07-07-2020 05:54 AM
I have an Vlan internet configuration done on cisco router but the internet is not wokring
interface 0/0 is configured with x.x.x.x IP
nat inside
interface 0/1.VLANid configured with WAN IP
encapsulation
nat outside
default gateway defined
source list 1 wan oveloaaded
surce list 100 overloadded
ip route any to wan gateway
ip lan to interface0/0
access list 1
access list 23
access list 100
Is ther any command that I am missing need assistance
07-07-2020 05:58 AM
Hello @ishaq ,
do you have the following?
ip nat inside source list 1 <wan> overload
and have you defined acl 1 ?
access-list 1 permit 10.10.10.0 0.0.0.255
Hope to help
Giuseppe
07-09-2020 01:01 AM
Here is the configuration
interface GigabitEthernet0/0
ip address 20.20.20.2 255.255.255.0
ip nat inside
interface GigabitEthernet0/1.7201
encapsulation dot1Q 7201
ip address 46.172.25.11 255.255.255.248
ip nat outside
shutdown ** here i see something shutdown, i have noticed that I am unable to link up this interface.
ip default-gateway 46.172.25.10
ip nat inside source list 1 interface GigabitEthernet0/1.7201 overload
ip nat inside source list 100 interface GigabitEthernet0/1.7201 overload
ip route 0.0.0.0 0.0.0.0 46.172.25.10
ip route 192.168.3.0 255.255.255.0 20.20.20.1
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 23 permit 192.168.3.0 0.0.0.255
access-list 100 permit ip 20.20.20.0 0.0.0.255 any
07-09-2020 01:13 AM
Hello,
interface GigabitEthernet0/1.7201
encapsulation dot1Q 7201
ip address 46.172.25.11 255.255.255.248
ip nat outside
Router#conf t
Router(config)#interface GigabitEthernet0/1
Router(config-if)#no shut
You need to 'no shut' the main interface, GigabitEthernet0/1, in order for the subinterface to come up. That said, who is your ISP, what country are you in ?
07-09-2020 01:41 AM
The interface is up now, however there is no internet.
I want to check is there any command missing in the configuration that i posted
07-09-2020 01:19 AM
Hello @ishaq ,
the Vlan-id is a value between 1 and 4094 you have probably modified your configuration before posting.
If there is an interface or subinterface with command shutdown that interface or subinterface will not work, because it is disabled.
You need to remove it using
no shut
at interface or sub-interface level.
The internal network should be private like RFC 1918 , subnet 20.20.20.0/24 is already a public IP subnet so I think you have modified it.
Hope to help
Giuseppe
07-09-2020 01:40 AM
Yes I have modified and it is a private IP.
The interface is up now, however there is not internet.
I want to check is there any command missing in the configuration that i posted
07-09-2020 01:49 AM
Hello,
it is hard to tell what you have configured. Post the output of 'show run'.
07-09-2020 02:08 AM
below is the configuration
ip virtual-reassembly in
duplex auto
speed auto
!
interface GigabitEthernet0/1
no ip address
duplex auto
speed auto
!
interface GigabitEthernet0/1.200
encapsulation dot1Q 00
ip address 49.75.120.11 255.255.255.248
ip nat outside
ip virtual-reassembly in
!
!
ip default-gateway 49.75.120.10
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/1.200 overload
ip nat inside source list 100 interface GigabitEthernet0/1.200 overload
ip nat inside source list 101 interface GigabitEthernet0/1.200 overload
ip route 0.0.0.0 0.0.0.0 49.75.120.10
ip route 192.168.3.0 255.255.255.0 11.11.11.1
!
logging esm config
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 23 permit 192.168.3.0 0.0.0.255
access-list 100 permit ip 11.11.11.0 0.0.0.255 any
access-list 101 permit ip 11.11.11.0 0.0.0.255 any
07-09-2020 02:25 AM
Hello,
simply post the full output of 'show run' without any modifications. It is impossible to figure out what you modify in the snippets you post...
interface GigabitEthernet0/1.200
encapsulation dot1Q 00 <-- is this a typo ?
ip address 49.75.120.11 255.255.255.248
ip nat outside
ip virtual-reassembly in
07-07-2020 06:04 AM - edited 07-07-2020 06:05 AM
well,
maybe there are some configuration miss in your device.
See tips about:
ip nat inside sourcer xx wan overload
ip route 0.0.0.0.0 0.0.0.0.0 x.x.x.x
ip access-list xx permite 192.168.0.0 0.0.0.255
If possible, share your full configuration to we provide a correct solution to you
07-07-2020 06:33 AM - edited 07-07-2020 06:51 AM
interface 1
ip address 1.1.1.2 255.255.255.0
ip nat inside
interface 2
encapsulation vlanid
ip address 2.2.2.2 255.255.255.0
ip nat outside
ip default-gateway 3.3.3.3
ip nat inside source list 1 interface 2 overload
ip nat inside source list 100 interface 2 overload
ip route 0.0.0.0 0.0.0.0 2.2.2.3
ip route 4.4.4.4 255.255.255.0 1.1.1.1
access-list 1 permit 4.4.4.4 0.0.0.255
access-list 23 permit 4.4.4.4 0.0.0.255
access-list 100 permit ip 1.1.1.0 0.0.0.255 any
07-07-2020 06:42 AM
Hello,
post your full running configuration (show run)...
interface 0/1.VLANid configured with WAN IP
encapsulation
nat outside
If you have a subinterface configured, that (not the main interface) is where all your NAT and routing needs to go to.
07-07-2020 09:59 AM
Hello
When you say internet isn’t working - can you elaborate please?
You cannot access the internet from the router or just from the lan users or both?
Is this a recent issue or are you trying to establish new connection?
Can you post the running configuration and route table of the rtr please (in a attached file)?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide