04-09-2020 09:50 AM
I try configure old Cisco 877M. Yes, I know, it is old product. But, no idea byu new and make just same steps and found same problem.
I want use 877M as router. WAN is 4G-modem. LAN is my home-office-mini-network.
4G modem is connected to FE0. Configuration is, in nutcell, "VLAN 1000, named WAN, switchport FE0. IP DHCP". This step tested and work. This 4G modem is really hole to internet and I can configure it and router show it.
BUT. LAN I does not understand. This I want: FE1, 2, 3 are LAN-port. IP Address is 100.0.0.0/16, DHCP I want 100.0.1.0/24. Default gateway (eg.) 100.0.0.1. SO: I want LAN static ip addresses 100.0.0.1...100.0.0.255, and DHCP share ip addresses 100.0.1.0 ... 100.0.1.255. Simply, printers etc "fixed" devices use this static area 100.0.0.1-255 and computers use 100.0.1.0-255. (Eg. my other network is 10.15.10.0/24, gateway is 10.15.10.1, static ip:s are 10.15.10.1...10.15.10.20 and dynamic ip:s 10.15.10.21...255. I want same but larger.)
Reason I want use FE1, 2, 3 as LAN-ports, I make "VLAN 123" and connect FE1,2,3 to this VLAN. Cannot know is this right way, but I cannot know...
Here is my configuration. In my opinion no any error, but this not work. All is ok, but not work.
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname elkesan-router
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
!
no aaa new-model
clock timezone EST 2
!
!
dot11 syslog
ip source-route
!
!
!
ip dhcp pool JUKANDHCPPOOLI
import all
network 100.0.1.0 255.255.255.0
default-router 100.0.0.1
dns-server 8.8.8.8
domain-name elkesanverkkohalli
!
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
no spanning-tree vlan 1000
vtp mode transparent
!
!
!
archive
log config
hidekeys
!
!
vlan 123
name PORTIT123
!
vlan 1000
name WAN
!
!
!
!
interface ATM0
no ip address
shutdown
no atm ilmi-keepalive
!
interface FastEthernet0
switchport access vlan 1000
no cdp enable
!
interface FastEthernet1
switchport access vlan 123
no cdp enable
!
interface FastEthernet2
switchport access vlan 123
no cdp enable
!
interface FastEthernet3
switchport access vlan 123
no cdp enable
!
interface Vlan1
no ip address
!
interface Vlan123
ip address 100.0.0.1 255.255.0.0
ip nat enable
!
interface Vlan1000
ip address dhcp
ip nat enable
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
ip nat source list NATTILISTAJUKKA interface Vlan1000 overload
!
ip access-list standard NATTILISTAJUKKA
permit 100.0.0.0 0.0.255.255
!
no cdp run
!
!
!
!
!
control-plane
!
!
line con 0
no modem enable
line aux 0
line vty 0 4
login
!
scheduler max-task-time 5000
end
04-09-2020 10:01 AM
One of the things I'm not seeing here is the NAT zone designations. Specify your "ip nat ouside" on your egress interface.
Next, I'm not seeing a default route. Specify your 0.0.0.0 0.0.0.0 {ISP gateway}.
04-09-2020 11:05 AM
04-09-2020 11:49 AM - edited 04-09-2020 11:51 AM
For IP Route, you can specify an interface, so long as it's not a virtual router you are using (like VRF). The configuration is:
ip route 0.0.0.0 0.0.0.0 {Interface, such as Gi 0/1}.
Again, the NAT configuration for an interface specifies which direction NAT is being performed. On your egress interface, the configuration "ip nat outside" tells the router that this is the egress interface, and that NAT translations will occur this way.
To this end, as you are using DHCP and interface routing, you need your NAT to state:
ip nat inside source list {YOUR LIST} {Interface, such as Gi 0/1} overload
Hope this helps.
04-09-2020 12:16 PM
04-09-2020 11:58 AM
I want to add that you really should use a physical interface as your egress interface, and not a VLAN. I would configure the physical interface like this, pretending that your egress interface (because I don't know what it is) is FastEthernet 0/0, or just fa0/0 for the example, realizing that you said it was 4G this doesn't matter: specify the interface connecting to your ISP:
interface fa 0/0
ip address dhcp
ip nat outside
Then, in global configuration:
ip route 0.0.0.0 0.0.0.0 fa 0/0
ip nat inside source list NATTILISTAJUKKA int fa0/0 overload
04-09-2020 01:18 PM
04-09-2020 02:24 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: