cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
883
Views
0
Helpful
9
Replies

Firewall on 892 Router

tsipoulanis
Level 1
Level 1

Hello everone,

can someone help troubleshooting my new 892 router?

based on a basic configurations i have the Status below,

from the router,

1. ping internal, a host

2. ping internet IP

3. ping website(name)as

from host,

1. ping internal IP from the router

2. ping my public IP

i dont see any website from a browser.

i have configured also zones. (from both directions)

any help is wellcome,

best regards,

thomas

1 Accepted Solution

Accepted Solutions

You only have "ip nat inside" configured on vlan1, but vlan1 is not a member of any zone.

You only need zone-member on layer 3 interfaces (interfaces with IP addresses).

View solution in original post

9 Replies 9

johnd2310
Level 8
Level 8

Hi,

Can you  ping a website or external device from internal host? Have you checked DNS for internal hosts.

Thanks

John

**Please rate posts you find helpful**

hi and thanks for the respond,

from a host I ping only my gateway(the cisco router) and my pyblic IP(which is the external WAN IP from my cisco router).
no ping website, no ping 8.8.8.8 ,no ping an other Internet IP

best regards,

thomas

Philip D'Ath
VIP Alumni
VIP Alumni

It could be a million things. You'll need to post your config.

You could also try my wizard for an 897 to get you 99% of a working configuration for an 892.

http://www.ifm.net.nz/cookbooks/890-isr-wizard.html

please see attachment,
I will try also the link you gave me to see if i succed with the tool

thanks for the respond,
Thom

You only have "ip nat inside" configured on vlan1, but vlan1 is not a member of any zone.

You only need zone-member on layer 3 interfaces (interfaces with IP addresses).

you make my day,
:) thank you.

how i forgot that ??? :)

best wishes,
TThomas

and now i can have no traffic between my networks from the vpn.
i see a zone on the tunnel,
then, i think i have to create a zone-pair. ;) right?

Thom

The short answer is - yes.

I am a little unclear if you are having an issue or not.  Is everything now working?

i have also something else to ask.
i have internet, the vpn is connected and
Router_A ping all the IPs from Router_B
Router_B ping all the IPs from Router_A
Host form A ping all the IPs from Router_B
Host from B ping all the IPs from Router_A

but is not possible to ping from Host_A to Host_B

it seems to be firewall issue.

Review Cisco Networking for a $25 gift card