General discussion

Locked

Unable to get out of Cisco 1811

By stuff ·
Hi, I have been trying to configure my CISCO 1811 for a while now, I am able to ping out from the router itself, and I get an ip from the 1811 on another PC). However I cannot ping out from it, can you please check my configuration and see if you can find something wrong or missing, thanks, here is my current config, I am connecting using FA0 into another router that gives the 1811 and ip of 10.19.15.150, I set it up as a static ip. It could be an issue with Acess-list or NAT but I don't know, Please help, thanks again.

Current configuration : 3241 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
!
no aaa new-model
memory-size iomem 15
!
crypto pki trustpoint TP-self-signed-950502357
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-950502357
revocation-check none
rsakeypair TP-self-signed-950502357
!
crypto pki certificate chain TP-self-signed-950502357
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 39353035 30323335 37301E17 0D303830 39313430 38303735
365A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3935 30353032
33353730 819F300D 06092A86 4886F70D 01010105 000381 00308189 02818100
C7438606 216F0E1A 7F5FCBCB 888D8F35 4AA31C30 53712960 6C2F4916 7B31E236
59B99D52 9E4C334A 435957CF DAE4A63A 5F362E30 02CFDE14 DD2FC040 618E4C9B
8F626EDE 0D80F11A 466CE047 6BC674DA 42D2CFCD 1B7922CC 2CEBCCB9 0549C29D
8A9AF7DD 827B5887 C455A37D 73CD60C2 1A43F114 99E894DA 421C010C E89E63C5
02030100 01A36630 64300F06 03551D13 0101FF04 05300301 01FF3011 0603551D
11040A30 08820652 6F757465 72301F06 03551D23 04183016 8014E45F FF5C457C
F94BF916 AA4B1135 F19E4D07 1F71301D 0603551D 0E041604 14E45FFF 5C457CF9
4BF916AA 4B1135F1 9E4D071F 71300D06 092A8648 86F70D01 01040500 03818100
4627BE72 E07B32A1 AC0D20DF BA8E7836 DF2B766A 0DE5FAA4 00614009 EB8E0A4C
50957850 734FE0A1 F3B0A95B 99BC2C32 3AA873AA 85F9ED63 E3E48E21 C27C87C7
75859D8F AF550B8F D6CA02A2 0C1FD38F EB8C42B1 39B0B4A7 4C481CA4 30F2F6AA
C5955986 41BD1878 C4BE1AA8 A1FCA635 AA659601 CB686BF4 08F7D972 4C66C9F9
quit
dot11 syslog

ip source-route
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.0.1
!
ip dhcp pool MAIN
import all
network 192.168.1.0 255.255.255.0
dns-server 65.32.1.65 65.32.1.70
default-router 192.168.1.1
!
!
ip cef
no ip domain lookup
!
no ipv6 cef
multilink bundle-name authenticated
!
!
!
username admin privilege 15 password 0 XXXXX
!
archive
log config
hidekeys
!
!
!
!
!
interface FastEthernet0
ip address 10.19.15.150 255.255.255.0
duplex auto
speed auto
!
interface FastEthernet1
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
!
interface FastEthernet5
!
interface FastEthernet6
!
interface FastEthernet7
!
interface FastEthernet8
!
interface FastEthernet9
!
interface Vlan1
ip address 192.168.1.1 255.255.255.0
ip access-group 100 in
ip access-group 100 out
ip nat outside
ip virtual-reassembly
ip tcp adjust-mss 1452
!
interface Async1
no ip address
encapsulation slip
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
!
!
access-list 1 permit 192.168.1.0 0.0.0.255
!
!
!
!
!
!
!
control-plane
!
!
line con 0
line 1
modem InOut
stopbits 1
speed 115200
flowcontrol hardware
line aux 0
line vty 0 4
login
!
end

This conversation is currently closed to new comments.

2 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

A few suggestions

by NetMan1958 In reply to Unable to get out of Cisc ...

Yes, you do need to enable NAT. Also, you need to change this:
ip dhcp excluded-address 192.168.0.1
to:
ip dhcp excluded-address 192.168.1.1

You need to change:
ip nat outside
to
ip nat inside
on interface Vlan1

Add the following:
ip nat inside source list 1 interface FastEthernet0 overload

I would change:
interface FastEthernet0
ip address 10.19.15.150 255.255.255.0
duplex auto
speed auto
to
interface FastEthernet0
ip address dhcp
ip nat outside
duplex auto
speed auto

Remove this line:
ip access-group 100 out
from interface Vlan1
in fact, just for testing you can remove both ip access-group commands from that interface.

Finally, add this command:
ip route 0.0.0.0 0.0.0.0 dhcp

Start with those suggestions and see how it goes.

Collapse -

Thanks

by stuff In reply to A few suggestions

Netman,

Thanks for your help, I had already change the:
ip dhcp excluded-address 192.168.0.1
to:
ip dhcp excluded-address 192.168.1.1

It was a typo and I saw it right after I posted the config file here. But I have to tell you that I did exaclty what you told me and it worked just fine, I am able to access the net now. The problem I have now is that I usually access my work via VPN from home now I have to figure out a way to do so (VPN Pass-through) Thanks again for all your help.
Tico

Back to Networks Forum
2 total posts (Page 1 of 1)  

Related Discussions

Related Forums