<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [help] 851W and ISP DHCP in Cisco</title>
<link>http://www.dslreports.com/forum/r19449583</link>
<description></description>
<language>en</language>
<pubDate>Tue, 15 Dec 2009 05:11:50 EDT</pubDate>
<lastBuildDate>Tue, 15 Dec 2009 05:11:50 EDT</lastBuildDate>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19454737</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : Thanks for the help.<br><br>I was amazed when it worked, but I was glad I followed your suggestion!<br><br>I'll work on taking out the application inspection. I put a fair amount of stuff in there that I probably will never use. I kind of want the paranoid route to start with.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19454737</guid>
<pubDate>Fri, 16 Nov 2007 09:23:10 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19454680</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Aha! So your ISP (Verizon?) does lock down your WAN router interface MAC address .... :D<br><br>The Linksys router was probably running some non-compliance RFC code that could somehow "go around" the MAC address lock down. Typically consumer-grade routers like Linksys are behaving so.<br><br>Well, at least now you can connect using your 851W router even you feel it is slow. One thing I can think of is the application inspection. When you notice, your router inspects a lot of application traffic; especially those that are running over HTTP like IM. If you like to experiment, you can try to remove the inspection and see if your connection is running faster. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19454680</guid>
<pubDate>Fri, 16 Nov 2007 09:11:54 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19452689</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : OK, I'm totally in shock, but when I cloned the MAC of my Actiontec router, the 851W got assigned an IP! It's so strange because I never cloned the MAC address on either of the Linksys routers I tried.<br><br>Now it seems that the 851W is a bit slow on my connection. When I ran a speed test, I only got about 8Mb/s from my 15Mb/s connection. Any suggestions on how to improve that?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19452689</guid>
<pubDate>Thu, 15 Nov 2007 21:52:28 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19449640</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I highly doubt that the MAC cloning will solve the problem.<br><br>The 851W will be the 4th router that I have used with this connection (only used one at a time)<br><br>Verizon supplied an Actiontec MI424-WR router that I am currently using. I have also gotten 2 seperate Linksys routers to pick up an IP from Verizon.<br><br>The 851W is the only one that will not get an IP from Verizon. (I never colned MAC addresses on any of the other routers)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19449640</guid>
<pubDate>Thu, 15 Nov 2007 13:57:41 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19449583</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : You could "borrow" the Linksys WAN interface MAC address and implement it into the 851W WAN interface; and see if it works. Here is how to implement the MAC address.<br><br>configure terminal<br>interface FastEthernet4<br>mac-address [LINKSYS WAN INTERFACE MAC ADDRESS]<br>shutdown<br>no shutdown<br>end<br><br>Note that the Linksys must never be within the same broadcast domain as the Cisco to make the borrowing works.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19449583</guid>
<pubDate>Thu, 15 Nov 2007 13:47:48 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19449453</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I have a dynamic IP with my ISP.<br><br>I don't know 100% that they do not lock down the MAC address for asssigning IP addresses, but I do know that I currently have the Verizon supplied Actiontec router and that I also was able to get a crappy Linksys WRV200 router to work. The poor performance of the WRV200 is what spurred my purchase of the 851W]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19449453</guid>
<pubDate>Thu, 15 Nov 2007 13:30:25 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19449374</link>
<description><![CDATA[<A HREF="/useremail/u/1072934"><b>DocLarge</b></A> : Would "access-list 103 deny ip any any" be a factor here?<br><br>Jay]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19449374</guid>
<pubDate>Thu, 15 Nov 2007 13:17:44 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19449014</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Yup, it was the right command ... :D<br><br>Btw, do you have Static IP plan with your ISP?<br><br>You may want to confirm with the ISP if they use a system that lock down MAC address into their system. When they do, then you need to confirm that they have the correct WAN interface MAC address. Your correct WAN interface MAC address should be the one on the <i>show interface FastEthernet4</i>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19449014</guid>
<pubDate>Thu, 15 Nov 2007 12:29:04 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19448828</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I had previously used SDM to take the interface down and back up.<br><br>I just tried the shut / no shut and that did not seem to work either. But, just to be sure I'm doing it right. I enterd these commands:<br><br>configuration terminal<br>int fa4<br>shut<br>no shut<br>end<br><br>Did I get it right?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19448828</guid>
<pubDate>Thu, 15 Nov 2007 11:53:23 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19448795</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : After applying the ACL 101, did you reset the WAN interface?<br><br>Something like shut/no shut or reload the router would do.<br>No need to wipe out the entire config ..... at least not yet .... :D<br><br>By resetting the interface, the router will reinitialize DHCP session with your ISP. See if your router can have the IP address then.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19448795</guid>
<pubDate>Thu, 15 Nov 2007 11:47:20 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19448775</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : Unfortunately no luck with switching the ACL.<br><br>If you think I would be best defaulting the router and starting again, I can do that. I've been thrashing about with SDM and the command line and it's possible that I've got some built up junk that's messing things up.<br><br>If I rebuild, I think it would be best to stay away from SDM because it seems to do lots of things that one might not intend. I'll just need some guidance in building the firewall rules.<br><br>Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19448775</guid>
<pubDate>Thu, 15 Nov 2007 11:44:44 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19448638</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Sailing_Nut,<br><br>Replace ACL 102 under WAN interface with ACL 101 and see if it works. Here is the step<br><br>configure terminal<br>interface FastEthernet4<br>no ip access-group 102 in<br>ip access-group 101 in<br>end<br>copy running-config startup-config]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19448638</guid>
<pubDate>Thu, 15 Nov 2007 11:22:05 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19448436</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I was just editing a file to include what you suggested and I noticed that I already have a line in the access list that reads:<br><br>access-list 102 permit udp any any eq bootps<br><br> and it is several lines before the line<br><br>access-list 102 deny ip any any log<br><br>Am I misunderstanding something here or should that be working?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19448436</guid>
<pubDate>Thu, 15 Nov 2007 10:48:30 EDT</pubDate>
</item>

<item>
<title>Re: [help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19447208</link>
<description><![CDATA[<A HREF="/useremail/u/660498"><b>TomS_</b></A> : I think you will find it is because access-list 102 doesnt permit the DHCP response back into your router.<br><br>Try adding the following line, but make sure it is added <i>before</i> the "deny ip any any" line:<br><br><textarea name="code" class="text" cols=50 rows=10>access-list 102 permit udp any any eq bootps&#012;</textarea><!--end code block--><br>Easiest way to do it is to take a copy of your existing access-list, add the new rule, "no" the existing access-list, then paste the new one back in.<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19447208</guid>
<pubDate>Thu, 15 Nov 2007 03:15:23 EDT</pubDate>
</item>

<item>
<title>[help] 851W and ISP DHCP</title>
<link>http://www.dslreports.com/forum/remark,19446524</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I have configured my 851W but it refuses to pick up an IP address from my ISP's DHCP server.<br><br>I dredged with Google and found other people asking similar questions, but none had solutions posted.<br><br>It's probably something in my configuration, since I'm extremely new to Cisco and IOS.<br><br>Here's my config:<br><br>Current configuration : 9198 bytes<br>!<br>version 12.4<br>no service pad<br>service tcp-keepalives-in<br>service tcp-keepalives-out<br>service timestamps debug datetime msec localtime show-timezone<br>service timestamps log datetime msec localtime show-timezone<br>service password-encryption<br>service sequence-numbers<br>!<br>hostname Cisco851W<br>!<br>boot-start-marker<br>boot-end-marker<br>!<br>logging buffered 51200 debugging<br>logging console critical<br>enable secret 5 ???????????????????????<br>!<br>aaa new-model<br>!<br>!<br>aaa authentication login default local<br>aaa authorization exec default local<br>!<br>aaa session-id common<br>!<br>resource policy<br>!<br>clock timezone PCTime -5<br>clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00<br>ip subnet-zero<br>no ip source-route<br>!<br>!<br>ip cef<br>ip inspect log drop-pkt<br>ip inspect name SDM_MEDIUM appfw SDM_MEDIUM<br>ip inspect name SDM_MEDIUM cuseeme<br>ip inspect name SDM_MEDIUM dns<br>ip inspect name SDM_MEDIUM ftp<br>ip inspect name SDM_MEDIUM h323<br>ip inspect name SDM_MEDIUM https<br>ip inspect name SDM_MEDIUM icmp<br>ip inspect name SDM_MEDIUM imap reset<br>ip inspect name SDM_MEDIUM pop3 reset<br>ip inspect name SDM_MEDIUM rcmd<br>ip inspect name SDM_MEDIUM realaudio<br>ip inspect name SDM_MEDIUM rtsp<br>ip inspect name SDM_MEDIUM esmtp<br>ip inspect name SDM_MEDIUM sqlnet<br>ip inspect name SDM_MEDIUM streamworks<br>ip inspect name SDM_MEDIUM tftp<br>ip inspect name SDM_MEDIUM tcp<br>ip inspect name SDM_MEDIUM udp<br>ip inspect name SDM_MEDIUM vdolive<br>ip inspect name SDM_MEDIUM sip<br>ip inspect name SDM_MEDIUM sip-tls<br>ip tcp synwait-time 10<br>no ip bootp server<br>ip domain name wtbhome.net<br>ip name-server 192.168.0.2<br>ip name-server 71.242.0.12<br>ip ssh time-out 60<br>ip ssh authentication-retries 2<br>!<br>appfw policy-name SDM_MEDIUM<br>  application im aol<br>    service default action allow alarm<br>    service text-chat action allow alarm<br>    server permit name login.oscar.aol.com<br>    server permit name toc.oscar.aol.com<br>    server permit name oam-d09a.blue.aol.com<br>  application im msn<br>    service default action allow alarm<br>    service text-chat action allow alarm<br>    server permit name messenger.hotmail.com<br>    server permit name gateway.messenger.hotmail.com<br>    server permit name webmessenger.msn.com<br>  application http<br>    strict-http action allow alarm<br>    port-misuse im action reset alarm<br>    port-misuse p2p action reset alarm<br>    port-misuse tunneling action allow alarm<br>  application im yahoo<br>    service default action allow alarm<br>    service text-chat action allow alarm<br>    server permit name scs.msg.yahoo.com<br>    server permit name scsa.msg.yahoo.com<br>    server permit name scsb.msg.yahoo.com<br>    server permit name scsc.msg.yahoo.com<br>    server permit name scsd.msg.yahoo.com<br>    server permit name cs16.msg.dcn.yahoo.com<br>    server permit name cs19.msg.dcn.yahoo.com<br>    server permit name cs42.msg.dcn.yahoo.com<br>    server permit name cs53.msg.dcn.yahoo.com<br>    server permit name cs54.msg.dcn.yahoo.com<br>    server permit name ads1.vip.scd.yahoo.com<br>    server permit name radio1.launch.vip.dal.yahoo.com<br>    server permit name in1.msg.vip.re2.yahoo.com<br>    server permit name data1.my.vip.sc5.yahoo.com<br>    server permit name address1.pim.vip.mud.yahoo.com<br>    server permit name edit.messenger.yahoo.com<br>    server permit name messenger.yahoo.com<br>    server permit name http.pager.yahoo.com<br>    server permit name privacy.yahoo.com<br>    server permit name csa.yahoo.com<br>    server permit name csb.yahoo.com<br>    server permit name csc.yahoo.com<br>!<br>username tborland privilege 15 secret 5 ??????????????<br>!<br>!<br>!<br>bridge irb<br>!<br>!<br>interface Null0<br> no ip unreachables<br>!<br>interface FastEthernet0<br>!<br>interface FastEthernet1<br>!<br>interface FastEthernet2<br>!<br>interface FastEthernet3<br>!