Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] Silly problem with ping on 851
Search Topic:
Uniqs:
268
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Config] bitorrent with cisco router 2611 »
« Inserted a new WIC, need command  
AuthorAll Replies

Sailing_Nut

join:2006-11-07
Annapolis, MD

[Config] Silly problem with ping on 851

I'm unable to ping my router fm the Internet, but I thought I had the icmp echo-reply enabled in myACL for FA4 (my WAN port)

Here is my FA4 config


and here is mt ACL 107 that is applied to FA4


What am I missing? (Keep in mind that a good portion of the ACL is a mystery to me)

aryoba
Premium,MVM
join:2002-08-22


edit:
July 8th, @03:43PM

Try to implement the following ACL 107 instead ...

access-list 107 remark auto generated by SDM firewall configuration
access-list 107 remark SDM_ACL Category=1
access-list 107 deny ip 10.0.0.0 0.255.255.255 any
access-list 107 deny ip 172.16.0.0 0.15.255.255 any
access-list 107 deny ip 192.168.0.0 0.0.255.255 any
access-list 107 deny ip 127.0.0.0 0.255.255.255 any
access-list 107 deny ip host 255.255.255.255 any
access-list 107 permit tcp any any eq 27000
access-list 107 permit tcp any any range ftp-data ftp
access-list 107 permit udp any eq bootps any eq bootpc
access-list 107 permit icmp any any echo
access-list 107 permit icmp any any echo-reply
access-list 107 permit icmp any any time-exceeded
access-list 107 permit icmp any any unreachable
access-list 107 deny ip any any log

Sailing_Nut

join:2006-11-07
Annapolis, MD
I re-did my ACL as you suggested, but I'm still not answering ping requests. :-(

Any more thoughts?

aryoba
Premium,MVM
join:2002-08-22


edit:
July 8th, @04:53PM

How does the ACL look like now? Does it look exactly the same as I suggested line by line?

Another possibility is that you are either pinging the wrong IP address, the router has different IP address now, or the router is down

Sailing_Nut

join:2006-11-07
Annapolis, MD

Here is the new ACL. As far as I can tell it's exactly as you had it, but I may not be able to read! ;-)


I verified that the router is not ping-able using the line quality test from this site.

The router isn't down because I'm using it to access the Internet to write this reply.


Gordon Brown

@co.uk

Check line 11 of the acl 107.

Aryoba's has permit icmp any any echo.

You have deny icmp any any echo.

Enter the command "sh ip access-lists 107" and you'll see hits against each line in the acl. As the acl is now with the deny icmp statement you should see hits when you try to ping the router from the Internet and don't get a reply.

After changing the deny to permit you shoudl get a reply and see hits against line 11 in the acl

Sailing_Nut

join:2006-11-07
Annapolis, MD
Oops!

Told you al I couldn't read!

Thanks for catching my stupid mistake.

Sailing_Nut

join:2006-11-07
Annapolis, MD
That fixed it.

Amazing how a little change like deny to permit can change things!

Serves me right for using SDM and not looking a the default for the action.


GordonBrown

@co.uk
No problems. Sometimes it just needs another pair of eyes to spot the silly mistake. Especially if you've staring at a config for a while and can't see the forest for the trees.

aryoba
Premium,MVM
join:2002-08-22

I too have the same problem reviewing ACL; especially a complex one with various applications. Sometime it takes me days to review them properly to ensure I don't miss anything

Anyway it is good to hear that the problem was fixed
Forums » Equipment Support » Hardware By Brand » Cisco[Config] bitorrent with cisco router 2611 »
« Inserted a new WIC, need command  


Saturday, 22-Nov 17:34:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [199] Obama FCC Selection Team Won't Make AT&T Happy
· [109] DSL's Not Dead Yet
· [87] Zone Alarm Pro Free Just For Today
· [84] Storm Reviews Come Rolling In
· [80] Harvard Law Professor Sues RIAA
· [69] New Xbox 360 'Experience' Goes Live
· [69] CRTC Rules Against Indie ISPs In Throttling Dispute
· [59] Just 26% of U.S. Broadband Users Faster Than 5Mbps
· [56] Friday Open Thread
· [51] Cable Grabbing 71% Of New Broadband Customers
Most people now reading
· CRTC ruling coming Thursday Nov 20 [TekSavvy]
· Disabling Autorun in XP? [Security]
· Pentagon Hit by Unprecedented Cyber Attack [Security]
· [video] Chicken Head Tracking [56k lookout! (broadband heavy)]
· Local Regulations/Code for Running Cat5e? [Home Repair & Improvement]
· Things to give up if we're capped [TekSavvy]
· What Deathknight Race to roll with? [World of Warcraft]
· [WotLK] PVP gear at 80 [World of Warcraft]
· Unionized cuts starting at Bell [Canadian Chat]
· [ PvE] Leatherworking [World of Warcraft]