Hello, tis is my first post here, so hopefully it will be pleasent.
I have a Cisco 851 (wired version) wired to a cable modem. My problem: I make contact with my ISP’s DNS server, and receve the Dynamic IP. I can ping extenal sites such as google, using their IP. What I can’t do is access the sites from the internet. I assume ping and http access are different. I have my current raw running config posted below.
I followed the setup config that they have posted here, and stripped out the wirelesssegments. You’ll have to excuse any jumble thats in the config, I have been trying all sorts of things to get it going. if someone could help me out, it would be much appreciated. Or you could post a working dynamic IP config, and I could use that.
Building configuration…
Current configuration : 6178 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname itsrouter
!
boot-start-marker
boot-end-marker
!
logging buffered 51200 warnings
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
aaa session-id common
!
crypto pki trustpoint TP-self-signed-1295381371
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1295381371
revocation-check none
rsakeypair TP-self-signed-1295381371
!
!
crypto pki certificate chain TP-self-signed-1295381371
certificate self-signed 01
30820251 308201BA A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31323935 33383133 3731301E 170D3032 30333031 30323032
30345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 32393533
38313337 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100C677 F762215C D5075A65 3D637843 015E56E7 ED8C2A9F 7B2C0F6A DD840964
7C0697A2 6627E8C9 2B369DF5 C5FBA933 2D4B0A0A CBBB42FA 3C9B20AA 220F3361
D8462F00 173A6249 49CBFA69 6769DABF 053CC080 B2E421F9 8459AE79 0D2702B6
DBE26C0D D3C77FD3 525F36F6 80C68D8D 10F2D62A C1208414 A00353A2 247FE67E
C1430203 010001A3 79307730 0F060355 1D130101 FF040530 030101FF 30240603
551D1104 1D301B82 19697473 726F7574 65722E69 74732D63 6F6E7472 6F6C2E63
6F6D301F 0603551D 23041830 1680143B DEB5EA12 0C6CABC7 02445C39 F2DA9E6E
219C4A30 1D060355 1D0E0416 04143BDE B5EA120C 6CABC702 445C39F2 DA9E6E21
9C4A300D 06092A86 4886F70D 01010405 00038181 0071DA0E 12A24BE6 D4189528
68C2077D 00B619EF 27D42F2C 17063E32 6977A4F6 1DD36794 1AE2DB75 C695495F
F2D1C47E 2D3157C9 1B18ACF1 1CA9A867 843CFED3 74698447 47E04994 15A7324B
FDBE4A90 C0DAC2AA 398BAD3D 40473E4B 4C35A52F F9AC2EBA E1D0A3C1 033A84C4
2455C75C 11F0D992 16B19446 DDA46CB8 61B590ED 61
quit
dot11 syslog
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.1.1 192.168.1.99
!
ip dhcp pool internal-net
import all
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1
domain-name its-control.com
lease infinite
!
!
ip cef
ip inspect name myfw tcp
ip inspect name myfw udp
ip inspect name myfw router
ip inspect name myfw icmp
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
ip domain name its-control.com
!
!
!
username admin privilege 15 secret 5 $1$vt6v$L6kWlFLt4HTZMLNqTHZmI.
!
!
archive
log config
hidekeys
!
!
!
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
description internal network$ETH-WAN$
mac-address 0014.6c97.7049
ip address dhcp client-id FastEthernet4
ip access-group internet-inbound-acl in
ip access-group internet-inbound-acl out
no ip redirects
no ip unreachables
ip directed-broadcast
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$
ip address 192.168.1.1 255.255.255.0
ip access-group internet-inbound-acl in
ip access-group internet-inbound-acl out
no ip unreachables
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
!
router rip
passive-interface FastEthernet4
network 192.168.1.0
no auto-summary
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 FastEthernet4 permanent
ip route 0.0.0.0 0.0.0.0 dhcp
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat pool internalnetwork 192.168.1.0 192.168.1.254 netmask 255.255.255.0
ip nat inside source list sdm_vlan1_in interface FastEthernet4 overload
!
ip access-list extended SDM_ESP
remark SDM_ACL Category=0
permit esp any any
ip access-list extended SDM_GRE
remark SDM_ACL Category=0
permit gre any any
ip access-list extended SDM_OSPF
remark SDM_ACL Category=0
ip access-list extended SDM_PCP
remark SDM_ACL Category=0
permit pcp any any
ip access-list extended SDM_PCP0
remark SDM_ACL Category=0
permit pcp any any
ip access-list extended SDM_PIM
remark SDM_ACL Category=0
ip access-list extended guest-acl
deny ip any 192.168.1.0 0.0.0.255
permit ip any any
ip access-list extended internet-inbound-acl
remark SDM_ACL Category=17
permit udp any eq bootps any eq bootpc
permit icmp any any echo
permit icmp any any echo-reply
permit icmp any any traceroute
permit tcp any any
permit gre any any
permit esp any any
permit icmp any any
ip access-list extended sdm_vlan1_in
remark SDM_ACL Category=2
permit icmp any any
permit udp any any
permit tcp any any
ip access-list extended sdm_vlan1_out
remark SDM_ACL Category=1
permit icmp any any
ip access-list extended trafic
remark SDM_ACL Category=128
permit ip any any
!
access-list 1 remark SDM_ACL Category=16
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 1 permit 192.168.2.0 0.0.0.255
access-list 195 remark permit HTTP traffic
access-list 195 remark SDM_ACL Category=2
access-list 195 permit tcp any any eq www
no cdp run
!
control-plane
!
banner login ^C
^C
!
line con 0
no modem enable
line aux 0
line vty 0 4
access-class sdm_vlan1_in in
access-class sdm_vlan1_in out
transport input telnet ssh
!
scheduler max-task-time 5000
end
THANKS!
-Andrew