Cisco Switching/Routing :: 1921 Cannot Access Internal Web Server

Oct 31, 2011

i cant resolve one problem in may 1921 isr router, i have a web server in my internal lan , i set up static nat for accessing that web server from outside and it woks fine but i cannot view that site from internal workstations can you suggest me what to do. as i know when request gets to router it performs static nat and sends packet to the web server, but the server responds with its private source  address instead the public address  witch workstation expects and connection cannot established.

View 3 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 1921 Routing Access From Mixed IP Ranges Between VLANS

Jan 23, 2013

I have the following config using a Cisco 1921.  I am trying to get devices on the the native VLAN to get internet access via the gateway x.x.x.73.Any thing being routed from the other Vlans 15/20/30 can get access, but nothing from an internal IP address.  Is there something I am missing.
 
The Xs replace the same 3 octets for each interface.I am trying to route from VLANs 15/20/30 to see VLAN 5.  I have tried a few things, in terms of adding extra ip routes, but can't get anything to work.  Each of those Vlans have another router on the other side of them, which I have also tried adding ip routes too, but nothing.  One of the routers (Vlan15 is a Draytek 2830). [code]

View 5 Replies View Related

Cisco Switching/Routing :: (10.10.50.0 / 24) - After Applying ACL / Unable To Hit Internal Web Server

Apr 7, 2013

This isn't a big deal as the rest of the ACL works fine, but this is an annoynace since the web auth redirects to our company website (internal for now) after successful login.We have a Cisco WLC that provides access to our production and guest wireless environments.  The guest environment of course is in a separate vlan (10.10.50.0/24).  So I created this ACL:
 
access-list 107 permit udp any host 10.10.2.13 eq bootpc <----internal DHCP server
access-list 107 permit udp any host 10.10.2.13 eq bootps
access-list 107 deny ip any 10.10.0.0 0.0.255.255 <---all internal networks
access-list 107 deny ip any 172.28.16.0 0.0.0.255 <----DR Network
access-list 107 permit ip any any
int vlan 50
Desc "Guest wireless network"
ip access-group 107 in
 
This ACL basically gives the wireless guests access to an internal DHCP server and full access to the internet.  For the 10.10.50.0/24 scope, the DHCP server assigns Internet DNS servers and my rationale is that wireless clients would access it via the external IP address but I suppose it doesn't work quite like that with the website being behind the same router as the client machines.

View 1 Replies View Related

Cisco Switching/Routing :: IP SLA Support On 1921/K9 Or 1921-SEC/K9?

Oct 5, 2012

We want to puchase new Cisco ISR 1921/K9 .   i want to know does it support the following sample IP-SLA commands
 
ip sla 2icmp-echo 172.16.1.2timeout 500frequency 1ip sla schedule 2 life forever start-time now
 
track 10 rtr 1 reachability
delay down 1 up 1
!
track 20 rtr 2 reachability
delay down 1 up 1 
ip route 0.0.0.0 0.0.0.0 192.168.1.2 track 10ip route 0.0.0.0 0.0.0.0 172.16.1.2 track 20
  
Im asking above question because we will need to enable ip-sla  on  the mentioned router.   as i read on the cisco webside, it says Cisco-ISR-1921/K9-IP Base  support only  IP-SLA RESPONDER  feature nothing else. If  Cisco-921/K9  does not support the above commands , should i go for ordering Cisco-1921-SEC/K9 ? 

View 4 Replies View Related

Cisco Switching/Routing :: 891W ISR - Can't Access Internal AP

Jan 26, 2012

I have an 891W router that requires a firmware update to fix a bug wth the internal AP where all you get when accessing it via the CP Express ("Launch Wireless Application", which is  just opening another web browser to your AP) is an Enter button.  This issue seems to be common so I found a thread, though for the 881W (but same process) where the fix is to update the AP's firmware. 
 
So I downloaded ap801-rcvk9w8-tar.124-21a.JY.tar from cisco.com, set it up in my tftp server, and at the console ran the following from the router:
 
Router#service-module wlan-ap 0 session <enter>
 
This brings me to the AP.  
 
I then type in:
 
InternalAP#archive download-sw /force-reload /overwrite tftp://192.168.0.71/filename.tar <enter>
 
It seems to go through the process of re-imaging the fw but the end result now after it is done is that I cannot access the ap at all and the hostname has been screwed up.  So now when I go to the AP (via Router#service-module wlan-ap 0 session <enter>), this is what I see:
 
AP6400.f177.d0ee>
 
If I type "enable", I get no username prompt but I do get a password prompt, however my pw no longer works.  Also the IP address of the AP (192.168.0.2=) is no longe rpingable. 
 
I did save the log of the console session for the (failed??) firmware upgrade process - the only odd thing I recall was that it seemed like it was trying to enter part of the update process commands but instead the router was interpreting them as a DNS lookup or something.  Kind of stupid process it seems but anyway I am quite lost.  Don't know what it'ssuch a challenge to update firmware.

View 9 Replies View Related

Cisco Switching/Routing :: 2601X / NAT Translations DHCP And Access To Internal Servers

Jan 19, 2013

I'm using a 2601X router connecting to a broadband connections.  The following NAT connections is working but I need to do NAT exemptions to set up my VPN appliance on the DMZ.  I see a lot of documentation on how to use a pool of public addresses to do that, but I only have the one dhcp address from my isp. 

!
boot system flash:c2600-adventerprisek9-mz.124-25d.bin
!
!
!
interface FastEthernet0/0

[code]....

View 5 Replies View Related

Cisco WAN :: 2821 / When Web Server NAT 'd Access From Internal LAN

Mar 26, 2012

For a config on a 2821 router with IOS 15.1?I've setup an internal web server and am able to acccess it from outside our network but not from inside (on a separate internal LAN - 192.168.10.0).  When on the internal LAN - DNS points to the Public IP for the web server - so we'd need to route through the Public IP to access the web server. 
 
What is the best way to allow access to the web server XX.XX.XX.231 from 192.168.10.0 network?
  
Related Config Lines to Allow Access to Web Server
NAT
ip nat inside source static tcp 192.168.1.230 80 XX.XX.XX.231 80 extendable
ip nat inside source static tcp 192.168.1.230 443 XX.XX.XX.231 443 extendable
 ACL
ip access-list extended WAN
permit tcp any host XX.XX.XX.231 eq 443
permit tcp any host XX.XX.XX.231 eq www

[code]....

View 2 Replies View Related

Cisco Firewall :: ASA 5505 8.4(2) Allow User To Access Internal Www Server?

Aug 2, 2011

I tried the solution posted at [URL] however it did not work on my ASA5505 8.4(2). I thought that it may be because I only have a single public address so the web server is responding to port forwarding through the one public IP already. looking in ASDM it appears to indicate that a configured access list is blocking the server from responding to the internal hosts.
 
object network Private_IP
host 192.168.1.15
object network Public_IP
host 1.1.1.1
object-group network internal_net

[code]....
 
Can I fix an access list (or something) to make this work or am I wishing for too much with only one public IP? This worked by default on my Netgear firewall.

View 4 Replies View Related

Cisco Firewall :: 5520 Can't Access Internal Web Server From Outside Network

Aug 23, 2011

I am using ASA 5520 with 8.2.4 IOS. I'm new to ASA/Firewall. I need to do access webserver from outside network.From Laptop (192.168.2.51), If I connect to url... it should open page from 10.10.10.50.I also need to ssh to webserver from laptop. If I ssh to 192.168.2.50 from laptop, it should connect to 10. 10. 10.50. [code]I can't get to webserver from outside network, so now, I connected laptop to directly ASA 5520 outside port with crossover cable.ASA Inside port connects to L3 switch. Webserver also connects to L3 switch. But still doesn't work.

View 9 Replies View Related

Cisco VPN :: 2811 - Static NAT Causes Unable To Access Server Via Internal IP

Nov 22, 2011

I running site-to-site IPsec VPN in Cisco 2811 IOS 12.4 both site. Here I encounter a problem to access server on  Site A from Site B
 
Site A having Leased Line connected to router with Public IP. I have done static mapping 1 web server to Public IP (NAT). This to allow external users to access the server via Public IP. At the same time, users at Site B would need to access to same server via Internal IP since they have Site-to-Site VPN established. But once I done Static Mapping (NAT), user at Site B unable to access the server at Site A using its internal IP. But external user can access server via Public IP. What went wrong here. Do i need to add extra command to get this done?

View 3 Replies View Related

Cisco Firewall :: 3391 / 3389 - PIX Config For RDP Access To Internal Server?

