you ping any of the other devices on Vlan 1 ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 21:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750296#M305041</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T21:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750301#M305043</link>
      <description>&lt;P&gt;Unfortunately i only have the one device connect currently.&amp;nbsp; I wanting to get this working before migrating the other devices.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 21:23:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750301#M305043</guid>
      <dc:creator>shawntaylor17</dc:creator>
      <dc:date>2018-11-20T21:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750336#M305049</link>
      <description>&lt;P&gt;This is a very interesting problem. If I am understanding correctly your device can ping addresses in the Internet successfully. This would seem to eliminate routing issues as the source of the problem. You have told us that&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I can even ping aaa.bbb.ccc.129 from any internet device but not able to ping aaa.bbb.ccc.130.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;So the Internet routing is correct to reach your subnet from outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If traffic initiated from inside to outside is successful but traffic initiated from outside to inside fails then I can think of a couple possible causes: 1) something is doing stateful inspection allowing inside traffic out and accepting response traffic but denying traffic outside to inside. 2) some type of entry is created as traffic goes out and allows response traffic, but it times out and does not allow traffic outside to inside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) if traffic from Internet is able to access the router interface address then it seems that it is not a stateful inspection issue. So we are looking at table entries that time out. Probably the more obvious choice might be the arp table on the router. Can you post the output of show arp (or perhaps show ip arp)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also wonder if you turn on debug for arp and let it run a bit what output might tell us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It also occurs to me that it would be interesting to do a test where you coordinate between a device in the Internet and the router/server. Have the server ping the device in the Internet (we assume this would be successful) and immediately have the Internet device attempt to access the server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 22:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750336#M305049</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2018-11-20T22:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot route between WAN Subinterface with dot1q  and Public IPs on Vlan1</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750346#M305050</link>
      <description>&lt;P&gt;What do you have as VPN server ? A Windows machine ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 23:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/cannot-route-between-wan-subinterface-with-dot1q-and-public-ips/m-p/3750346#M305050</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2018-11-20T23:13:19Z</dc:date>
    </item>
  </channel>
</rss>

