04-22-2015 10:55 AM - edited 03-07-2019 11:41 PM
Hello,
I am attaching a very simple network map to this post to illustrate what I am trying to accomplish. I recently acquired a Cisco 2911 router. We have a 192.168.1.x/24 network, but we have run out of IP's. We are also moving to a new suite, and I figured I could run a fiber line between the suites, connect a switch to give both suites connectivity to the same network. Furthermore, I can create a /22 network and migrate servers/machines to new network at my leisure with near zero down time. I seem to have hit a brick wall. I factory defaulted the 2911 config. Next I set a username and password for router and enabled telnet. Next, I gave interface gi0/0 ip address 192.168.1.176. This should now join the router to the current network. I gave interface gi0/1 ip address 192.168.100.1 255.255.252.0 which should open the inside interface to the 100.x network which it did. I ran into an issue browsing the internet etc due to no NAT, so I nat'ed everything through the gi0/0 interface, and I can remote desktop from my 192.168.1.112 machine to the 192.168.100.100 server, can ping it fine etc. However through the 192.168.100.100 server I can't ping out to 8.8.8.8 from anywhere. When I'm consoled into the router I can ping everything everywhere fine from the router.
Could someone please take a look at my ip route statement and my config and guide me where I'm going wrong? I have tried a wealth of settings/configs and can't seem to get this to work.
Thank you.
IP Route:
sh ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, + - replicated route
Gateway of last resort is 0.0.0.0 to network 0.0.0.0
S* 0.0.0.0/0 is directly connected, GigabitEthernet0/0
192.168.1.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.1.0/24 is directly connected, GigabitEthernet0/0
L 192.168.1.176/32 is directly connected, GigabitEthernet0/0
C 192.168.100.0/22 is directly connected, GigabitEthernet0/1
192.168.100.0/32 is subnetted, 1 subnets
L 192.168.100.1 is directly connected, GigabitEthernet0/1
Here is current config:
Current configuration : 1666 bytes
!
! Last configuration change at 15:53:30 UTC Wed Apr 22 2015
!
version 15.0
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
! card type command needed for slot/vwic-slot 0/0
!
no aaa new-model
!
no ipv6 cef
ip source-route
ip cef
!
multilink bundle-name authenticated
!
voice-card 0
!
license udi pid CISCO2911/K9 sn FTX1349A0PJ
!
!
username XXXXXXX password 0 XXXXXXX
!
redundancy
!
interface GigabitEthernet0/0
description Internet
ip address 192.168.1.176 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/1
description Inside Network
ip address 192.168.100.1 255.255.252.0
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip nat inside source static tcp 192.168.1.176 23 interface GigabitEthernet0/0 23
ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0
!
access-list 1 permit 192.168.1.176
!
control-plane
!
mgcp fax t38 ecm
mgcp behavior g729-variants static-pt
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 10000 0
line aux 0
line vty 0 4
exec-timeout 10000 0
login local
transport input telnet
line vty 5 20
exec-timeout 10000 0
login local
transport input telnet
!
scheduler allocate 20000 1000
end
04-27-2015 10:39 AM
Andre,
Is it possible to open all from 192.168.1.x to 192.168.100.x? I can remote from 192.168.100.x to 192.168.1.x no problem.
04-27-2015 09:28 AM
Hi Andre,
Here is a to the minute copy of my running config. I can currently browse out etc from my 192.168.100.x network, I can ping from 192.168.1.x TO 192.168.100.x but I am unable to RDP from my 192.168.1.x network TO 192.168.100.x.
I basically want to join both networks. I know I'm close and maybe just looking too hard at things, but missing why it isn't working. I've tried several variations of configs, so hoping to also learn something in this process.
Thanks for your help! Here's the config:
interface GigabitEthernet0/0
description Internet
ip address 192.168.1.176 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/1
description Inside Network
ip address 192.168.100.1 255.255.252.0
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 192.168.1.3
!
access-list 1 permit 192.168.0.0 0.0.255.255
!
!
!
!
!
!
control-plane
!
!
!
!
mgcp fax t38 ecm
mgcp behavior g729-variants static-pt
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 10000 0
line aux 0
line vty 0 4
exec-timeout 10000 0
login local
transport input telnet
line vty 5 20
exec-timeout 10000 0
login local
transport input telnet
!
scheduler allocate 20000 1000
end
04-27-2015 09:42 AM
Hi Andre,
Here is a to the minute copy of my running config. I can currently browse out etc from my 192.168.100.x network, I can ping from 192.168.1.x TO 192.168.100.x but I am unable to RDP from my 192.168.1.x network TO 192.168.100.x.
I basically want to join both networks. I know I'm close and maybe just looking too hard at things, but missing why it isn't working. I've tried several variations of configs, so hoping to also learn something in this process.
Thanks for your help! Here's the config:
interface GigabitEthernet0/0
description Internet
ip address 192.168.1.176 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/1
description Inside Network
ip address 192.168.100.1 255.255.252.0
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 192.168.1.3
!
access-list 1 permit 192.168.0.0 0.0.255.255
!
!
!
!
!
!
control-plane
!
!
!
!
mgcp fax t38 ecm
mgcp behavior g729-variants static-pt
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 10000 0
line aux 0
line vty 0 4
exec-timeout 10000 0
login local
transport input telnet
line vty 5 20
exec-timeout 10000 0
login local
transport input telnet
!
scheduler allocate 20000 1000
end
04-27-2015 09:53 AM
Hi Andre,
Here is a to the minute copy of my running config. I can currently browse out etc from my 192.168.100.x network, I can ping from 192.168.1.x TO 192.168.100.x but I am unable to RDP from my 192.168.1.x network TO 192.168.100.x.
I basically want to join both networks. I know I'm close and maybe just looking too hard at things, but missing why it isn't working. I've tried several variations of configs, so hoping to also learn something in this process.
Thanks for your help! Here's the config:
interface GigabitEthernet0/0
description Internet
ip address 192.168.1.176 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/1
description Inside Network
ip address 192.168.100.1 255.255.252.0
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 192.168.1.3
!
access-list 1 permit 192.168.0.0 0.0.255.255
!
!
!
!
!
!
control-plane
!
!
!
!
mgcp fax t38 ecm
mgcp behavior g729-variants static-pt
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 10000 0
line aux 0
line vty 0 4
exec-timeout 10000 0
login local
transport input telnet
line vty 5 20
exec-timeout 10000 0
login local
transport input telnet
!
scheduler allocate 20000 1000
end
04-23-2015 03:03 AM
Although you have enabled NAT, you have only enabled the 192.168.1.176 to be NATTed.
access-list 1 permit 192.168.1.176
You need to expand this access list to ALL source IP addresses that need to be NATTed.
access-list 1 permit 192.168.1.0 0.0.0.255
This would enable all hosts with a source IP address in the 192.168.1.* network to be NATTed.
You can expand this to the whole 192.168.0.0 /16 network by using:
access-list 1 permit 192.168.0.0 0.0.255.255
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide