06-27-2013 06:39 AM - edited 03-04-2019 08:19 PM
Hello i have a new 861 router no wireless or anything and i am having trouble gettting it to work. i put the IP address on the Fastethernet 4 and the inside ip address on the VLAN1 i can ping out from the router both ways to the gateway and back to the local machine but i can not get out to the internet from the local machines.the DHCP works just cant get to the internet
below is a copy of current config any help would be great.
!
hostname 861router
!
boot-start-marker
boot-end-marker
!
no aaa new-model
memory-size iomem 10
crypto pki token default removal timeout 0
!
crypto pki trustpoint TP-self-signed-3456406442
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3456406442
revocation-check none
rsakeypair TP-self-signed-3456406442
!
crypto pki certificate chain TP-self-signed-3456406442
certificate self-signed 01
3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33343536 34303634 3432301E 170D3036 30313032 31323231
34315A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 34353634
30363434 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100D7A9 53C08EAE 1558F10B AE84A678 A0C98D33 AB41472B 9D4248DA 0675896C
E7CF40E4 E634905F 17F0E3F2 A35013BC 93204847 3AF54F16 44321BC8 72DFAEE5
0DE1D6FD D5BC7190 A973E790 8982ED1C 29E5ADDC 8EC06918 6375A32E D2274953
21286478 9FE65AF0 A0E6FE38 8953F3B5 7BA52054 F92FF817 662197F8 5744A8C8
30090203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603
551D2304 18301680 1483DEC0 6CEEAF08 85AB21E1 E00C85F2 F438E12A EA301D06
03551D0E 04160414 83DEC06C EEAF0885 AB21E1E0 0C85F2F4 38E12AEA 300D0609
2A864886 F70D0101 05050003 8181005E 4DEEDF37 6D619DAD 6A91E463 AB1B7EE7
8340BB76 2FC84662 B9DCE3F1 5F3FADB0 D83AE457 9392C3EC 4FD15173 487D54F8
F9F4286D C56820FB 0AF9DEB2 AA6FDC56 19F181A2 82CA2D07 2AE15644 2C224F4F
9FC2E1CF F396724D A5003947 306921F9 A38B7CC4 B72B94AA D9C76774 B4FCC4D7
CB65C7D6 B833F6F7 BD879AA6 94A8F3
quit
ip source-route
!
!
ip dhcp excluded-address 192.168.4.1 192.168.4.10
ip dhcp excluded-address 192.168.4.200 192.168.4.250
!
ip dhcp pool PPool
import all
network 192.168.4.0 255.255.255.0
default-router 192.168.4.1
dns-server 10.5.60.2
domain-name domain
lease 0 2
!
!
!
ip cef
no ip domain lookup
!
!
license udi pid CISCO861-K9 sn FGL1708240F
!
!
username admin privilege 15 secret 4 password
!
interface FastEthernet0
no ip address
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface FastEthernet4
description outside wan
ip address 10.5.35.1 255.255.0.0
duplex auto
speed auto
!
interface Vlan1
ip address 192.168.4.1 255.255.255.0
ip nat enable
ip virtual-reassembly out
!
ip forward-protocol nd
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip route 0.0.0.0 0.0.0.0 10.5.10.1
ip route 192.168.4.0 255.255.255.0 10.5.10.1
!
access-list 4 permit any
access-list 23 permit 192.168.4.0 0.0.0.255
access-list 110 permit ip any any
no cdp run
!
line con 0
login local
line aux 0
line vty 0 4
access-class 23 in
privilege level 15
login local
transport input telnet ssh
!
end
!
hostname 861router
!
boot-start-marker
boot-end-marker
!
no aaa new-model
memory-size iomem 10
crypto pki token default removal timeout 0
!
crypto pki trustpoint TP-self-signed-3456406442
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3456406442
revocation-check none
rsakeypair TP-self-signed-3456406442
!
