Hello all! My first post here. I have used these forums through google many times. On to my question.
I am upgrading from a T1 to a 20mb Metro Ethernet circuit for Internet that is unmanaged. I have a Cisco 2921 that I am using. I am setting up the router now. AT&T gave me three IP address: Serial, AT&T, and Customer IP. I assume the Customer IP is the IP for my interface facing the internet and the AT&T IP will be my default route. I am not sure what the Serial IP is for. They also gave me a block of LanIPs that are /28. So I assume this will be my static IPs (which I requested at least 10). After setting up a test config I could ping to the internet from the router but I could not access the internet from my PC (hooked directly to the router). So I thought maybe I need to set up NAT on the router. My question is, if I set up NAT will I be able to get to the internal addresses from the internet? I have not tested NAT on it yet as I wanted to post this question before disconnecting myself to test. Here is my config:
version 15.0
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname FMC
logging buffered 51200 warnings
no aaa new-model
no ipv6 cef
ip source-route
ip cef
ip domain name yourdomain.com
ip name-server
multilink bundle-name authenticated
crypto pki trustpoint TP-self-signed-
(cut out all the crypto stuff)
interface GigabitEthernet0/0
description Internet
ip address
ip nat outside
ip virtual-reassembly
duplex full
speed 100
interface GigabitEthernet0/1
description EthernetLAN
ip address
ip nat inside
ip virtual-reassembly
duplex full
speed 100
interface GigabitEthernet0/2
no ip address
duplex auto
speed auto
ip forward-protocol nd
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip route
access-list 23 permit
line con 0
login local
line aux 0
line vty 0 4
access-class 23 in
privilege level 15
login local
transport input telnet ssh
line vty 5 15
access-class 23 in
privilege level 15
login local
transport input telnet ssh
scheduler allocate 20000 1000
I am upgrading from a T1 to a 20mb Metro Ethernet circuit for Internet that is unmanaged. I have a Cisco 2921 that I am using. I am setting up the router now. AT&T gave me three IP address: Serial, AT&T, and Customer IP. I assume the Customer IP is the IP for my interface facing the internet and the AT&T IP will be my default route. I am not sure what the Serial IP is for. They also gave me a block of LanIPs that are /28. So I assume this will be my static IPs (which I requested at least 10). After setting up a test config I could ping to the internet from the router but I could not access the internet from my PC (hooked directly to the router). So I thought maybe I need to set up NAT on the router. My question is, if I set up NAT will I be able to get to the internal addresses from the internet? I have not tested NAT on it yet as I wanted to post this question before disconnecting myself to test. Here is my config:
version 15.0
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname FMC
logging buffered 51200 warnings
no aaa new-model
no ipv6 cef
ip source-route
ip cef
ip domain name yourdomain.com
ip name-server
multilink bundle-name authenticated
crypto pki trustpoint TP-self-signed-
(cut out all the crypto stuff)
interface GigabitEthernet0/0
description Internet
ip address
ip nat outside
ip virtual-reassembly
duplex full
speed 100
interface GigabitEthernet0/1
description EthernetLAN
ip address
ip nat inside
ip virtual-reassembly
duplex full
speed 100
interface GigabitEthernet0/2
no ip address
duplex auto
speed auto
ip forward-protocol nd
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip route
access-list 23 permit
line con 0
login local
line aux 0
line vty 0 4
access-class 23 in
privilege level 15
login local
transport input telnet ssh
line vty 5 15
access-class 23 in
privilege level 15
login local
transport input telnet ssh
scheduler allocate 20000 1000