Cisco WAN :: 1841 - No Internet Access Via LAN Clients

Apr 27, 2012

I have a Cisco 1841 router that is connected to a switch. I have WAN/LAN configured on the router and the switch is handing out internal IP's. The issus that none of the client machines can access the Internet. From within the router console, I am able to ping external domain names, my ISP DNS servers.
 
Once the client machines picks up an IP they are unable to ping any external domain names or IP's and not even the ISP DNS servers, but they can ping the Cisco router IP. As a note I have tried my ISP DNS servers and as a test Google's DNS servers, but neither will allow access to the Internet.
 
Below is the current running config:
 
Building configuration...
 
Current configuration : 1440 bytes
!
version 12.4
service timestamps debug datetime msec

[Code].....

View 26 Replies


ADVERTISEMENT

Cisco VPN :: 1841 Cannot Access PCs If Internet Is Enabled

Apr 28, 2013

I have a branch office connected to the Head Office through a VPN Tunnel in cisco 1841 Router. If i enable Internet for any pc in Branch Office through cisco router i cannot access it remotely from Head Office. [code]

View 2 Replies View Related

Cisco Switching/Routing :: 1841 / HWIC-AP-AG-A Not Providing IP Address To Clients

Dec 5, 2012

I have not yet completed my CCNA, however I have managed to configure a 1841 router with 1 x HWIC-ADSL1 and it also has 1 x HWIC-AG-AP-A which is the only part I am unable to get working.
 
The Wi-Fi (Dot11Radio) config has enabled me to see the SSID from wireless devices, but they never get an IP address. I need them to get the same IP range as the DHCP service I have in there 203.35.10.xxx, there is no option for "IP ADDRESS DHCP" only "IP ADDRESS POOL LAN" Lan is of course my DHCP pool name. however I cannot have the same DHCP pool on both Dot11Radio interfaces.
 
I know I'm missing one very simple command, but as I've never worked with Radio on Cisco equipment, I am unsure how to fix it.
 
Then once I get that worked out, I need changing the access from OPEN to WPA or WPA2, etc..
 
IOS Software on Router is C1841-ADVSECURITYK9-M - Version 12.4(9) T
 
I can upgrade to a better version of software if needed, I only have a 32mb Flash and 128Mb Ram.
 
The current Radio Config is:
 
!
interface Dot11Radio0/1/0
no ip address
no ip redirects

[Code]....

View 1 Replies View Related

Cisco Switching/Routing :: 1841 Vlan 5 Cannot Access Internet

Oct 31, 2012

i have router 1841 have 2 interface.i make routing between vlan  by subinterface in router and in switch trunk but vlan 5 cannot access internet

View 3 Replies View Related

Cisco VPN :: ASA 5510 / 1841 - How To Configure Local Network To Access Internet

Jun 10, 2011

I configure for our office site to site VPN project. Now I configured already  Site to site vpn between ASA 5510 and 1841 router.               

HQ LAN                              
Branch LAN   10.2.1.0/24 >>> ASA 5510>>>>> 1841 >>> INTERNET <<<<<< 1841 <<<<<< 10.30.3.0/24 ^^^^ Call Manager 2851 

Now can access from Branch LAN to HQ LAN each other. I face the problems that are 

1) In branch LAN , they can access HQ LAN & resource , but cannot access internet. I didn't configure NAT on PH Router

2)  Can I access internet from BRANCH LAN through HQ LAN to INTERNET. Or  Can I access Internet from Branch LAN from PH Router directly while  access to VPN to HQ LAN ?  

3)  In Branch Site , hard phone cannot work but soft phone on PC can call to HQ. Hard phone IP are same in Remote Network (172.16.1.0/24 ) . Is it problem ? how can I configure separately ?

View 2 Replies View Related

Cisco WAN :: QOS On 1841 With Access Lists?

Jan 15, 2013

I have new DIA Internet service coming in and unlike the last vendor who provided a router, I am configuring my own.  This is my first full Cisco config - I've been looking at this for 3 days now.  I have SIP signalling, rtp and default traffic on a (3) t1 multilink (4.5mb).   My lan and firewall uses dscp tags and passes them to the 1841 for outbound.  The ISP only prioritizes by destination address so I just need the 1841 to respect the tags internally.  Inbound, I have only port numbers to go by to differentiate voice traffic and I want to tag EF and CS3 accordingly for use by the 1841 and the rest of my network. 

Below is part of my proposed config.   I have read tons of Cisco docs and looked at all the queuing methods and this one I understand the best.  I am getting the error: "CBWFQ : Can be enabled as an output feature only", so I presume that something is wrong on an input definition somewhere.  For now all the firewall functions are done at the actual firewall (Sonicwall NSA) so other than limiting ports to the PBX everything else is just pass-through.  Any changes required. IOS is 12.4(4)T1.

[Code]....

View 6 Replies View Related

Cisco Firewall :: Cannot Access To DMZ From Vpn Clients ASA 5505 V 9.1(1)

Dec 31, 2012

ASA Version 9.1(1)
!
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6

[Code]....

View 9 Replies View Related

Cisco VPN :: 5510 VPN Clients Can't Access DMZ Network

Mar 22, 2012

The title says VPN clients cannot access DMZ network, but that is not exactly the problem, the situation is this, a group of users are using an actual 10.x network where they have their servers and pretty much everything. The users must be relocated into a new network, the 172.16.x.  In a point in time they will not have to use 10.x anymore, but meanwhile, they need access to that network.

I have an ASA 5510 as default gateway for the new network (172.16.x.x), one interface e0/0 connected to the outside (internet), interface e0/1 to the inside and other interface connected to the actual 10.x (which I call DMZ), so basically I am using the ASA as a bridge using NAT to grant access to the users in the network 172.16.x to the resources in the 10.x network while the migration is completed.

All the users must use the path to the internet thru the ASA using the NAT overload to the outside interface and I put in place a NAT policy to 10.x to allow access to the 10.x network only when the internal users 172.16.x try to reach that path and so far, everything is working just fine for the internal users.Now for some reason, when I do VPN, the VPN clients cannot reach the 10.x network, even when they are supposed to be in the internal network (because they are doing VPN right?) .

I have enabled split tunneling with NAT exempt the 172.16 network and I am not sure if that is causing the problem, because when I trace from my PC the 172.16.16.1 address using the VPN I get the proper route path, but when I try to reach 10.x, my PC is using its default gateway and not the VPN gateway which has a route to 10.x.

I’m not even sure if what I am trying to do is possible, I want VPN users to be able to access a 10.x network using NAT overload with the Interface of the ASA plugged to the 10.x network, just like the internal users are doing right now.

View 1 Replies View Related

Cisco VPN :: 891 - Clients Cannot Access Remote Site

Dec 12, 2012

I have 2 site here:
 
site A
 
Cisco 891
external IP: 195.xxx.yyy.zzz
VPN Gateway for Remote users

[Code]....

View 1 Replies View Related

Cisco VPN :: ASA 5505 VPN Clients Can't Ping Router Or Other Clients On Network

Jun 18, 2012

I have a ASA5505 and it has a vpn set up. The VPN user connects using the Cisco VPN client. They can connect fine (the get an ip address from the ASA), but they can't ping the asa or any clients on the network. Here is the running config:
 
Result of the command: "show running-config"
 
: Saved
:
ASA Version 7.2(4)
!
hostname ASA
domain-name default.domain.invalid
 
[code].....

what I need to add to get the vpn client to be able to ping the router and clients?

View 3 Replies View Related

Cisco VPN :: 5520 / 5510 - Can VPN Clients Communicate With Other Dynamic Clients

Nov 5, 2012

We currently have an ASA 5520 communicating with 10 ASA 5510's, all on static outside addresses.  I was asked to add 5 additional 5510's on dynamic address.  All worked well in testing until it was decided that some of the dynamic clients needed to talk to each other.

My testing shows packets just dying in the 5520.

View 1 Replies View Related

Cisco VPN :: 1841 Connected But No Access To External LAN

Mar 12, 2012

my configuration of Cisco 1841.
 
I was able to configure the cisco to accept VPN connections from clients. But when i am connected i can not access the VPN LAN. My cisco VPN client shows all the time Packet Decrypted: 0 when connected. I tried the split tunneling configuration based on the example on cisco.com for split tunneling.
  
I include config for better understanding. The outside interface is fa0/1 with ip 10.0.0.2 w LAN 10.0.0.0 Inside interface fa0/0 with ip 192.168.10.9 w LAN is 192.168.10.0
 
IP for VPN clients 192.168.20.100 - 105

View 5 Replies View Related

Cisco WAN :: Simultaneous Dual Wan Access With Nat 1841

Mar 25, 2012

I have a 1841 router with two wan access from two different ISP:throught dialer with fixed ip obtained from dhcp - ATM interface,thought fastethernet 0/1 with fixed ip and a specific gateway - can be use for Internet traffic if dialer is down.I can't manage to make them accessible at the same time (ping and ssh).In a second time I would like to have a VPN client access on one wan and site to site VPN on the other, instead of having the two on one wan.

View 12 Replies View Related

Cisco WAN :: 1841 Can't Access Network Resources

Nov 26, 2012

I'm working on setting up a couple of new WAN sites with 256K frame relay circuits back to our main building.  Each new site has a new PVC, and both are pointing back to a PVC on a T1 at the main building.  The main site has a 2801 with a single CSU/DSU WIC, and each new site has a 1841 with a 3560 connected to fa0/1.  At both sites, I'm able to get the circuit up, and the serial interfaces at both new sites show up/up, and the subinterfaces at the main site also show up/up for both sites.  Routing is being done by EIGRP, and both sites are able to establish the 2801 as an EIGRP neighbor, and I'm able to ping/tracert anywhere on our network by name or IP, so routing and DNS appear to be working.  I can also ping both new routers from the main site.  However, that's about all I can do.  I'm not able to access any resources on our network (email/shares/internet/intranet/etc) from the two new sites.  I can ping the new routers/switches from the main site, but can't ssh to them.  I can ssh to them locally.  There are no firewalls in the equation, and I don't think there are any ACL's in the picture either. 
 
Can ping and tracert just fine anywhere on our network (from both the 1841, a PC plugged into the 3560, or a PC plugged directly into the fa0/1 port on the 1841), including  out to the internet, by name or ip.Can ssh to local router, but not to anything that isn't localDNS is workingDHCP not working using  ip helper pointing to DHCP scope on server at main site, have to use static IPCan't rdp to anythingCan't get emailCan't browse windows  sharesCan't get to any websites, external or intranet.  IE says "Website found, waiting for reply..." but eventually times out.  
 
I did some testing for communication over certain port numbers using telnet and nmap, and found the following:
 
Can telnet to url.. and local intranet webserver on port  80 (http)Can telnet to two of our Exchange Servers on port 25 (SMTP)If I run an nmap scan on url...com, or our intranet webserver, it confirms that 80 and 443 are open, but the pages will not load.  I am able to telnet (port 23) to a state mainframe via the internet that some of our employees use, and I do get the expected login screen.  I tried erasing the config one of the new routers, and just added back the bare minimum config to get the circuits up (serial/ethernet interface configs, eigrp), but saw the same symptoms. 
 
One other thing to note: the 2801 at the main site has three other frame relay sites connected to it on the same WIC as the new sites, all of which are working fine. 
 
I just don't understand why I can ping everywhere I need to be able to ping, and port scans show that communication is open over needed ports, but the applications don't work. 

View 1 Replies View Related

Cisco VPN :: 1841 Remote Access Not Working Right

May 27, 2011

I have setup a remote access on our 1841 device, with split tunnel.
 
now i am able to connect via the vpn tunnel, and even ping and telnet into the cisco device, but when i try to ping any device past the 1841, the ping fails and no traffic is even been encrypted to go over the vpn traffic (looking at the vpn client statistics).
 
From the ciscos side, pings to the vpn client is failing, yet i see the vpn client in the routing table. 

Here is my config: 
 
cisco1841#sh run Building configuration...
Current configuration : 7682 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecservice password-encryption!hostname cisco1841!boot-start-markerboot-end-marker!logging buffered 51200

[Code].....

View 4 Replies View Related

Cisco WAN :: 1841 - Cannot Access Configure Menu

Sep 11, 2011

I can not access the configure menu.
 
I try access with Serial cable blue DB09 / RJ45 on console port and serial ports on PC using putty or hyperterminal but any connection can not be done. The screen stay black and not show any text.
 
The computer found the port COM1 but i csn not access any information from Cisco router model 1841

View 1 Replies View Related

Cisco WAN :: 1841 With Virtual-Access Interface

Dec 22, 2010

I have a problem in my Cisco 1841 in Virtual-Access Interface  all interfaces is UP Except Virtual Access is Down . [code]
 
when i want recover the virtual access to up ,should i do shut & no shut to the ATM interface.What is the cause of the problem, and how I can solve this issue?

View 2 Replies View Related

Cisco VPN :: Asa 5510 Allow AnyConnect Clients Access To Only Few Servers

Jun 26, 2012

We have 30 remote workers which we have recently acquired which are being set up with the AnyConnect client to connect to our head end ASA 5510. For security purposes, we have to allow them access to only 3 of our local internal servers, all on our 10.10.X.X/16 subnet. The remotes are being issued a 10.10.50.X/24 address via DHCP on the ASA when connecting. I thought this would be as simple as creating an access list but have not had any luck doing so. In addition, we need to allow them full access to servers in a datacenter connected to our same head end ASA via a site-to-site VPN while they are connected to us using AnyConnect.

View 1 Replies View Related

Cisco :: Any Chance To Access Files On 4400 With Ssh Clients

Mar 18, 2011

Is there any chance to access files on 4400 with ssh (winscp etc.) clients ?
 
For example we upload webauth bundle and then we want to delete it and recopy another files..

View 4 Replies View Related

Cisco VPN :: PIX 525 VPN Clients Unable To Access LAN After Connection Is Made

Jan 9, 2011

I had an unusual circumstance come up on an older PIX 525 (6.3(5))
 
On a recent remote site visit we made a connection to our main office using ver 4.9 of the Cisco VPN Client for OS X. While we were working on a server, the macbook went to sleep shutting down the network interface the VPN Client was using.
 
From that point forward we were unable establish any layer 3 connectivity to the LAN in out main office using that PIX as a VPN head end. Any connections that were attempted to that firewall would complete and be assigned a client IP from the correct pool but without access to the LAN on the inside interface.
 
We tested this from multiple external locations using multiple systems, cleared SA's and even debugged IKE and IPSEC using an alternate connection method. There were no errors reported on the firewall but there was also no connectivity.

View 5 Replies View Related

Cisco VPN :: ASA 5510 - Allow AnyConnect Clients Access To Only Few Servers

Mar 19, 2012

We have 30 remote workers which we have recently acquired which are being set up with the AnyConnect client to connect to our head end ASA 5510. For security purposes, we have to allow them access to only 3 of our local internal servers, all on our 10.10.X.X/16 subnet. The remotes are being issued a 10.10.50.X/24 address via DHCP on the ASA when connecting. I thought this would be as simple as creating an access list but have not had any luck doing so. In addition, we need to allow them full access to servers in a datacenter connected to our same head end ASA via a site-to-site VPN while they are connected to us using AnyConnect.

View 4 Replies View Related

Cisco Firewall :: Pix 506E - Clients Do Not Access Some Websites?

Feb 27, 2012

I have a problem with PIX 506E that meets the version 6.1, and in an simple computer network equipment seems to behave in strange ways because some web sites do not open or very open slow thereby its operation impracticable. On the other hand other web sites open normally.
 
Querying the web site of the Cisco, I found several documents discussing the same problem but in a later version ( 7.0 ), not in this version 6.1.
 
I've tried removing the pix from the network , not the error occurred, again insert pix however tested only with a machine, without the rest of the network and the problem persists

View 13 Replies View Related

Cisco :: AP1240 / Clients Cannot Connect To Access Point

Apr 9, 2013

I have a AP1240 Cisco IOS Software, C1240 Software (C1240-K9W7-M), Version 12.4(10b)JDA3, RELEASE SOFTWARE (fc1), and want to configuration WPA2 without using Radius.But my clients can not connecto to AP. On AP always display messages "%DOT11-7-AUTH_FAILED: Station 0026.6609.e55d Authentication failed"
 
Here is my configuration:
 
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname AC1P1F08

[code]......

View 10 Replies View Related

Cisco VPN :: ASA 5510 - Clients Cannot Access Remote Site

Dec 12, 2011

I have 2 sites :

site A :
ASA 5510
VPN gateway for remote users
LAN 192.168.192.0/22
 site B :
ASA 5505
LAN 192.168.208.0/22
 
Both sites are connected through a site to site VPN.Remote clients (AnyConnect/VPN client) can connect to Site A LAN  and see machines on LAN A but cannot see Site B LAN.

Here is a part of my configuration :
 
On Site A (ASA 5510)
--------------------------------
name 192.168.192.0 SiteA_Internal_Network
name 192.168.208.0 SiteB_Internal_Network
name 192.168.133.0 VPNPool_AnyConnect
name 192.168.133.32 VPNPool_VpnClient

[code]....

View 9 Replies View Related

Cisco VPN :: ASA 5520 8.2(3) - Allow Remote Clients To Access Other Networks

Oct 24, 2012

I have an ASA 5520 8.2(3) and allowing my remote client-to-site-vpn clients to access resources directly connected to my ASA on separate lower security interfaces (not the outside) besides just clients on my internal networks.  Someone mentioned to me configuring 'VPN on a stick' however from what I've read this seems to be only applicable when it comes to split-tunneling back out the outside interface (could be off on that).  Is this possible on other lower security interfaces as well, and if so what would a mock config that accomplishes that look like (acl's, nat, etc)?  Also, if I want internal users to be able to connect to these remote clients once they are active, are there any nat statements necessary (such as nonatting them) or are the vpn clients just seen as internal clients from the rest of the internal network's standpoint by default?

View 5 Replies View Related

Cisco Wireless :: WLC2504 - Configure Clients To Access 802.1x?

Jul 4, 2012

configured Cisco 2504 WLC with 1142 Aps...  Guest wireless works fine
 
for the staff wireless I wanted to authenticate with 802.1x & Radius. So configured an external Radius server (Imprivata) and configured the 2504 Radius options for the extenal server.( Layer 2:  WPA2-AES & Auth Key Mgmt:  802.1x )
 
When I connect a client to this wireless, the authentication fails, I wonder whether it is because of the client side settings..
 
Which trusted Root Certification Authorities need to be checked?

View 3 Replies View Related

Most Wireless Clients Associate To One Access Point?

Feb 23, 2011

most of my wireless clients are associating to one ap when there are ap's closer. do i have some setting configured wrong on my controllers?

View 1 Replies View Related

Linksys Access Point :: Where I Can See Clients Associated To A WAP200E

Nov 7, 2011

Because of a connection problem, I would like to know where I can see the clients associated to a WAP200E AP and the signal level of each client.

View 1 Replies View Related

Routers / Switches :: Dlink DIR 615 Router - Wireless Clients Can't See Ethernet Clients

Feb 1, 2011

I have 4 desktops cat5 to Dlink DIR 615 router. All work fine. Any wireless clients, laptop or netbooks, see the desktop computers for a while then disconnect somehow. All machines can see the Internet through the router at all times. The desktops disappear from the laptop/netbooks but the wireless machines can be seen from the desktop computers but clicking on them gets 'Access Denied' message after a wait.3 desktops = XP, 1 98SE. All laptop/netbooks = XP

View 2 Replies View Related

Cisco Firewall :: ASA 5505 Anyconnect Clients Cannot Access Slingbox

Mar 27, 2012

I'm trying to configure an ASA 5505 to view my Slingbox from my iPhone/iPad from an outside or 3G network.  I can't ping my internal networks while connected via AnyConnect.  I know that I need to free up port 5001, but I can't seem to get it to work. 

View 0 Replies View Related

Cisco VPN :: ASA5515X - Remote Access VPN Clients / Multiple DNS Suffixes?

Dec 13, 2012

I am setting up a new remote access VPN using the traditional IPSec client via ASA 5515-X runnning OS 8.6.1(5). We require to provide each client multiple DNS suffixes, but are only to provide a single DNS suffix in the group policy.I have tested using an external DHCP server, but using our Windows Server 2008 infrastructure and Option 119 the list is not provided to clients, and I have read that Windows 7 clients may ignore this option anyway.

View 0 Replies View Related

Cisco VPN :: ASA5540 - AnyConnect Clients IP Address Access Rules?

Jul 1, 2012

I setup ASA5540 for SSL-VPN (clientless) works fine. But I try to use Client (AnyConnect) to access internal resources, it is failed.  It is stiil initiate sessions from remote client IP. I need to initiate session from client IP assigned by ASA5540 box (same with Cisco VPN client connect to Cat65 SVC module). How I setup it?

View 3 Replies View Related

Cisco VPN :: ASA 5505 - AnyConnect Clients Can't Access External Sites?

Jun 9, 2010

I'm looking to setup AnyConnect VPN with no split tunneling. ASA 5505 v8.2. It seems this should be really easy. I must be missing something.
 
I can get the AnyConnect users to connect fine and they can access sites internal and at other IPSec-tunneled sites. But no access to the internet.
 
Internal is 10.1.1.x, VPN pool is 10.1.1.251-253 (Temp list for testing). I issued the following tracer: packet-tracer input outside tcp 10.1.1.253 12345 69.147.125.65 80 detailed
 
The last reported point (where it fails) is:
  
Phase: 7
Type: WEBVPN-SVC
Subtype: in

[Code].....

View 10 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved