cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
19312
Views
10
Helpful
6
Replies

Destination Host Unreachable issue in Packet Tracer

Sara94
Level 1
Level 1

I'm a student at a college and I keep getting issues in doing the ping and it always tell me that the destination host is unreachable. I would to get some help on what's wrong with the configuration. 

 

I used 255.255.255.0 for the mask, and for the hub I used 10.1.1.1 

 

Regards,

Sara 

1 Accepted Solution

Accepted Solutions

Sara good morning,

 

I have done a small review of your topology, you have some mistakes.

 

1. The PCs you have conected in switch S2 aren't in the 192.168.3.0/24 network, so they couldn't go out the network.

2. You have not defined the 101 ACL you match in your Crypto-map CMAP in any device.

3. I do not understand between which devices do you want to do the VPN, because I see it in all the routers. In the begining I belived that the VPN was between R1 and R3 trought the cloud. You have to define this better.

4. I need the ASA enable password to review it.

I will continue to review if I see anything else I will tell you. Please do not forget to rate useful answers this motivate us to participate at the community.

 

Best Regards,

View solution in original post

6 Replies 6

Diana Karolina Rojas
Cisco Employee
Cisco Employee

Hello Sara, 

 

How is your network? can you provide the lab to review the configuration?

 

Best Regards,

I'm supposed to do the PPP, VPN topology for two routers, firewall, and frame relay.

I did all of the above except the PPP, but the ping doesn't work at all. 

 

Here is my network in packet tracer

Download WAN Project

Sara good morning,

 

I have done a small review of your topology, you have some mistakes.

 

1. The PCs you have conected in switch S2 aren't in the 192.168.3.0/24 network, so they couldn't go out the network.

2. You have not defined the 101 ACL you match in your Crypto-map CMAP in any device.

3. I do not understand between which devices do you want to do the VPN, because I see it in all the routers. In the begining I belived that the VPN was between R1 and R3 trought the cloud. You have to define this better.

4. I need the ASA enable password to review it.

I will continue to review if I see anything else I will tell you. Please do not forget to rate useful answers this motivate us to participate at the community.

 

Best Regards,

Thank you Diana,

 

I did the whole configuration once again and solved most of the errors that you have mentioned. Before doing the PPP ping between three routers worked well but after doing the PPP it doesn't work on R1 and R3
- I have defined the 101 ACL in Crypto-map CMAP in Router 1 & Router 3.

Isues:
- Everything else worked, but the ping in firewall didn't work.
- For ASA firewall, I didn't add a password, so just click enter.
- When I do the PPP with PAP it change the state to down and then it doesn't turn back to up, so the ping doesn't work with router 1 and router 3 because of the PPP
- For VPN I thought that it most be one the whole network that's why I did it in all routers, However do you have anyway on how can I delete the VPN configuration on one of these routers?

 

Edited WAN Project: https://ufile.io/2449q

 

Regards,

Good afternoon Sara!

 

I really think you have to do a review about where (in the network) you want to prove the tecnologies you are using, for example, in R3 you have the VPN and you are matching all your traffic to go trough the VPN, at the same way you have PPP and FR, when you do a "show ip arp" the router does not know the mac/ip address relation and also does not know any route to the others networks (show ip route). The ASA does not have the necessary rules to premit the traffic from the untrusted interfaces (outside and DMZ) to go to a trusted interface (inside) you have to create it. And also the ping in the PPP doesn't arrive beacuse the routers do not even see each other connected. To delete a VPN you have to delete the crypto map, transforms-set, crypto policy, keys, all the things related to this.

 

----Do not forget to rate useful post.---

 

Regards,

Hi Diana, 

 

Thank you for the fast replay.

I'm a beginner in packet tracer so there are a lot of things that I just follow the laps that I have, However is there a way to make the ping in PPP work? an how can I make the router see each other I'm really not in where the problem is.

How can I make the ASA go to the trusted interface (inside)?

 

Thanks a lot Diana,

Regards,

 

Review Cisco Networking products for a $25 gift card