04-22-2021 10:50 PM - edited 04-23-2021 02:16 PM
Hello Cisco Community, I'm hoping you can assist me...
Don't know what happen, buy my post disappeared.
I have a IR 829 router that can ping the internet
GLE-CE-02#ping 8.8.8.8 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 32/34/40 ms
However when I connect any clients to the onboard lan ports they are not able to browser the internet.
I'm pretty sure I'm missing something just can't put my finger on it, any help would be greatly appreaciated.
Here is my config
GLE-CE-02#sh conf Using 6034 out of 262144 bytes ! ! Last configuration change at 15:35:41 AEST Fri Apr 23 2021 by lcladm ! NVRAM config last updated at 15:38:47 AEST Fri Apr 23 2021 by lcladm ! version 15.8 service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption service linenumber service sequence-numbers ! hostname GLE-CE-02 ! boot-start-marker boot system flash:/ir800-universalk9-mz.SPA.158-3.M6 boot-end-marker ! ! security authentication failure rate 3 log security passwords min-length 6 logging userinfo logging buffered 51200 informational logging rate-limit all 10000 logging console informational enable secret 5 <removed> ! no aaa new-model ethernet lmi global clock timezone AEST 10 0 clock summer-time AEST recurring 1 Sun Oct 2:00 1 Sun Apr 2:00 service-module wlan-ap 0 bootimage autonomous ! ignition off-timer 900 ! ignition undervoltage threshold 11 000 ! no ignition enable errdisable recovery cause udld errdisable recovery cause bpduguard errdisable recovery cause rootguard errdisable recovery cause pagp-flap errdisable recovery cause dtp-flap errdisable recovery cause link-flap ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ip dhcp excluded-address 10.250.3.20 10.250.3.254 ! ip dhcp pool GuestOS import all network 10.250.3.0 255.255.255.0 default-router 10.250.3.1 dns-server 8.8.8.8 4.4.4.4 ! ! ! ip domain list <removed> ip domain list <removed> no ip domain lookup ip domain name <removed> ip name-server 10.2.0.100 ip name-server 10.2.0.20 ip cef no ipv6 cef ! multilink bundle-name authenticated ! ! ! chat-script lte "" "AT!CALL" TIMEOUT 20 "OK" ! ! license udi pid IR829GW-LTE-GA-ZK9 sn <removed> no crashinfo-deletion enable ! ! username lcladm secret 5 <removed> ! redundancy ! ! ! ! ! controller Cellular 0 lte sim data-profile 1 attach-profile 1 slot 0 lte sim fast-switchover enable lte failovertimer 5 lte modem link-recovery disable ! ! ! ! ! ! ! ! ! ! ! interface GigabitEthernet0 no ip address ! interface GigabitEthernet1 no ip address duplex full speed 1000 ! interface GigabitEthernet2 no ip address ! interface GigabitEthernet3 no ip address ! interface GigabitEthernet4 no ip address ! interface Wlan-GigabitEthernet0 no ip address ! interface GigabitEthernet5 no ip address shutdown duplex auto speed auto ! interface Cellular0 ip address negotiated no ip redirects no ip unreachables no ip proxy-arp ip nat outside ip virtual-reassembly in encapsulation slip load-interval 60 dialer in-band dialer idle-timeout 0 dialer string lte dialer-group 1 ipv6 address autoconfig async mode interactive routing dynamic ! interface Cellular1 ip address negotiated no ip redirects no ip unreachables no ip proxy-arp encapsulation slip load-interval 60 dialer in-band dialer idle-timeout 0 dialer string lte dialer-group 1 ipv6 address autoconfig async mode interactive routing dynamic ! interface wlan-ap0 no ip address ! interface Vlan1 ip address 10.250.3.1 255.255.255.0 ip nat inside ip virtual-reassembly in ! interface Async0 no ip address encapsulation scada ! interface Async1 no ip address encapsulation scada ! ! ip forward-protocol nd ! no ip http server no ip http secure-server ! ip ftp source-interface Vlan1 ip tftp source-interface Vlan1 ip nat inside source list 1 interface Cellular0 overload ip route 0.0.0.0 0.0.0.0 Cellular0 ip tacacs source-interface Vlan1 ip ssh version 2 ! ip radius source-interface Vlan1 logging source-interface Vlan1 dialer-list 1 protocol ipv6 permit dialer-list 1 protocol ip permit ipv6 ioam timestamp ! ! snmp-server community <removed> RO snmp-server community <removed> RW snmp-server ifindex persist snmp-server location <removed> snmp-server contact <removed> snmp-server enable traps wpan tacacs-server directed-request access-list 1 permit 10.250.3.0 0.0.0.255 ! control-plane ! ! ! line con 0 session-timeout 60 exec-timeout 60 0 privilege level 15 password 7 <removed> logging synchronous login local transport output telnet stopbits 1 line 1 2 stopbits 1 line 3 script dialer lte no exec transport preferred none transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh rxspeed 100000000 txspeed 50000000 line 4 no activation-character no exec transport preferred none transport input all transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh line 8 no exec transport preferred none transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh rxspeed 100000000 txspeed 50000000 line 1/3 1/6 transport preferred none transport output none stopbits 1 line vty 0 4 exec-timeout 60 0 password 7 <removed> logging synchronous login local transport input telnet ssh transport output telnet ssh line vty 5 797 exec-timeout 60 0 password 7 <removed> logging synchronous login local transport input telnet ssh transport output telnet ssh ! no scheduler max-task-time ntp logging ntp update-calendar ntp server 127.0.0.1 no iox hdm-enable iox client enable interface GigabitEthernet5 no iox recovery-enable ! ! ! ! ! ! ! end
Solved! Go to Solution.
04-23-2021 12:13 AM
Add inside and test it.
ip nat inside source list 1 interface Cellular0 overload
04-23-2021 12:13 AM
Add inside and test it.
ip nat inside source list 1 interface Cellular0 overload
04-23-2021 01:43 AM
Hi BB thank you for your reply, I added the inside to the NAT statement and tested it, still no go.
I have updated my config in the original post to reflect its new state
I can't ping any addresses from the vlan interface see below
GLE-CE-02#ping ip 8.8.8.8 source 10.250.3.1 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds: Packet sent with a source address of 10.250.3.1 ..... Success rate is 0 percent (0/5) GLE-CE-02# GLE-CE-02# GLE-CE-02#ping 8.8.8.8 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 30/68/196 m
04-23-2021 04:32 AM
can you post :
show ip interface brief ( i belive your VLAN 1 is down)
show ip route
(i would advise to connect any device to Gi interface, allocate interface to vlan 1( or default should be VLAN)
Like Device should get IP address from DHCP and should be able to work ?
04-23-2021 04:05 PM
Hey BB, Apologies for the delay in my response, for some reason my post got marked as spam....
Thank you for your reply yes you were right my vlan 1 line protocol was down... couldn't work out why even though i had 2 devices plugged into the lan ports.. I deleted my vlan.dat file and on a whim i erased my config rebooted and then reapplied it and everything is working..
04-24-2021 12:57 AM
Glad to know the solution works as expected. happy to hear.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide