Cisco Infrastructure :: 2621 - Routing With Two LANs
Mar 9, 2006
I have a spare 2621 sitting on my desk and i would like to run a little experiment. i had two LAN segments that are seperated right now, but would like to stick this router between them and route traffic between them?
Current configuration : 1221 bytes
!
version 12.2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption(code)
I purchased a Cisco 2621 with IOS Version 12.3(26) on it. When I went through the commands, I couldn't find any VLAN or VTP available. I need to make sure I can see this on the device in order for me be able configure VLAN on my network and get ready for my CCNA exam.
Below is the version on the device and I also attached the available commands: Version: IOS (tm) C2600 Software (C2600-I-M), Version 12.3(26), RELEASE SOFTWARE (fc2)
I've created the VLAN on the Database but it tells me that there are no VLANs configured when i issue the command. Both VLAN 110 and 111 status are down, down.. Below is my config:
I have a 2621 that I am configuring on the internet. My ISP gives me a static DHCP assigned address and then two more static addresses that are not part of the same block. (e.g. 1.2.3.4 is static via dhcp and then they give me 5.6.7.8/30).
I have fa0/0 getting 1.2.3.4 ia dhcp. I have 5.6.7.8 on a loopback interface for PAT/NAT as I have the main one on fa0/0 doing vpn to a remote ASA. The problem is that I have yet another device that needs a public IP, mainly 5.6.7.9... I want to hook that device up to fa0/2 (this box has three fa interfaces). How do I setup fa0/2 if I want to give the device on it a real live public IP address? I have done this before, but it must have been 10 years back on an even older CISCO and I can not remember how I did it.
I'm moving into a new data center. I don't consider myself a network engineer or anything but I do understand the basics. The new data center I am moving into routes my network to me a bit differently than my old data center. The IOS on the Cisco 2621 is: c2600-i-mz.123-26.bin
I am assigned a /29 block which they configure as the routing network, it looks like this: Routing Network: A.A.A.0Routing Network Sub net Mask: 255.255.255.248Routing Network Def Gateway: A.A.A.1Customer Usable Address: A.A.A.4
I've been assigned a /28 block which is B.B.B.240/28. They stated that in order for me to use my allocated blocks, I had to act as my own gateway, routing the traffic through the routing network. This goes just a bit beyond my networking knowledge, though I still understand it, I just don't know exactly how to execute. I'm assuming my 2621 with 2 Fast Ethernet interfaces should be able to handle this routing scenario.
Any sample configs, or possible a link to a how to to get this setup? I was going to use FreeBSD to do the routing, but a appliance based Cisco router is much more attractive of an option to me.
My main issue was trying to connect virtuelly via GNS3 and my router setup on it. I have three Cisco 2621 XM routers set up. They all came with 2 Fast Ethernet ports. However, only one of them has a Serial port. So, what I'm doing is connecting the routers together with the fast ethernet ports using crossover cables. So, I baselined two routers to start with. Very simple AAA, set up IP HTTP server, IP HTTP Secure Server, etc. Privledge lvl 15 access, etc.
I then set my Router A's inside Fa0/1 port with a 192.168.1.0/24 network. The outside port Fa0/0 is 10.0.0.0/30 network.Router B is set up similar, 192. 168. 2. 0/24 insice Fa0/1, Fa0/0 is 10.0.0.0/30 network outside. So, three networks 192.168.1.0, 192.168.2.0, 10.0.0.0 network. [code] I then repeated the same on Router B, just transposing 2.0 network for interesting traffic, and Peer 10.0.0.2 for the Fa0/0 interface on Router A.When I "test" the tunnel, I get an error message. So, since I'm connected to Router B (which was working, had routing, and had Router A's network 1.0 in it's routing table), the error msg says that I need to add a route into the routing table (192.168.1.0). It was there up until I attempted to put the VPN in place. It's like it stopped the routing.
At face value, it looks like this should be working! But when I debug the ospf process, it looks like hello packets aren't tranversing across to the other side. Is it because I just have the 192.xxx.xxx.xxx networks as "interesting" traffic? Can I have multiple networks marked as "interesting"? I thought that's what the peer statements were doing to allow the tunnel to be established.
I need to setup a vlan between the 6509 and 2621 router. This needs to be a VLAN (200) the runs between the devices that uses DOT1Q trunking. The end result is all the networks (vlans) on the 6509 can talk to the LAN on the 2600 (10.133.22.0 / 23) and visa versa.
Device 1 6509 with CatOS / IOS Config I did on the MSFC: Interface Vlan 200 ip address 10.10.10.1 255.255.255.248
Setup is like this: Poly com IP phones -> Cisco 2960 switches -> Cisco 2621XM router running 12.28(r). A Windows 2003 server running on HP Proliant DL380 G4 with the correct DHCP scope is configured for the IP phones, also sitting on a Cisco 2960 switch.
A typical port config on the 2960 is: interface FastEthernet0/1 switchport mode access switchport voice vlan 60 mls qos trust cos auto qos voip trust spanning-tree portfast spanning-tree bpduguard enable
Relevant section of the config on the 2621XM router: interface FastEthernet0/0 no ip address no ip redirects no ip proxy-arp ip pim sparse-dense-mode [Code] .......
This used to work on a Windows 2000 server which sat on different piece of hardware, but stopped immediately after the migration to Windows 2003 server was done. There was no change on the router or switches prior to or after the server migration. I see DHCP server log on the 2003 server giving DHCP NACK because the phones are apparently asking for IP's in the data VLAN.
I've got a 2621 configured as my main gateway to the internet - right now it's obtaining a DHCP ip from a the ISP's proprietary router set to bridged mode.
As of now, I'm unable to ping the internal interface of the router. I can ping external IP's only, even though I have DNS servers listed, i am unable to resolve host names. I'm running a few servers to which people are able to connect to my web server, among other services. I even have a crypto map setup to another 2621 across the country and can ping all internal ips on the other end... I JUST CANNOT PING THE INTERNAL INTERFACE of the router!!
I've noticed that when I ping the router during it's boot process (using linux un-interupted) I get a response in a very short window, then dies again. I'll post my config below:
We want to use a Cisco 861 Ethernet router to link our LAN's data and voice segments together (each on separate switches). Our switches are not Layer3 so routing over them is not an option. We only use the default VLAN1 on both switches.There is a data segment 192.168.1.0/24 and a voice segment 192.168.150.0/24, each with it's own internet/WAN access (internet for the data lan and SIP provider for the voice lan).
- I want to make the Cisco 861 the default gw on both segments, but they should only route traffic destined for the other segment to each other and route all other traffic to their segment's designated internet connection. I don't want the Cisco to do any NATting and there's no need for firewalling either.
I have a lab setup to take my CCNA and CCNP and I'm having issues trying to get WAN connectivity back to a switch at the end of my network. My lab environment consists of 1 - 2950 switch, 1 - 2620 and 1 - 2621XM. I have 1 Ethernet connection from each router to the switch and 1 serial connection from the 2620 to the 2621XM. I have the serial interfaces in a shutdown state right now so there is no loop since I do not have Spanning tree setup on the ports on the switch yet.
Right now using the fast ethernet ports on the routers and I have no issues its when I shut down those Ethernet ports and try using the serial interfaces when I start having issues. So my network layout is Ethernet from switch port f0/4 to port f0/0 on 2620 and serial from s0/1 on the 2620 to s0/2 on the 2621XM. My 2621XM f0/1 is whats connected to the WAN and I have no issues getting to the WAN from my 2621Xm or my 2620 but when I try pinging any website or even my WAN default gateway from my switch I get nothing!
Ive also noticed that when I do a IP NAT translation (after accessing the WAN from my 2620) on my 2621XM the source IP is of my serial connection not the ip of my 2620 router? I have my default gateway on the 2620 as the the IP of my serial interface on the 2621XM and vice versa because my LAN network is 172.16.1.0 and my WAN is 172.16.9.0. I have a /31 setup between my serial connections 172.16.11.0 (s0/1) is on the 2620 and 172.16.11.1(s0/2) is on the 2621XM. I used the SDM (ver 2.5) to setup NAT to have f0/1 with Nat outside and s0/2 as Nat inside. Encapsulation is HDLC between the serial links. Ive attached the running configs of the switch and routers.
I am trying to get the Cisco 1921 to route between 2 LANs. I can ping from the router itself, but cannot ping across either, is there something I am doing wrong here:
version 15.1 ! no aaa new-model ! no ipv6 cef ip source-route ip cef
i have spent a few hours trying to NAT out a few intenal 192.168.x.x hosts through both my ethernet1/0 interface and also tryed using another IP from the range.
I've got a Cisco 2621 with this IOS image in flash: c2600-i-mz.120-7.bin (the only IOS in flash). When I power up the router, the following errors occur:
open: file "n" not found open(): Open Error = -1 loadprog: error - fileopen boot: cannot load "flash:n"
I have to press "Ctr l" and "break" to enter Roman, there i can use the boot command to start the IOS. Configuration register is set to 0x2102, all running config should be factory default.
What I have to do to boot the IOS directly when i power up my router (without entering Roman mode...)?
How to connect to LANs from one Computer Answer of : How to connect to two different LANs from one Computer with two LAN Cards :with 16 Port Switch in My Computer lab.
I have two complete and separate "networks", each with their own internet connections. One is for home use, one is for business use.
(1) Home network has a D-Link cable-modem/router to the ISP. Variable public IP address. NAT'd.This router is configured "as provided" by the ISP (except for a few port-forwards). DHCP serving is enabled, etc. If possible, I do not wish to change any major router settings.LAN IP Range: 192.168.0.0/255.255.255.0
(2) Business network has a 2-Wire ADSL-modem/router to a different ISP. Static public IP address. NAT'd.DHCP serving is handled by a Windows 2003 Server. I am happy to change any router and server settings.LAN IP Range:192.168.254.0/255.255. 255.0
I have a network printer. It is currently connected to the Home Network (1) and has a static IP address 192.168.0.8, but I wish it to be accessible by PC's on both networks.My first thought is to simply connect both routers LAN-side via an ethernet cable. However, I can't find a way to add a LAN-LAN static route on the Business Network router (it only has options for WAN-LAN static routes). Do I really need to internetwork the routers via the internet?!?