!
crypto pki certificate chain TP-self-signed-3456406442
certificate self-signed 01
3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33343536 34303634 3432301E 170D3036 30313032 31323231
34315A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 34353634
30363434 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100D7A9 53C08EAE 1558F10B AE84A678 A0C98D33 AB41472B 9D4248DA 0675896C
E7CF40E4 E634905F 17F0E3F2 A35013BC 93204847 3AF54F16 44321BC8 72DFAEE5
0DE1D6FD D5BC7190 A973E790 8982ED1C 29E5ADDC 8EC06918 6375A32E D2274953
21286478 9FE65AF0 A0E6FE38 8953F3B5 7BA52054 F92FF817 662197F8 5744A8C8
30090203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603
551D2304 18301680 1483DEC0 6CEEAF08 85AB21E1 E00C85F2 F438E12A EA301D06
03551D0E 04160414 83DEC06C EEAF0885 AB21E1E0 0C85F2F4 38E12AEA 300D0609
2A864886 F70D0101 05050003 8181005E 4DEEDF37 6D619DAD 6A91E463 AB1B7EE7
8340BB76 2FC84662 B9DCE3F1 5F3FADB0 D83AE457 9392C3EC 4FD15173 487D54F8
F9F4286D C56820FB 0AF9DEB2 AA6FDC56 19F181A2 82CA2D07 2AE15644 2C224F4F
9FC2E1CF F396724D A5003947 306921F9 A38B7CC4 B72B94AA D9C76774 B4FCC4D7
CB65C7D6 B833F6F7 BD879AA6 94A8F3
quit
ip source-route
!
!
ip dhcp excluded-address 192.168.4.1 192.168.4.10
ip dhcp excluded-address 192.168.4.200 192.168.4.250
!
ip dhcp pool PPool
import all
network 192.168.4.0 255.255.255.0
default-router 192.168.4.1
dns-server 10.5.60.2
domain-name domain
lease 0 2
!
ip cef
no ip domain lookup
!
license udi pid CISCO861-K9 sn FGL1708240F
!
!
username admin privilege 15 secret 4 password
!
interface FastEthernet0
no ip address
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface FastEthernet4
description outside wan
ip address 10.5.35.1 255.255.0.0
duplex auto
speed auto
!
interface Vlan1
ip address 192.168.4.1 255.255.255.0
ip nat enable
ip virtual-reassembly out
!
ip forward-protocol nd
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip route 0.0.0.0 0.0.0.0 10.5.10.1
ip route 192.168.4.0 255.255.255.0 10.5.10.1
!
access-list 4 permit any
access-list 23 permit 192.168.4.0 0.0.0.255
access-list 110 permit ip any any
no cdp run
!
line con 0
login local
line aux 0
line vty 0 4
access-class 23 in
privilege level 15
login local
transport input telnet ssh
!
end
Solved! Go to Solution.
06-27-2013 08:53 AM
As mentioned you need to configure NAT properly.
Something like:
interface fa0/4
ip nat outside
interface vlan1
ip nat inside
ip nat inside source list 4 interface fa0/4 overload
And remove this line - you don't need it:
ip route 192.168.4.0 255.255.255.0 10.5.10.1
I am curious as to what else you have upstream of this router - you are natting from one private range to another so there will need to be something further upstream that can NAT this traffic to a routable address.
06-27-2013 07:21 AM
You need to configure nat properly. You can search documention or the forum on the subject.
06-27-2013 08:53 AM
As mentioned you need to configure NAT properly.
Something like:
interface fa0/4
ip nat outside
interface vlan1
ip nat inside
ip nat inside source list 4 interface fa0/4 overload
And remove this line - you don't need it:
ip route 192.168.4.0 255.255.255.0 10.5.10.1
I am curious as to what else you have upstream of this router - you are natting from one private range to another so there will need to be something further upstream that can NAT this traffic to a routable address.
06-27-2013 09:05 AM
Hey thanks for the info that worked greate, right now it is just on local network but i will be changing the addresses on it and moving it to another site.
Thanks so much
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide