[CISCO 876] Krijg mijn ADSL verbinding niet werkend

Pagina: 1
Acties:

Acties:
  • 0 Henk 'm!

  • Jessez
  • Registratie: Maart 2008
  • Laatst online: 20:31
Ik ben sinds gisteravond al bezig om een CISCO 876 router/modem (ISDNoADSL) te installeren.

Waar gaat het nu precies om?
Ik heb hier een 876 router van Cisco. Dit is een modem, router en switch in één. Deze probeer ik dmv een standaard XS4ALL basic abbotje, verbinding te laten maken met internet. De lijn werkt zonder meer.

Er zijn mij een aantal dingen niet geheel duidelijk aan deze routerseries.
Tot zover begrijp ik het Dialer verhaal, het ATM verhaal en de verdere instellingen enigsinds. Verbinding met xs4all lukt want krijg een IP adres toe gewezen. pingen naar buiten toe via pc lukt niet. pingen naar router lukt wel.

Inmiddels heb ik 3 verschillende configuraties. Een config van de XS4ALL-site, van een andere router met vrijwel identieke configuratiebenodigdheden en een via topics @ GoT.

Ik zal hier onder ook een aantal configuraties posten zodat mensen even kunnen kijken of er misschien grote fouten in mijn configuratie zitten.
!This is the running config of the router: 10.0.0.138
!----------------------------------------------------------------------------
!version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname local
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$Z3O0$TjbZOOVVkF8JTkAdkC/WZ.
!
no aaa new-model
clock timezone PCTime 4 30
!
crypto pki trustpoint TP-self-signed-929624242
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-929624242
revocation-check none
rsakeypair TP-self-signed-929624242
!
!
crypto pki certificate chain TP-self-signed-929624242
certificate self-signed 01
30820254 308201BD A0030201 02020101 300D0609 2A864886 F70D0101 04050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 39323936 32343234 32301E17 0D303230 33303130 30343331
325A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3932 39363234
32343230 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
8BB1B8A4 CCF1376C 8DF8BE8C 23AF4D64 0EFAC983 92E6C5A0 1E578738 1B9A7B43
DA22FD17 42995E7B 7679F3A9 1E3D1C3F 07A10932 52B90A6C A2003FDB 983D92AE
533B461C 9247517A 18039FC0 09A72FB5 4A47B325 B6CBFE48 EFC932E7 89E87219
A668ECEB 1F657D6F E201C627 B79A9DDF 970F965E 9B2EC4FC B23F9C38 55C379DB
02030100 01A37E30 7C300F06 03551D13 0101FF04 05300301 01FF3029 0603551D
11042230 20821E4B 77696E74 656E6E65 74526F75 7465722E 6B77696E 74656E6E
65742E6E 6C301F06 03551D23 04183016 80148D45 29F67835 7C1EB9B9 C6E14DB5
98D0A987 7853301D 0603551D 0E041604 148D4529 F678357C 1EB9B9C6 E14DB598
D0A98778 53300D06 092A8648 86F70D01 01040500 03818100 1AE7103C AD525B01
F4F98C6E 45FB9EFB A8C5268E AE9A2956 086F349C 4CF955B9 104AEE0D 65B829AC
17B4EA34 199CACA5 7901EA9F 515C20C6 05B3549E 226C6CC7 A3BABD9A 5F62A964
27A5803E 7A4933BB 7F8A8D04 D94395D6 2C7A5F50 CA4B7C2A F62FD07F 422C1A5C
B3CDB95C DF1FFD65 B7DC2549 B7F1E615 A8FE8754 5DBA17BE
quit
dot11 syslog
no ip source-route
ip cef
!
!
no ip bootp server
ip domain name domain.nl
ip name-server 194.109.9.99
ip name-server 194.109.6.66
!
!
!
username <myuser> privilege 15 secret 5 <password>
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface BRI0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
encapsulation hdlc
ip route-cache flow
shutdown
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $FW_OUTSIDE$$ES_WAN$
pvc 8/48
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 10.0.0.138 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
ip tcp adjust-mss 1452
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication pap callin
ppp pap sent-username <myuser>@xs4all.nl password 7 <password>
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 100 interface dialer0 overload
access-list 100 permit ip any any
dialer-list 1 protocol ip permit
!
!
control-plane
!
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end
Het probleem zit hem vooral in het feit dat ik geen zak begrijp van het hele ADSL-config voor Cisco gebeuren. Er zijn nergens guides te vinden... nergens uitleg betreffende ATM, Dialers enof foutmeldingen met Fast Ethernet adapters. Het enige wat je kan doen is Cisco bellen, maar die willen dat je een abbonement voor support bij hun afsluit. Ik heb daar simpelweg gewoon geen geld voor.

Ik vraag me af of er iemand is die mij kan helpen met het in elkaar flanzen van een perfecte config zonder toeters en bellen die doet wat hij moet doen; ADSL verbinding opzetten en doorsturen naar switch. VPN en ACL's komen later wel... eerst de verbinding.

Op GoT is er vrij weinig te vinden over mensen die met hun Cisco apparatuur DSL verbindingen willen maken. Uiteraard zijn er verschijdenen topics zoals deze, deze en [CISCO 876] Krijg ADSL verbinding maar niet werkend. Maar echt veel concrete informatie blijft uit. Tevens zijn errors ook heel erg moeilijk terug te vinden op internet. Met weinig tot geen uitleg.

Heb ook een verbindings test gedaan
WAN troubleshooting report details


Router Details

Attribute Value
Router Model 876
Image Name c870-advsecurityk9-mz.124-15.T7.bin
IOS Version 12.4(15)T7
Hostname KwintennetRouter


Interface Details

Attribute Value
Interface ATM0.1
IP address Easy IP
Description


Test Activity Summary

Activity Status
Checking interface status... Up
Checking for DNS settings... Successful
Checking interface IP address.. Successful
Checking exit interface... Successful
Pinging to destination host... Successful


Test Activity Details

Activity Status
Checking interface status... Up
Interface physical status :Up
Line protocol status :Up
Checking for DNS settings... Successful
DNS lookup set :Yes
Statically configured DNS servers : 194.109.9.99 194.109.6.66
Dynamically imported DNS servers :None
Checking interface IP address.. Successful
Interface IP address :82.95.221.187
Interface IP address Type :Negotiated
Checking exit interface... Successful
Exit interface found :Dialer0
Exit interface found :Dialer0
Pinging to destination host... Successful
Destination pinged to :194.109.9.99
Size of the ping packet (in bytes) :100
Timeout interval :2
Number of ping packets sent to the destination address :5
Ping reply validated :No
Fragmentation allowed on ping packet :No
Destination pinged to :194.109.6.66
Size of the ping packet (in bytes) :100
Timeout interval :2
Number of ping packets sent to the destination address :5
Ping reply validated :No
Fragmentation allowed on ping packet :No


Troubleshooting Results Failure Reason(s) Recommended Action(s)
Dat was succes vol.

ik snap het allemaal niet meer... help!

Acties:
  • 0 Henk 'm!

  • jvanhambelgium
  • Registratie: April 2007
  • Laatst online: 30-08 21:29
Je bent er bijna ! ;-)
Wat je nu moet doen is het NAT verhaal in orde brengen (Network Address Translation) zodat je met het interne IP adres kan surfen.

Het "dial" gedeelte ziet er goed uit, connectie is up en je kreeg alvast 1 dynamisch IP van de provider.

Op je Ethernet/VLAN interface kleef je een "ip nat inside"
Op de dialer interface zet je een "ip nat outside"

en dan nog enkele andere statements in gewone config-mode in functie wat je wilt doen...

Zie hieronder...

http://www.cisco.com/en/U...6a0080094e77.shtml#topic3

http://www.cisco.com/en/U...rt_sub-protocol_home.html

Acties:
  • 0 Henk 'm!

  • Jessez
  • Registratie: Maart 2008
  • Laatst online: 20:31
Het werkt. _/-\o_
Hieronder heb ik het werkend exemplaar staan
!This is the running config of the router: 10.0.0.138
!----------------------------------------------------------------------------
!version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname local
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$Z3O0$TjbZOOVVkF8JTkAdkC/WZ.
!
no aaa new-model
clock timezone PCTime 4 30
!
crypto pki trustpoint TP-self-signed-929624242
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-929624242
revocation-check none
rsakeypair TP-self-signed-929624242
!
!
crypto pki certificate chain TP-self-signed-929624242
certificate self-signed 01
30820254 308201BD A0030201 02020101 300D0609 2A864886 F70D0101 04050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 39323936 32343234 32301E17 0D303230 33303130 30343331
325A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3932 39363234
32343230 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
8BB1B8A4 CCF1376C 8DF8BE8C 23AF4D64 0EFAC983 92E6C5A0 1E578738 1B9A7B43
DA22FD17 42995E7B 7679F3A9 1E3D1C3F 07A10932 52B90A6C A2003FDB 983D92AE
533B461C 9247517A 18039FC0 09A72FB5 4A47B325 B6CBFE48 EFC932E7 89E87219
A668ECEB 1F657D6F E201C627 B79A9DDF 970F965E 9B2EC4FC B23F9C38 55C379DB
02030100 01A37E30 7C300F06 03551D13 0101FF04 05300301 01FF3029 0603551D
11042230 20821E4B 77696E74 656E6E65 74526F75 7465722E 6B77696E 74656E6E
65742E6E 6C301F06 03551D23 04183016 80148D45 29F67835 7C1EB9B9 C6E14DB5
98D0A987 7853301D 0603551D 0E041604 148D4529 F678357C 1EB9B9C6 E14DB598
D0A98778 53300D06 092A8648 86F70D01 01040500 03818100 1AE7103C AD525B01
F4F98C6E 45FB9EFB A8C5268E AE9A2956 086F349C 4CF955B9 104AEE0D 65B829AC
17B4EA34 199CACA5 7901EA9F 515C20C6 05B3549E 226C6CC7 A3BABD9A 5F62A964
27A5803E 7A4933BB 7F8A8D04 D94395D6 2C7A5F50 CA4B7C2A F62FD07F 422C1A5C
B3CDB95C DF1FFD65 B7DC2549 B7F1E615 A8FE8754 5DBA17BE
quit
dot11 syslog
no ip source-route
ip cef
!
!
no ip bootp server
ip domain name domain.nl
ip name-server 194.109.9.99
ip name-server 194.109.6.66
!
!
!
username <myuser> privilege 15 secret 5 <password>
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface BRI0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
encapsulation hdlc
ip route-cache flow
shutdown
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $FW_OUTSIDE$$ES_WAN$
pvc 8/48
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 10.0.0.138 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication pap callin
ppp pap sent-username <myuser>@xs4all.nl password 7 <password>
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 100 interface Dialer0 overload
!
access-list 100 permit ip any any
dialer-list 1 protocol ip permit
!
!
!
control-plane
!
banner exec ^CCC
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CCCAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end
Van de week Firewall en VPN in ordemaken
bedankt ;)

ps.: weet iemand waar ik kan zien op welke snelke UP/Down snelheid hij staat?

Acties:
  • 0 Henk 'm!

Verwijderd

jep,

Show dsl interface atm0