I'm given an ASA 5505 to configure for remote access vpn. I can establish vpn connection to the ASA 5505 but can't access any of the internal vlan/subnets. I configured three of the ASA ports for connection into each of the internal subnets/vlan via a switch.Given below is my full configuration.
ASA5505# sh run: Saved:ASA Version 8.3(1)!enable password bLjadbVl0mgRQWih encryptedpasswd 2KFQnbNIdI.2KYOU encryptednames!interface Vlan1nameif insidesecurity-level 100ip address 192.168.1.1 255.255.255.0!interface Vlan2nameif
I have two LANs 192.168.0.* and 192.168.1.* (main)
I'd like to facilitate port forwarding on the sub-LAN - is there a way to configure the device to do so? The "main" LANs fowarding works just fine, however I have specific ports that need to go to the sub-LAN.
I have a 2621 with a WIC-1ADSL that connects to my ISP. Since the 2621 has 2 ethernet ports, I wanted to setup a network on the second ethernet port for testing things such as VPN into my network via my ASA5505. I have a DHCP pool set on the particular network but cannot get a client to get an address from the router. I think I might have an ACL that is blocking or need an ACL to allow bootp on the interface. Here is the config:
I have 2 LANs in my own PC & 2 Routers (TP-Link WR941N each) with 2 internet accounts (512Kbps each) connected to the same ISP signal & company using NanoStation 5 from ubnt.As u know the connections work separately by default!! (I use Windows 7 64bit)Can I merge them to get double speed (download/upload simultaneously) using reg edit or special software or method?
I need to connect my laptop that has a single wired network port to 2 different lans...currently I unplug the wire from wall port A and plug it into wall port B and back and forth. Is there something like a KVM switch, that can have wires from wall port A and B go in to with a single wire going out to the laptop's network card? Then I could just toggle a switch (push a button) to connect back and forth between the lan connected through wall port A and wall port B. Does such a device exist or would it make better sense to add another network card via USB and have both wall ports wired to the laptop all the time and use software to switch between each card?
how can i connect two offices in the same town.these two offices are separated by two kilometres.each office has ten rooms.how can i provide a secure intranet between the two offices ,what media can be used and hardware to provide a secure intranet via the two offices.
A is behind a Watchguard XTM25 11.5.3 B is behind a CISCO SA520W
Both have static public facing IP's.
B only has a IP based PBX system attached to it over a SIP ALG. (originally it was hooked up to the watchguard but they didn't play nice, but works great with the Cisco. Problem is the Cisco don't have all the features of the Watchguard)
A has all my users workstations attached. The issue is that computers on A need to talk to server on B for a desktop application to work. Since they are on separate subnets, it isn't working. The app itself still doesn't work by port forward/sNats, etc.
A & B are right next to each other, so cabling between them is not an issue.
Currently, I have a cable between the watchguard and the Cisco. The watchguard end is configured with a static private ip on the subnet A (the cisco side), and plugged into the lan on the cisco side. I have a policies to let all traffic flow freeley, and from the logs on the Watchguard, all A subnet traffic is correctly going to the Cisco via said cable.
But, nothing is coming back from the Cisco. So my question is, how can I get the Cisco to play nice with the other subnet and send traffic back to the B subnet?
I have a Cisco 2600 with IOS 12.3. I need a very basic configuration to allow traffic between two LANs. To test this I cleared the router config to the factory default state and configured my network addresses on the interfaces.
When I connected a PC to each interface I found they could ping each other, I was expecting to have to write ACLs to permit the traffic into the interfaces, thinking that the default behaviour of the router would be to deny access. default bahaviour without any ACLs or other routing configurations?
My config, such as it is, is as follows:
Current configuration : 770 bytes version 12.3 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption
I'm trying to figure out the best design for my network. I currently have a setup like this:Internet - Cable Modem - Pix 515E (doing NAT) - 2621 - Internal Network.Now, should I have the 2621 as my edge device or the Pix?
I have a 2621 router - old. but works well.Need to put in an ACL to limit the inbound SMTP traffic to be FROM a specific set of IP's, and deny all others.
I have tried various combinations with no luck. Something obvious, I am sure.
When I do a show access lists 160 it shows all SMTP traffic being snagged by the SMTP deny statement. All other traffic works correctly.
Here is my config so far...
Current configuration : 3093 bytes!version 12.2no service single-slot-reload-enableservice timestamps debug uptimeservice timestamps log uptimeno service password-encryption!hostname xxxxxxxxxx!logging rate-limit console 10 except errorsenable secret 5 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx!ip subnet- [Code] ....
The config I am posting is from a 2621 router. This routers Int fa0/0 connects to AT&Ts OPTEMAN 10Mbs Ethernet interface. The other end connects to our HQ router. At HQ is our PRIs and phone switches. I have configured QoS for this router, but don't I have to link them to the ingress interfacce (Int FA0/0)?