we are in the process of installing a wireless network within our conference and learning center. We want to have 1 vlan for guests and 1 for staff. I can do that with the aironet 1231's we have since it has vlan capabilities and filter to go with those vlans. thanks to another thread I created I was helped along by some of you and have now created two vlans on my 3com switches vlan 1 which will be the native one and vlan 2 the guest one. I am now trying to configure my router to let vlan 2 have internet access. my current router setup is that interface 0/0 is connected to internet feed and 0/1 is connected to our internal network. my current config is as follows. the internal interface does have 2 ip addresses on it. The 204.186 subnets on the internal and external interfaces are different. I am also getting rid of ipx, thus no ipx commands in the proposed config. also i am using the follow for nat
ip nat inside source list 5 interface FastEthernet0/0 overload
current config:
interface FastEthernet0/0
description external network
ip address 204.186.x.x 255.255.255.252
ip access-group 120 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
speed 100
half-duplex
no cdp enable
no mop enabled
!
interface FastEthernet0/1
description internal network
ip address 204.186.x.x 255.255.255.0 secondary
ip address 10.0.0.1 255.0.0.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
speed 100
half-duplex
appletalk cable-range 1-10 9.176
appletalk zone ANNEX
appletalk zone FIRST FLOOR
appletalk zone SECOND FLOOR
appletalk zone itec center
appletalk zone third floor
ipx network 92C9F053 encapsulation 802.1Q vLAN
ipx type-20-propagation
no cdp enable
no mop enabled
proposed config:
inter f0/0 stays the same
interface FastEthernet0/1
no ip address
interface fastethernet 0/1.1
description internal network vlan id 1
encapsulation dot1q 1 native
ip address 204.186.x.x 255.255.255.0 secondary
ip address 10.0.0.1 255.0.0.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
speed 100
half-duplex
appletalk cable-range 1-10 9.176
appletalk zone ANNEX
appletalk zone FIRST FLOOR
appletalk zone SECOND FLOOR
appletalk zone itec center
appletalk zone third floor
no cdp enable
no mop enabled
interface fastethernet 0/1.2
description internal network vlan id 2
encapsulation dot1q 2
ip address 192.168.3.1 255.255.255.0
no ip redirects
ip nat inside
is this close?
thanks for your help
ip nat inside source list 5 interface FastEthernet0/0 overload
current config:
interface FastEthernet0/0
description external network
ip address 204.186.x.x 255.255.255.252
ip access-group 120 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
speed 100
half-duplex
no cdp enable
no mop enabled
!
interface FastEthernet0/1
description internal network
ip address 204.186.x.x 255.255.255.0 secondary
ip address 10.0.0.1 255.0.0.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
speed 100
half-duplex
appletalk cable-range 1-10 9.176
appletalk zone ANNEX
appletalk zone FIRST FLOOR
appletalk zone SECOND FLOOR
appletalk zone itec center
appletalk zone third floor
ipx network 92C9F053 encapsulation 802.1Q vLAN
ipx type-20-propagation
no cdp enable
no mop enabled
proposed config:
inter f0/0 stays the same
interface FastEthernet0/1
no ip address
interface fastethernet 0/1.1
description internal network vlan id 1
encapsulation dot1q 1 native
ip address 204.186.x.x 255.255.255.0 secondary
ip address 10.0.0.1 255.0.0.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
speed 100
half-duplex
appletalk cable-range 1-10 9.176
appletalk zone ANNEX
appletalk zone FIRST FLOOR
appletalk zone SECOND FLOOR
appletalk zone itec center
appletalk zone third floor
no cdp enable
no mop enabled
interface fastethernet 0/1.2
description internal network vlan id 2
encapsulation dot1q 2
ip address 192.168.3.1 255.255.255.0
no ip redirects
ip nat inside
is this close?
thanks for your help