<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Config] Need help debugging a misconfiguration of NAT 850W Rout in Cisco</title>
<link>http://www.dslreports.com/forum/r20768080</link>
<description></description>
<language>en</language>
<pubDate>Wed, 03 Dec 2008 03:17:01 EDT</pubDate>
<lastBuildDate>Wed, 03 Dec 2008 03:17:01 EDT</lastBuildDate>

<item>
<title>Re: [Config] Need help debugging a misconfiguration of NAT 850W</title>
<link>http://www.dslreports.com/forum/remark,20772083</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : You're welcome.. Glad to hear.. and don't beat yourself up too much, we're all here to learn something.  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20772083</guid>
<pubDate>Thu, 10 Jul 2008 20:03:04 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Need help debugging a misconfiguration of NAT 850W</title>
<link>http://www.dslreports.com/forum/remark,20772003</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I thank you very much, I have made the changes and it is indeed working. I feel ashamed at the same time but it has been a good learning experience. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20772003</guid>
<pubDate>Thu, 10 Jul 2008 19:47:17 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Need help debugging a misconfiguration of NAT 850W</title>
<link>http://www.dslreports.com/forum/remark,20771494</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Doesn't sound like a nat issue, but sounds like you removed CBAC?  CBAC will allow the return traffic through that it inspects leaving your router.<br><br>You don't need all of this, but I've found them usefull at one point or another...  example:<br><br><textarea name="code" class="text" cols=50 rows=10>ip inspect name general-purpose cuseeme&#012;ip inspect name general-purpose dns&#012;ip inspect name general-purpose ftp&#012;ip inspect name general-purpose icmp&#012;ip inspect name general-purpose rcmd&#012;ip inspect name general-purpose realaudio&#012;ip inspect name general-purpose rtsp&#012;ip inspect name general-purpose sqlnet&#012;ip inspect name general-purpose streamworks&#012;ip inspect name general-purpose tftp&#012;ip inspect name general-purpose tcp&#012;ip inspect name general-purpose udp&#012;ip inspect name general-purpose vdolive&#012;ip inspect name general-purpose sip&#012;ip inspect name general-purpose esmtp alert on&#012;ip inspect name general-purpose pop3 alert on reset&#012;ip inspect name general-purpose ftps&#012;ip inspect name general-purpose isakmp&#012;ip inspect name general-purpose ipsec-msft&#012;ip inspect name general-purpose pptp&#012;ip inspect name general-purpose ntp&#012;ip inspect name general-purpose imap&#012;ip inspect name general-purpose imaps&#012;ip inspect name general-purpose imap3&#012;ip inspect name general-purpose pop3s&#012; &#012;interface FastEthernet4&#012; ip inspect general-purpose out&#012; &#012;</textarea><!--end code block--><br>Also, doesn't look like you need this line in there:<br><br>ip nat pool home 10.10.10.0 10.10.10.255 netmask 255.255.255.0<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20771494</guid>
<pubDate>Thu, 10 Jul 2008 18:00:21 EDT</pubDate>
</item>

<item>
<title>[Config] Need help debugging a misconfiguration of NAT 850W Rout</title>
<link>http://www.dslreports.com/forum/remark,20768080</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hello all,<br><br>First and foremost I want to thank you for taking the time to read this.<br><br>How I got to where I am now.<br>Decided to mess around with my configuration about 5 days ago and I think I messed something up and unfortunately I did not back up my config.<br><br>Here is what I've learned:<br>Keep frequent backups: Once my issue gets resolved I will definetely run a kron job to ftp over configurations on a daily basis.<br><br>Here is how it used to work:<br>Any traffic I requested from my inside interface in this case BVI1 as long as the acl in was configured to permit ip 10.10.10.0 0.0.0.255 any<br>anything I requested would be allowed to come back to me without problems<br><br>Here is how it's working now:<br>any traffic I request from the bvi1 interface with the same ACL as I had before gets denied by ACL 101 which is assigned to the public outside interface which basically allows bootpc traffic for it to receive DHCP info from the ISP and a deny ip all rule.<br><br>I can't just put an permit ip any any on the 101 ACL that's like not having a firewall. I have pasted my configuration here: &raquo;<A HREF="http://pastebin.be/12710" >pastebin.be/12710</A> <br><br>Once again, I thank you for your time, any help you provide here hope it comes back tenfold.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20768080</guid>
<pubDate>Thu, 10 Jul 2008 01:43:30 EDT</pubDate>
</item>

</channel>
</rss>
