Question
October 19, 2007 at 09:16 AM
jking_007

Cisco 857 and Cisco 5505 ASA in series

by jking_007 . Updated 18 years, 9 months ago

Hi

I have now been working on Cisco equipement for a grand total of about 2 weeks. Hence I don’t really know what I’m doing.

I want to make my Cisco 857 Router transparent, so that the Cisco 550 firewall has the external IP address, given to me from my ADSL connection.

My 1st thought was to copy the config of an existing router, set up in this manner, and configure the 857 in the same way. All ok apart from the fact that I cannot put an external IP address on FastEth0 as it states that it’s a L2 link. I resolved this by creating a vlan1 and placing the external IP on this.

The second bit that didn’t work was placing an “ip unnumbered” statement on Dialer1. The connection stopped working.

Here is my config. Any ideas anyone?

Current configuration : 1474 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname JayIISRouter
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$HYUajIqJk.oFPrOuthwi1/
!
no aaa new-model
!
resource policy
!
!
!
ip cef
no ip domain lookup
!
!
!
username netadmin privilege 15 secret 5 $1$AXkw$EdW.xwSRjcWZZ62wMCQ/
!
!
!
!
!
interface ATM0
no ip address
no snmp trap link-status
no atm ilmi-keepalive
pvc 0/38
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl operating-mode auto
!
interface FastEthernet0
shutdown
!
interface FastEthernet1
shutdown
!
interface FastEthernet2
shutdown
!
interface FastEthernet3
shutdown
!
interface Vlan1
ip address 91.84.225.225 255.255.255.252
!
interface Dialer1
ip address negotiated
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname naxxxxx@adsl.eclipse.co.uk
ppp chap password 0 xxxxxxx
ppp pap sent-username naxxxx@adsl.eclipse.co.uk password 0 xstexxxx
!
ip route 0.0.0.0 0.0.0.0 Dialer1
!
no ip http server
no ip http secure-server
!
access-list 10 permit 217.45.222.8 0.0.0.7
access-list 10 permit 193.132.72.8 0.0.0.7
access-list 10 permit 194.152.81.120 0.0.0.7
access-list 10 remark VTY Access Control
!
control-plane
!
!
line con 0
no modem enable
line aux 0
line vty 0 4
access-class 10 in
login local
!
scheduler max-task-time 5000
end

I haven’t bothered talking about the 5505 yet,as I’ll cross this bridge once I’m happy with the cfg of the 857.

N.B I can telnet into the router from my home, so it is connected to the net properly.

cheers
Jonathan

This discussion is locked

All Comments