cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1133
Views
5
Helpful
7
Replies

Verizon Residential FIOS ONT - L2/L3 Switch - Dynamic PAT

HelpMePleaze
Level 1
Level 1

I have Internet only Verizon Residential FIOS. The Ethernet port is the active port (instead of the coaxial) on my Verizon Optical Network Terminal (ONT) box because I do not have TV service that uses coaxial connection. 

 

I am trying to interconnect the ONT box's ethernet port and interface GigabitEthernet1/0/1 on my Cisco L2/L3 switch. The Verizon ONT box hands out a single public IP address using DHCP. My goal is to make dynamic PAT to work so that client computers on the inside private IP addressing subnets 192.168.0.0/24 and 172.16.0.0/24 are translated to the single public IP address.

 

Please take a look at my switch configuration (attached) to see what I am missing. Not sure if I am missing a default route or static routes.

 

Any suggestions are welcomed, thank you very much!

1 Accepted Solution

Accepted Solutions

Hi Richard, 

 

This is a 3750 switch running IP Service license. I was not able to make the

ip nat 

working, that's why I am posting this to seek assistance. From the switch, I am able to ping 8.8.8.8 sourcing interface vlan 172 and I see the translation happening

 (show ip nat translation) 

for the interface vlan 172 when I do that. However, the client PC is not able to ping 8.8.8.8 and I don't see any translation occurring.

 

my current setup:

ONT <<>> switch <<>> Client PC

 

Do I need to change the setup to

 ONT <<>> router <<>> switch <<>> Client PC?

 

View solution in original post

7 Replies 7

Hello
Your configuration looks okay for PAT , Would suggest as this rtr is internet facing that you also hardened down the rtr possible with ZBFW or at least CBAC  


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

I would like to know what device this is. The original post describes it as L2/L3 switch. In general Cisco switches do not support nat. But the config does contain

 nat 

commands. Can you check and see if

 nat 

is really working?

HTH

Rick

Hi Richard, 

 

This is a 3750 switch running IP Service license. I was not able to make the

ip nat 

working, that's why I am posting this to seek assistance. From the switch, I am able to ping 8.8.8.8 sourcing interface vlan 172 and I see the translation happening

 (show ip nat translation) 

for the interface vlan 172 when I do that. However, the client PC is not able to ping 8.8.8.8 and I don't see any translation occurring.

 

my current setup:

ONT <<>> switch <<>> Client PC

 

Do I need to change the setup to

 ONT <<>> router <<>> switch <<>> Client PC?

 

Thanks Paul for the suggestion. I am currently only using a L2/L3 switch. I may need to acquire a router to enable ZBFW.

Hello,

 

what was connected to the ONT box before, a Verizon router ? Is your GigabitEthernet1/0/1 interface actually acquiring a valid DHCP IP address ?

George, yes the interface GigabitEthernet1/0/1 does acquire a valid public DHCP IP address

Hello


@HelpMePleaze wrote:

my current setup:

ONT <<>> switch <<>> Client PC



Do I need to change the setup to

 ONT <<>> router <<>> switch <<>> Client PC?

 


Yes - As

 Nat 

isn't supported on 3750 switches so you would require a router in-between the ONT and the 3750 just like you have shown above

 

 


@HelpMePleaze wrote:

 
From the switch, I am able to ping 8.8.8.8 sourcing interface vlan 172 and I see the translation happening

(show ip nat translation) 

for the interface vlan 172 when I do that


I assume this is after you've introduced the rtr  in-between the ONT and the switch, or are you getting the nat table off the ONT device?


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul
Review Cisco Networking products for a $25 gift card