<br>interface FastEthernet4<br> description $ES_WAN$$FW_OUTSIDE$<br> ip address dhcp<br> ip access-group 102 in<br> no ip redirects<br> no ip unreachables<br> no ip proxy-arp<br> ip inspect SDM_MEDIUM out<br> ip nat outside<br> ip virtual-reassembly<br> ip route-cache flow<br> duplex auto<br> speed auto<br> no cdp enable<br>!<br>interface Dot11Radio0<br> no ip address<br> !<br> encryption mode ciphers tkip<br> !<br> encryption vlan 1 mode ciphers tkip<br> !<br> ssid wtbhome<br>    vlan 1<br>    authentication open<br>    authentication key-management wpa<br>    wpa-psk ascii 7 0014550F0356020D182E181C5B4950<br> !<br> speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0<br> 54.0<br> station-role root<br> no dot11 extension aironet<br> no cdp enable<br> bridge-group 1<br>!<br>interface Dot11Radio0.1<br> encapsulation dot1Q 1 native<br> no snmp trap link-status<br> no cdp enable<br> bridge-group 1<br> bridge-group 1 subscriber-loop-control<br> bridge-group 1 block-unknown-source<br> no bridge-group 1 source-learning<br> no bridge-group 1 unicast-flooding<br>!<br>interface Vlan1<br> description Internal Network<br> no ip address<br> ip nat inside<br> ip virtual-reassembly<br> ip tcp adjust-mss 1452<br> bridge-group 1<br> bridge-group 1 spanning-disabled<br>!<br>interface BVI1<br> description Bridge to Internal Network<br> ip address 192.168.0.1 255.255.255.0<br> ip access-group 100 in<br> no ip redirects<br> no ip unreachables<br> no ip proxy-arp<br> ip nat inside<br> ip virtual-reassembly<br> ip route-cache flow<br> ip tcp adjust-mss 1412<br>!<br>ip classless<br>ip route 0.0.0.0 0.0.0.0 FastEthernet4<br>!<br>ip http server<br>ip http authentication local<br>ip http secure-server<br>ip http timeout-policy idle 60 life 86400 requests 10000<br>ip nat inside source list 1 interface FastEthernet4 overload<br>!<br>logging trap debugging<br>access-list 1 remark INSIDE_IF=BVI1<br>access-list 1 remark SDM_ACL Category=2<br>access-list 1 permit 192.168.0.0 0.0.0.255<br>access-list 100 remark auto generated by Cisco SDM Express firewall configuration<br>access-list 100 remark SDM_ACL Category=1<br>access-list 100 deny   ip host 255.255.255.255 any<br>access-list 100 deny   ip 127.0.0.0 0.255.255.255 any<br>access-list 100 permit ip any any<br>access-list 101 remark auto generated by Cisco SDM Express firewall configuration<br>access-list 101 remark SDM_ACL Category=1<br>access-list 101 permit udp any eq bootps any eq bootpc<br>access-list 101 deny   ip 192.168.0.0 0.0.0.255 any<br>access-list 101 permit icmp any any echo-reply<br>access-list 101 permit icmp any any time-exceeded<br>access-list 101 permit icmp any any unreachable<br>access-list 101 deny   ip 10.0.0.0 0.255.255.255 any<br>access-list 101 deny   ip 172.16.0.0 0.15.255.255 any<br>access-list 101 deny   ip 192.168.0.0 0.0.255.255 any<br>access-list 101 deny   ip 127.0.0.0 0.255.255.255 any<br>access-list 101 deny   ip host 255.255.255.255 any<br>access-list 101 deny   ip any any<br>access-list 102 remark auto generated by SDM firewall configuration<br>access-list 102 remark SDM_ACL Category=1<br>access-list 102 deny   ip 192.168.0.0 0.0.0.255 any<br>access-list 102 permit icmp any any echo-reply<br>access-list 102 permit icmp any any time-exceeded<br>access-list 102 permit icmp any any unreachable<br>access-list 102 deny   ip 10.0.0.0 0.255.255.255 any<br>access-list 102 deny   ip 172.16.0.0 0.15.255.255 any<br>access-list 102 deny   ip 192.168.0.0 0.0.255.255 any<br>access-list 102 deny   ip 127.0.0.0 0.255.255.255 any<br>access-list 102 deny   ip host 255.255.255.255 any<br>access-list 102 deny   ip any any log<br>access-list 103 remark VTY Access-class list<br>access-list 103 remark SDM_ACL Category=1<br>access-list 103 permit ip 192.168.0.0 0.0.0.255 any<br>access-list 103 deny   ip any any<br>no cdp run<br>!<br>control-plane<br>!<br>bridge 1 protocol ieee<br>bridge 1 route ip<br>banner login ^CAuthorized access only!<br> Disconnect IMMEDIATELY if you are not an authorized user!^C<br>!<br>line con 0<br> no modem enable<br> transport output telnet<br>line aux 0<br> transport output telnet<br>line vty 0 4<br> access-class 103 in<br> transport input telnet ssh<br>!<br>scheduler max-task-time 5000<br>scheduler allocate 4000 1000<br>scheduler interval 500<br>end]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19446524</guid>
<pubDate>Wed, 14 Nov 2007 23:28:32 EDT</pubDate>
</item>

</channel>
</rss>