Aug 21, 2011

It's been a while since I've done a lot with a PIX config so what is the best way to allow access for 2 IP addresses that need to RDP into a server here inside our network. They also wanted to have ports redirected, 3391 to 3389 and 3397 to 3389.

View 12 Replies View Related

Linksys Wireless Router :: WRT54GS Can't Access Any Internal Server?

Sep 13, 2012

I had an Linksys WRT54GS and this wireless is connected to a switch in an internal enviroment but i want connect guest users without them see my internal network and can't access to any internal server....how can i configure this?

View 1 Replies View Related

Linksys Wired Router :: Static Route To Access TMG Internal Network Through RV042 Pptp Server?

Mar 20, 2012

Currently i am having a scenario where i have setup RV042 and which is connected to Microsoft Forefront 2010. PPTP works fine only on rv042 subnet but i am not able to access the "internal" network of TMG.RV042 (172.16.1.1) ---> TMG [external] (172.16.1.2) ---> TMG [internal] (192.168.1.1) Is there any way through static route to access the TMG internal network through RV042 pptp server?

View 1 Replies View Related

Cisco Switching/Routing :: 1921 VLAN Routing

Aug 1, 2012

I will be installing two Cisco 1921 Routers to connnect a T1 between two offices.  We are changing out our current AdTran routers as we would like to bridge three VLAN's across the T1 link.  I followed the instructions at (URL) shtml to the best of my ability and my two Gigabit Ethernet ports are tied into a bridged virtual interface (BVI1).  I then assigned a IP to BVI1 and another to my Serial0/0/0 then made a route to get to the other side of the T1 and a defualt route out our proxy. What I want to do now is setup QoS to make sure my voice data gets priority. 

I setup a QoS ACL called "Voice" with the TCP and UDP source and destination ports that our phone system uses.  I then setup a QoS policy on the Serial0/0/0 outgoing interface called "VoiceTraffic" and under the "match" list I match DSCP 46 or my "Voice" access rule.  For the action I turned on "Queuing" and set it up for LLQ at 50%.  Does this sound about right?  Is there anything els eI can setup?  I tried ot setup something else on the ethernet side but because they have the BVI I can't.  I read some article sin this forum that said I could still apply QoS to the GigabitEthernet ports even if they are in the bridge group but it doens't let me do that.

View 10 Replies View Related

Cisco Switching/Routing :: 1921 How To Set Password

Jan 24, 2013

How do I set a password? new Cisco 2911 router, C1900 Software (C1900-UNIVERSALK9-M), Version 15.1(4)M4 ?

View 6 Replies View Related

Cisco Switching/Routing :: 1921 Can't Go Any Further To Internet

Apr 30, 2012

I am setting up a new 1921 for a public library and I am running  into a problem and I bet I am missing something simple. All the internal stuff works and I can ping the outside IP on the 1921 but can't go any further to the internet. The 1921 has the 2 gig ethernet ports, 0/0 is connected to a DSL getting DHCP settings fine from the DSL modem. The other gig ethernet port 0/1 is running the inside network and its function fine, I have a server on it and other clients and they can ping and get dhcp settings etc.I've pasted the config output below and IP addresses of the main actors. [code]

View 1 Replies View Related

Cisco Switching/Routing :: Upgrade IOS From 1921 ISR?

Dec 18, 2012

How I can upgrade the iOS from CISCO 1921 ISR? Without losing my configurations.

View 3 Replies View Related

Cisco Switching/Routing :: ISR 1921 - IP SLA Tracking

Oct 5, 2012

I have already ordered a Cisco ISR 1921/K9.    but as i read on Cisco website, it is written that Cisco 1921/K9 only support  (IP SLA Responder) feature.
 
I don't know actually what is sla- responder.  but our requirement is we will connect that Router 1921/K9  into 2-ISP links and i want to enable  IP- SLA probes on that router so that it can track  both the routes into those isp links. so my question is  does  CISCO 1921/K9  have the support for what i need ?How about  Cisco 1921-SEC/K9 ?

View 1 Replies View Related

Cisco Switching/Routing :: Getting 2509 Access Server Configuration?

Jul 24, 2012

I am trying to connect my Access Server to my main network via the AUI port and I am not able to ping any device..

Current Config:
 
Access_Server#show run
Building configuration... 
Current configuration : 1113 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption

[code].....

View 14 Replies View Related

Cisco Switching/Routing :: 1841 - Access To Web Server On Outside Address From LAN

Jan 22, 2012

I have a 1841 deployed as my NAT device towards internet. NAT is setup so that internal addresses can access WWW. I also have some NAT translations opening speciic ports from outside to inside in the form: ip nat inside source static tcp A.B.C.D 443 A.B.C.D 443 extendable.
 
Now have an outside address/port setup with a public DNS reference and using NAT from outside to get access to the corresponding inside address. It works when being outside the LAN.
 
Now to the problem: From the LAN side of the router - i cannot access the public name. I can ping it - but my browser dont find the webserver behind the name. Someone told me it should be setup as "local firewall domain" - and i should set this up as "source NAT".

View 12 Replies View Related

Cisco Switching/Routing :: L2 Bridge On 1921 Interface?

Nov 20, 2012

I need to set up a L2 llink between my LAN and this 1921 router. I though IRB would do it but its not working yet. Here is the topology- I dont want to see another hop on this 1921 rtr so I hope I can just trunk it or something with IRB. Not working.

View 6 Replies View Related

Cisco Switching/Routing :: 1921 Router LAN Configuration

Mar 27, 2012

I have recently configured a cisco 1921 router for internal routing on my network.  Here is what i am trying to accomplish:
 
Main network 10.65.1.0   mask 255.255.255.0- all office devies and computers.
Second network 10.65.2.0  mask 255.255.255.0 - All plant equipment machinery and production lines
 
i have configure gig 0/0 for my company network and gig 0/1 for my plant network.  I can ping the router from both networks but am unable to route traffic betwenn them.  what am i missing?

View 8 Replies View Related

Cisco Switching/Routing :: Using 1921 With Watchguard Firebox?

Dec 6, 2012

Im having some major issues with my new setup.  I have a Cisco Router (1921ISR) that is connected to the internet through a t1. In addition to that is another cable modem.  Each of these are connected to my firebox through an external interface.My router is on the 10.1.10.X network.  My internal network is 192.168.1.X I have several NAT statements on my router pointing to 10.1.10.X addresses.  These addresses are defined on my firebox as seconday external addresses and I am SNAT'ing them to 192.168.1.X addresses on my local LAN.This is mostly working well for everything.  However, there is an FTP I am connecting to through the a VPN on the cisco that will not connect.  The source is a 192.168.1.X address. 

View 1 Replies View Related

Cisco Switching/Routing :: 3750 / Access A Target Server With IP Address 10.2.2.13?

Oct 16, 2012

Today when we run one applcation to access a target server with IP address 10.2.2.13, the application cannot run through and appearing error message related networking.The target server has two network ports whereby another one with IP 10.2.2.14 is running OK with the same application. All these two connections are connected to the same Cisco switch 3750, after the switch then go to Cisco ASA firewall which has no access control rule for this 10.2.2.13 and its subnet, and then the firewall connect directly to the application server.We can ping, remote desktop access and telent port for the application to the target server by using 10.2.2.13.We swapped the cable connection of the ports from one another and try the application again, the IP with 10.2.2.13 is still fail and IP with 10.2.2.14 is OK.We then change the IP from 10.2.2.13 to 10.2.2.12 or 10.2.2.155, all are OK. We changed back to 10.2.2.13, it is failed again.The switch is in running real time production and so we cannot power cycle or reload the switch.

View 9 Replies View Related

Cisco Switching/Routing :: 4500 DHCP Server On Access Port

Apr 24, 2011

On a 4500 switch port , defined as access vlan 10, if the user connects his own dhcp server ( instead of the normal pc that should be connected ), will it cause issues with my existing network. the existing network is all static ip. In above case, will the dhcp server start looking out and assign dhcp ip's , if a user unknowingly removes his static ip and changes to obtain ip via dhcp option on the lan properties.

View 10 Replies View Related

Cisco Switching/Routing :: Catalyst 3560 Can't Access Radius-server In Vrf

Aug 23, 2012

My configuration:          
    
radius-server host 10.138.44.57 auth-port 1645 acct-port 1646 key 7 ******
!
aaa new-model
!
aaa authentication dot1x default group radius local

[code]....

View 2 Replies View Related

Cisco Switching/Routing :: Unable To Configure Access Server On 2509

Mar 26, 2012

I am having trouble trying to configure my cisco 2509 cisco router for access server.  I have two guides shown below: URL and URL
 
However I am running into some problems.  I can go through the second guide up until it asks me to do this command
 
Step 5: Configure the transport input protocol on the async lines to Telnet.
Access_Server(config-line)#transport input telnet
 
I cannot put in Transport Input,  I only have the option of doing Transport Output let me show some lines from my console:
 
---------------------------
Access_Server(config)#line 0 14Access_Server(config-line)#no execAccess_Server(config-line)#transport input ?% Unrecognized commandAccess_Server(config-line)#transport ?  output     Define which protocols to use for outgoing connections  preferred  Specify the preferred protocol to use
Access_Server(config-line)#transport
------------------------
 
Im not sure whats going on.   I have two routers(cisco 2600 series) plus my 2509 cisco router I am going to use for a access server.  I have a two switches 2950 series and I have the access server connected to all of them via a octal cable.
 
Here is the configuration from the access server:
 
--------------------------------------
Cisco Internetwork Operating System Software
IOS (tm) 2500 Software (C2500-IS-L), Version 12.3(26), RELEASE SOFTWARE (fc2)
Technical Support: [URL]
Copyright (c) 1986-2008 by cisco Systems, Inc.
Compiled Mon 17-Mar-08 14:39 by dchih
cisco 2509 (68030) processor (revision M) with 14336K/2048K bytes of memory.
Processor board ID 22840809, with hardware revision 00000000
Bridging software.

View 7 Replies View Related

Cisco Switching/Routing :: Cannot Access Server Or Ping On WS-X6708-10GE

May 2, 2012

Connected server on a  tenGigabitEthernet interface simple configuration setup

switchport
switchport access vlan 201
end
 
for server connection.  Connected with Fibre. The interface is up and up but cannot ping server?

View 10 Replies View Related

Cisco Switching/Routing :: 4500 - Dhcp Server On Access Port

Dec 24, 2011

On a 4500 switch port , defined as access vlan 10, if the user connects his own dhcp server ( instead of the normal pc that should be connected ), will it cause issues with my existing network. the existing network is all static ip. In above case, will the dhcp server start looking out and assign dhcp ip's , if a user unknowingly removes his static ip and changes to obtain ip via dhcp option on the lan properties.

View 1 Replies View Related

Cisco Switching/Routing :: 1921 To Replace A Software Firewall

Feb 26, 2013

We purchased a cisco 1921 router to replace a software firwall not long ago. The router was sold as a firewall with the suggestion that an ASA would be unnecessary.Unfortunately a router does not replace/do the jobs a firewall does, so I looked online and noticed that Cisco do offer firweall security features in one of their IOS.How do I tell if this is implemented on my router?If not, does my IOS support this, or do I need to buy an extension/another version of the IOS?,The version of the IOS I have is: c1900-universalk9-mz.SPA.151-4.M4.bin.

View 3 Replies View Related

Cisco Switching/Routing :: 1921 LAN Adapter Unable To Reach Outside

Apr 2, 2012

The Cisco 1921 router has two routed adapters. One is GE0/0 which I am using for my WAN interface. It is working properly. The 2nd interface is GE0/1 which is being used as my internal adapter. It is running NAT. When I attempt to reach the internet it fails while checking the exit interface. Here is the report.
 
AttributeValueRouter ModelCISCO1921/K9Image Namec1900-universalk9-mz.SPA.151-3.T.binIOS Version15.1(3)THostnameBulldog 
Interface Details   
AttributeValueInterfaceGigabitEthernet0/1IP address192.168.1.1DescriptionNOC Link Test Activity Summary

[Code].....

View 1 Replies View Related

Cisco Switching/Routing :: 1921 - Can't Login To Brand New Router

Nov 29, 2012

I have a brand new 1921 router that I can't login to using cisco/cisco.  Is there a new password?
 
[URL]
 
I don't have physical access so I can't reboot it until Monday.  Just wanted to get it working today. 

View 8 Replies View Related

Cisco Switching/Routing :: Decipher Differences Between Two Models Of 1921?

Mar 7, 2013

I am trying to decipher the differences between the two models of the 1921 router. One has an IP Base IOS and the other has a Security IOS. I have an ASA so I don't think I need all the Security IOS bells and whistles on an internal router. Although, does the IP Base IOS allow for trunking and sub interfaces? I definitely need that and on CDW's website it says that the 1921-Sec/K9 w/ Security IOS includes 802.1Q and that spec is not listed on the 1921/K9 IP Base IOS model.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved