Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Can not ping our router. Can ping internal network??

Status
Not open for further replies.

69DVINE

Technical User
Feb 23, 2005
5
US
We have an old Nortel 1500 Contivity switch. We currently use it to VPN to a client. I simply want to set this up so that a specific IP address can go out to the Internet. The Nortel box has a router but I can not ping the router. There is no Firewall set up on the box. Can I do this??
 
You want the Contivity to be a IP router ?
If you want to do this you need to turn on interface filter.

And if you want it to be a router both interfaces neeed to be set to private.

But the best way is to turn on interface filter and enable a NAT rule.

 
No. I am sorry. What I have is a nortel 1500 contivity switch. the switch is conected to a cisco 675 router. I can ping everything that is on our network but I can not ping the cisco router. We do not have the firewall software set up on the nortel so i did not think that the filtering was working. I try and run a trace but it never makes it out of the nortel. I know the router is working because we have a tunnel on the nortel that is up and running.

Question is why am I being blocked.
 
Is the ciso 675 on the public or private side ?

Cisco is you internet router ?


You try to ping the cisco from public or private side ?
 
The cisco is on the public side. I have tried pinging from the private side (My PC) and it timeout. I tried pinging from the nortel box using the tools ping diagnostic utility and it says "No Answer from IPADDRESS". From the Nortel box I can ping any address on the private side awith a response. Just when I try to go out to anything on the outside of the Nortel Box??
 
Oki.. Then you need to set up a NAT rule in the Contivity, and enable interface filter. (you don't need licens for this)
Services- FW/NAT. enable NAT and Interface filter. -- Reboot.

Change the filter on the interface if it setup to be deny all, and create a pool nat.


The Contivity is not set default up to be a router.
 
I enabled Contivity Firewall, Contivity Filter, and Nat Interface. I rebooted. I set up a new Nat Configuration. Set it to Pooled. Set the Internal Start Address to my PC IP .151 to .151. I then set the External Range to what my Cisco Router address is .30 to .30. I looked under profiles, filters and made sure that Dey all did not have any rules associated with it. I also made sure that we are permitting HTTP in and out.

I tried pinging from my PC .151 to the Router .30 and timed out. I tried pinging from the Nortel Box to .30 and still no response??

Any other ideas???

Thanks
 
You have to set det External Range to be the public interface on the contivity.
 
The nortel box is .26 from the outside. I set the Start and ending address to be .26 to .26 I rebooted and still can not ping to the router of .30.

Is the default to the firewall closed to all traffic by default unless you open it up by filter. Or is the firewall Open to everything unless you Close it by filters??
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top