Hello all,
I have an issue with my new Cisco 871. I can connect fine if I set the Eth4 interface to Dynamic DHCP, but if I want to assign it a specific IP, the connection fails on step 5 of the test, stating “Ping to the destination host(s) failed.”
My config is below:
Current configuration : 6849 bytes
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname Corporate
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging buffered 51200 debugging
logging console critical
enable secret 5
!
no aaa new-model
!
resource policy
!
clock timezone PCTime -5
clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00
ip subnet-zero
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.0.2
!
ip dhcp pool sdm-pool1
import all
network 192.168.0.0 255.255.255.0
default-router 192.168.0.2
!
!
ip tcp synwait-time 10
no ip bootp server
ip domain name e-motionsoftware.com
ip name-server 192.168.0.149
ip name-server 64.105.199.74
ip ssh time-out 60
ip ssh authentication-retries 2
ip inspect name DEFAULT100 cuseeme
ip inspect name DEFAULT100 ftp
ip inspect name DEFAULT100 h323
ip inspect name DEFAULT100 icmp
ip inspect name DEFAULT100 netshow
ip inspect name DEFAULT100 rcmd
ip inspect name DEFAULT100 realaudio
ip inspect name DEFAULT100 rtsp
ip inspect name DEFAULT100 esmtp
ip inspect name DEFAULT100 sqlnet
ip inspect name DEFAULT100 streamworks
ip inspect name DEFAULT100 tftp
ip inspect name DEFAULT100 tcp
ip inspect name DEFAULT100 udp
ip inspect name DEFAULT100 vdolive
!
!
crypto pki trustpoint TP-self-signed-1031634910
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1031634910
revocation-check none
rsakeypair TP-self-signed-1031634910
!
!
crypto pki certificate chain TP-self-signed-1031634910
certificate self-signed 01
30820256 308201BF A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31303331 36333439 3130301E 170D3038 30353237 30323230
30375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 30333136
33343931 3030819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100D86B E81AC8F2 6B5F041A C14DF58F DFF2F8A9 F14257D8 571CEF87 C136114B
3BB7A452 DB7C57BD 26D3BD01 59A3C2C4 49795D0C C8F21887 B63512A4 3E7F8EFF
49A36A07 A0FC5F04 FC0C4FB9 0EB617BE 97842BA8 5B0E7CA8 46E56140 F9939EC4
D3722230 D36AAED0 504698C8 43D26884 1C475BEC A0C64B85 2F9B2BCD 3C5C44C0
4AF50203 010001A3 7E307C30 0F060355 1D130101 FF040530 030101FF 30290603
551D1104 22302082 1E436F72 706F7261 74652E65 2D6D6F74 696F6E73 6F667477
6172652E 636F6D30 1F060355 1D230418 30168014 EC7B4D26 50236B92 99F7F473
10DCC102 07AB885F 301D0603 551D0E04 160414EC 7B4D2650 236B9299 F7F47310
DCC10207 AB885F30 0D06092A 864886F7 0D010104 05000381 81003742 13832BA3
9E022CAB 60A3BF5A 88920858 CF31D99B C1DDF939 B3E20B17 B6D0A0A2 D429861C
C3423229 99EFB940 D8B88341 251A1CFE 7F955DDA 122DE1BA E831E71C AA79C83F
8E9848CE FC7CC822 D9AACB6D CF1EBE74 39F62257 895CB2CC 77791DA0 A127D0C1
50E0F5BF 63E14A41 6C2442FF 86CD0889 79C54964 FD2E1FBB B1BC
quit
username xxxx privilege 15 secret 5 xxxxxxx
!
!
!
!
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
description $ES_WAN$$FW_OUTSIDE$$ETH-WAN$
ip address 67.100.242.154 255.255.255.248
ip access-group 101 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip inspect DEFAULT100 out
ip virtual-reassembly
ip route-cache flow
duplex auto
speed auto
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 192.168.0.2 255.255.255.0
ip access-group 100 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1452
!
ip classless
ip route 0.0.0.0 0.0.0.0 FastEthernet4
!
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface FastEthernet4 overload
ip nat inside source static tcp 192.168.0.149 25 67.100.242.158 25 extendable
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.0.0 0.0.0.255
access-list 100 remark auto generated by Cisco SDM Express firewall configuration
access-list 100 remark SDM_ACL Category=1
access-list 100 deny ip host 255.255.255.255 any
access-list 100 deny ip 127.0.0.0 0.255.255.255 any
access-list 100 permit ip any any
access-list 101 remark auto generated by Cisco SDM Express firewall configuration
access-list 101 remark SDM_ACL Category=1
access-list 101 permit udp host 64.105.199.74 eq domain any
access-list 101 permit udp host 192.168.0.149 eq domain any
access-list 101 permit tcp any host 67.100.242.158 eq smtp
access-list 101 permit udp any eq bootps any eq bootpc
access-list 101 deny ip 192.168.0.0 0.0.0.255 any
access-list 101 permit icmp any any echo-reply
access-list 101 permit icmp any any time-exceeded
access-list 101 permit icmp any any unreachable
access-list 101 deny ip 10.0.0.0 0.255.255.255 any
access-list 101 deny ip 172.16.0.0 0.15.255.255 any
access-list 101 deny ip 192.168.0.0 0.0.255.255 any
access-list 101 deny ip 127.0.0.0 0.255.255.255 any
access-list 101 deny ip host 255.255.255.255 any
access-list 101 deny ip any any
no cdp run
!
!
control-plane
!
banner exec ^CC
% Password expiration warning.
———————————————————————–
Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username “cisco” for one-time use. If you have already
used the username “cisco” to login to the router and your IOS image supports the
“one-time” user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.
It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.
username
Replace
use.
———————————————————————–
^C
banner login ^CCAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end
Thanks for any direction!