04-02-2018 02:37 PM - edited 03-05-2019 10:12 AM
I have a cisco 800 series router and its connected to a subnet (10.2.1.XXX local network address) and is connected to the Internet.How can I configure the LAN interfaces(FE0 to FE3) to be able to connect to the internet?Now I'm able to assign a 192.168.X.X address to internal devices connected to router but it isn't connected to Internet!
.Here is the summary of the configurations I did,
interface Vlan1
ip address 192.168.1.1 255.255.255.0
ip dhcp excluded-address 192.168.1.1 192.168.1.30
ip dhcp pool mypool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1
dns-server 8.8.8.8
interface FastEthernet4
ip address dhcp
p nat outside
no shutdown
The router is picking the address 10.2.1.74(connected to internet) and a host device is having address 192.168.1.31 but it isn't connected to Internet.
Also I tried adding this,
ip nat inside source list 1 fastethernet4 overload
Please provide with a suggestion as I'm new to this!
Naveen
Solved! Go to Solution.
04-03-2018 02:23 PM
Hello,
here is the config you need (important parts in bold).
The ip dhcp excluded address had a type, make sure it is .168 and not .169.
version 15.5
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
enable secret 5 $1$vj0L$Vr9N06SezranvjdQ/gLK/1
!
no aaa new-model
ethernet lmi ce
!
ip dhcp excluded-address 192.168.1.1 192.168.1.30
!
ip dhcp pool my pool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1
dns-server 8.8.8.8 8.8.4.4
lease 3
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
license udi pid C881-K9 sn FJC2210L07Y
!
interface FastEthernet0
no ip address
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface FastEthernet4
ip address dhcp
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
!
interface Vlan1
ip address 192.168.1.1 255.255.255.0
ip nat inside
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
ip route 0.0.0.0 0.0.0.0 FastEthernet4 dhcp
!
ip nat inside source list 1 interface FastEthernet4 overload
!
access-list 1 permit 192.168.1.0
!
control-plane
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
line con 0
no modem enable
line aux 0
line vty 0 4
login
transport input none
!
scheduler allocate 20000 1000
!
end
04-03-2018 03:07 PM
Hello,
you mean your computers have IP addresses in the 10.2.x.x range ? Can you at least ping 8.8.8.8 from the router ?
Anything can be routed, but you need a layer 3 interface which is the default gateway for your clients. The network also needs to be added to the access list that is used for NAT, e.g.;
interface VLAN10
ip address 10.2.1.1 255.255.255.0
ip nat inside
access-list 1 permit 10.2.1.0 0.0.0.255
04-02-2018 04:42 PM
Can you post the output of "sh run"?
HTH
04-03-2018 02:03 PM
Building configuration...
Current configuration : 1477 bytes
!
! Last configuration change at 20:57:12 UTC Tue Apr 3 2018
!
version 15.5
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
enable secret 5 $1$vj0L$Vr9N06SezranvjdQ/gLK/1
!
no aaa new-model
ethernet lmi ce
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip dhcp excluded-address 192.169.1.1 192.169.1.30
!
ip dhcp pool my pool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1
dns-server 8.8.8.8
!
!
!
ip cef
no ipv6 cef
!
!
!
!
!
multilink bundle-name authenticated
!
!
!
!
!
!
!
license udi pid C881-K9 sn FJC2210L07Y
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0
no ip address
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface FastEthernet4
ip address dhcp
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
!
interface Vlan1
ip address 192.168.1.1 255.255.255.0
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
ip nat inside source list 1 interface FastEthernet4 overload
!
!
!
control-plane
!
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
!
!
!
line con 0
no modem enable
line aux 0
line vty 0 4
login
transport input none
!
scheduler allocate 20000 1000
!
end
04-02-2018 04:50 PM
Hi,
What device is connected to interface fa4?
Thanks
John
04-03-2018 01:17 PM
Fa4 is connected to the internet through a cable
04-03-2018 09:46 AM
I think you almost have everything done... Just some minor tweaks:
You must configure the NAT for the inside interfaces (Fe0 to Fe3)
interface fastethernet 0 ip nat inside interface fastethernet 1 ip nat inside interface fastethernet 2 ip nat inside interface fastethernet 3 ip nat inside
You define the NAT for the outside interface
interface fastethernet 4 ip nat outside
Use your nat definition:
ip nat pool NAME 10.2.1.74 10.2.1.74 prefix 24 <--- i think...
Indicate the translation:
ip nat inside source list 1 pool NAME overload access-list 1 permit 192.168.1.0 0.0.0.255
Also, i think you need a route to the outside... something like:
ip route 0.0.0.0 0.0.0.0 <IP OF THE INTERNET NEXT HOP>
ANd with that i think you can connect your endpoints to the internet.
04-03-2018 02:07 PM
Thanks for the reply followed your instructions and got
Router(config)#interface FastEthernet0
Router(config-if)#ip nat inside
^
% Invalid input detected at '^' marker.
04-03-2018 01:26 PM
Hello everyone,
thanks for the reply guys,
here 10.2.1.74 is the address assigned for FA4(WAN) USING DHCP.Just to be clear!
04-03-2018 01:32 PM
thanks for the reply guys,
here 10.2.1.74 is the address assigned for FA4(WAN) USING DHCP.Just to be clear!
and I want the other interfaces(FE0 to FE3) to have the same IP 10.2.X.X and connected to internet as well(like a switch)!
Is is possible?
04-03-2018 02:23 PM
Hello,
here is the config you need (important parts in bold).
The ip dhcp excluded address had a type, make sure it is .168 and not .169.
version 15.5
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
enable secret 5 $1$vj0L$Vr9N06SezranvjdQ/gLK/1
!
no aaa new-model
ethernet lmi ce
!
ip dhcp excluded-address 192.168.1.1 192.168.1.30
!
ip dhcp pool my pool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1
dns-server 8.8.8.8 8.8.4.4
lease 3
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
license udi pid C881-K9 sn FJC2210L07Y
!
interface FastEthernet0
no ip address
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface FastEthernet4
ip address dhcp
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
!
interface Vlan1
ip address 192.168.1.1 255.255.255.0
ip nat inside
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
ip route 0.0.0.0 0.0.0.0 FastEthernet4 dhcp
!
ip nat inside source list 1 interface FastEthernet4 overload
!
access-list 1 permit 192.168.1.0
!
control-plane
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
line con 0
no modem enable
line aux 0
line vty 0 4
login
transport input none
!
scheduler allocate 20000 1000
!
end
04-03-2018 02:55 PM
Thanks for the suggestion,
I followed the instructions but still devices connected to FE0-FE3 not connected to Internet.Is it because the router is connected to private network(10.2..x.x addresses) and its not possible to route? (asked in other forums)
N
04-03-2018 03:07 PM
Hello,
you mean your computers have IP addresses in the 10.2.x.x range ? Can you at least ping 8.8.8.8 from the router ?
Anything can be routed, but you need a layer 3 interface which is the default gateway for your clients. The network also needs to be added to the access list that is used for NAT, e.g.;
interface VLAN10
ip address 10.2.1.1 255.255.255.0
ip nat inside
access-list 1 permit 10.2.1.0 0.0.0.255
04-03-2018 03:21 PM
All devices connected to internet have 10.2.x.x address because its a private network.And i'm able to ping 8.8.8.8 on the router and its successful.But on the device connected to router through FE0 to FE3 not able to ping google.com.
yes 10.2.1.1 is the default gateway for the clients.
04-03-2018 04:02 PM
04-04-2018 07:56 AM
10.2.1.1 is the gateway already used Can I use the same for this router bacause
FE4 has IP address 10.2.1.74
and when I configure
interface Vlan1
ip address 10.2.1.1 255.255.255.0
I get IP address conflicts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide