Make a VLANs talk to the internet

Hello all,
I need help making a Cisco router and Catalyst 3550 talk. I'm new with VLANs and such, in fact new to Cisco stuff in general. I've learned a bit and I learn quick.
Does anyone have any idea how I can connect my router to the internet, preferably managing multiple public IPs, and then connect those public IPs to the VLANs in the Catalyst 3550. Assume I am starting from a blank config on both router and switch. I have 2 Ethernet interfaces on the router. I'm trying to setup VLANs on the Catalyst, and do the routing on there.
I need the cisco router to handle my 5 public IP addresses. I think I can do that by assigning each public IP to fa0/1 having one as a primary and the other 4 as secondary. Then have fa0/0 connect to the Catalyst and have 5 subnets on there. I want to map each subnet (and subsequently LAN PCs or servers) to a specific public IP.
192.168.1.0 --> 96.xxx.xxx.170
192.168.2.0 --> 96.xxx.xxx.171 and so on.
Every time I have tried setting this type of configuration up nothing works properly. I know the equipment I have can do it, I'm just not sure how to achieve it. I know I've been close, yet not close enough obviously. I'm pulling my hair out!I must have been missing something critical in my router or switch config, but i couldn't see what it was. After butchering stuff badly many times I decided to start fresh on both, again. So, starting with blank slate, can anyone give me any ideas? Thanks in advance.

This isn't really a complicated config that you need, it just needs great care in doing it. Things, especially access list need to be done in a given order.
On the router you will need to create route maps for each IP address that you want to use as well as an appropriate NAT translation for the route map. Once this is done you will also need to create access list that permit one subnet and deny others for a given public IP address. Lastly you will need to creat static routes or enable EIGRP/OSPF to build the appropriate routes back to each VLAN.
The switch config is simple create your VLANS and route them to the Cisco router. Personally I set assign a port on the switch that is a L3 port, the command is "no switchport", assign an IP address to the port that is in the same subnet as the router and connect the router to this port. However you can keep the port as a switchport as you wish.
I'll attach a couple of sample configs for you to review. Like I said it isn't really a difficult config it's just tedious.
In the attached sample config the first IP will be assigned to fa0/1, the others will be assigned to the route maps. Notice that in this sample config the VLAN addresses are segmented from 10.244.0.0/22, 10.24.40.0/24 & 10.13.13.0/30.
The permit lines in the access lists are the physical addresses that are permitted for a given IP address.

Similar Messages

  • How to make some computers available on the Internet? Remote Desktop.

    We have 12 computers (VMs) that are used for training. They are configured with the software to be trained on and are set up just the way we want them. We are looking for a way that we can make these computers available to the internet so that someone can Remote into the VMs to go through some training courses. We do need to be able to control who can get onto these machines so we don't have random people logging into them. We handle training through a GotoTraining type system and would provide a link to each of the attendees.Does anyone know if a way to do this?It could be as simple as a list of 12 links that we tell each person to click a link. It could be as fancy as having the person click the link and having them put into any machine that doesn't already have someone in it.This could involve installing some sort of 3rd party...
    This topic first appeared in the Spiceworks Community

    Hi,
    Beforing answering your Q....How the dashboard will get the data....how it will display??
    See to diplay any Grid,charts,bar..... it need to fetch the data from the database servers that means if your in netcafe also .......it need to be connected to the netwrok were it can fetch the data from.
    so having the link is not sufficient ....... you need to have the authorization to the xMIIserver from Net cafe.
    Regards,
    Phani

  • I try to run photoshop and it says i cannot log in and to try later or make sure im connected to the internet which i am?...

    i try to run photoshop and it says i cannot log in and to try later or make sure im connected to the internet which i am?...

    If you are using someone else's WiFi they may have restrictions in place.
      (cofee shop, etc..)
    Have you tried connecting using at least more than one particular WiFi network ?
    You might want to try googling for a bandwidth test site
      verify you have reasonable throughput..
        1 megabit up and 1 megabit down..
          (bandwidthplace.com is what I typically use..)

  • Is there any way to make an iPad3 connect to the internet in an Extended Verizon area?

    Is there any way to make an iPad3 connect to the internet in an Extended Verizon area?

    If you have the prepaid 3G account, no. The prepaid service, the kind activated directly from the iPad only works on Verizon's own network. You'd need to change to the month-to-month postpaid service to roam on the extended network. Call customer service about changing it over. You will need to do a credit check but there is no contract.

  • The little 'E' that was next to my signal bars has dissapeared and now i can't send texts, make calls or go on the internet.HELP!

    The little 'E' that was next to my signal bars has dissapeared and now i can't send texts, make calls or go on the internet. WHY? HELP!

    As suggested make sure "cellular data" is ON and you have valid cellular data plan.
    That "E" sign only shows the network (Edge) or 3G (if you are in the 3G network), but it has no relation to you not been able to make regular calls or sending regular texts with network signal (in the form of bars) being present.
    Double check if you have credit in your phone (in case of pre-paid) or if you have reached your limit (in case of post-paid)

  • Upgrading to 10.6 make my Mac safer on the internet?

    I'm happily using 10.5.8. Would upgrading to 10.6 make my Mac safer on the internet? I'm not interested in new features - so why should I upgrade?
    Thanks
    Mark

    I am assuming you have an Intel Mac because 10.6 won't run on a PowerPC.
    Your concern was my primary reason for upgrading from 10.5 to 10.6 several months ago.
    It is fairly similar to 10.5 and I am mostly quite pleased with it.
    Despite the arrival of Mountain Lion, Snow Leopard still managed to get a security update as recently as last month.
    Pricing has changed dramatically over the years. Where once a 10.5 retail DVD upgrade cost me here in Australia $179, I got Snow for $39. It is even cheaper in the U.S.
    Snow Leopard still has Rosetta so older PPC applications like Appleworks still work, so I think it is definitely worth doing.

  • RVL200 VLANs Cannot access the internet

    Hi Everyone
    I have a RVL200, Firmware Version: v1.1.7 and i cannot get my clients on a VLAN to access the internet.
    I currently have port 3 on the router set to Access mode with untagged VLAN #4.
    I have Multiple VLAN subnets setup and i am using the DHCP server on the router, it is correctly distributing the IP addresses.
    The clients on VLAN #4 can see other clients on the same VLAN but they cannot contact the router ip(192.168.1.254) or any website
    Any suggestions, questions etc.

    Alastair,
    One weird thing about these routers is they give dhcp to every vlan, BUT they do it all from the same subnet. For example, Vlan1 and 2 will both pull a 192.168.1.x ip address if connected via DHCP. Their default gateway will be the same. If you do not allow routing between the vlans, then they should only be able to access the internet. I think this is your desired result. Try setting each client to dhcp, set the router to manage vlans on a port by port basis, and then you should be able to access the internet/default gateway/dhcp server without pinging the other hosts on the other vlans.
    Just remember that the dhcp server will give the same scope to every vlan, but will filter the traffic at the router based on what port it came in on.
    If you are still having issues, please post your results.
    Bill

  • Itunes cant make a secure connection to the internet

    my itunes wont conntect to the itunes store, i have done everything that has been sugested as far as uninstalling itunes and reinstalling it, done the command prompt file dump not useing proxy survers, turned all my firewalls off everything googled everything i could about this, every time i run the diognostic through itunes it comes back with can not make a sacure connection to the internet, im using windows 7, would really like to resolve this problem becasue i havent been able to update my podcasts or update anything sens feb

    Close your iTunes,
    Go to command Prompt -
    (Win 7/Vista) - START/ALL PROGRAMS/ACCESSORIES, right mouse click "Command Prompt", choose "Run as Administrator".
    (Win XP SP2 n above) - START/ALL PROGRAMS/ACCESSORIES/Command Prompt
    In the "Command Prompt" screen, type in
    netsh winsock reset
    Hit "ENTER" key
    Restart your computer.
    If you do get a prompt after restart windows to remap LSP, just click NO.
    Now launch your iTunes and see if it is working now.
    If you are still having these type of problems after trying the winsock reset, refer to this article to identify which software in your system is inserting LSP:
    Apple software on Windows: May see performance issues and blank iTunes Store
    http://support.apple.com/kb/TS4123?viewlocale=en_US

  • Route Guest VLAN directly to the internet

    All, I am wanting to create a guest SSID/VLAN that is redirected straight to the internet, without any access to our network? I know how to create a guest SSID/VLAN but dont know how to send all traffic on that VLAN directly to the internet? How would the client obtain a DHCP address if its on a VLAN seperate the network?

    Here is how I set up our wireless guest vlan:
    1. I use 802.1x with PEAP to authenticate guests against a MS RADIUS server. Once successful, the AP allows guest to broadcast DHCP request.
    2. My router forward the DHCP request to DHCP server which assign IP and necessary options to guests, using IP helper-address command.
    3. My router has access-lists to prevent guests from accessing any corporate IP addresses (allowing only DHCP broadcasts)
    4. A route-map is configured on the default router on the guest vlan so that it will route all traffic sourced from that vlan out to the Internet. I use "set IP default next-hop xxx.xxx.xxx.xxx" to route the traffic directly to our proxy server or firewall.
    This is not a very user-friendly setup on the client side, because I have to mannually configure guest laptops to do 802.1x w/ PEAP. Sometime it is a pain with work with so many different wireless cards/utilities.
    HTH,
    daniel

  • Can someone point in the right direction for how to make a multiplayer game over the internet

    Hello,
    I am looking into making a game where two people who can be in different places would log on to the app, log in and can play - i.e. they would be connected over the internet. I'm looking for a hint on what is the direction to take and which technologies.
    For example is there a best practice for example if you make an app with DirectX and C++, and you use some kind of web service or something? or is it easier using C# and XNA? just looking for some pointers in the right direction. I have played around
    with DirectX, far from proficient but have familiarity, I have no experience with XNA but hear it's less hardcore and easier going. I'm particularly interested in what the best way to connect over the internet.
    Thanks

    What you are asking is very complicated and one of the more difficult things you can do in gaming. I'd strongly recommend you start smaller to learn and then move up to multi-player games as your skills grow.
    From the multiplayer client perspective it doesn't really matter which technology you use. You can write a multiplayer game in any engine or technology that can talk to the network. Choose the client technology that you are most adept at and interested in
    and learn it. You can go straight to DX, use a third party library such as Monogame (XNA isn't supported for Windows Store apps), or a complete game engine such as Unity. Once you can write a decent one-player game you'll have the foundation to start on to
    build a two-player game.
    At that point you'll need to define the problem much more specifically. As you state it, it is really wide open. How do you want the users to connect? Directly machine to machine? Matched through a web server but running client side? Connecting to a game
    running on a remote server? Something else?
    The network connection itself is probably fairly straightforward, but where to connect and how to manage that can be difficult. You'll have to decide what properties you want. Is this an action game where responsiveness is important or
    a turn based game where timing is less relevant?
    Are the players connecting locally or completely remotely? If the former then they can probably connect directly over the local network (NFC is great here). If the latter then they probably will need to connect to a matchmaker service to avoid firewalls.
    This can get very complex, but there are existing solutions you can use rather than writing your own.
    --Rob

  • Talking over the internet

    If I want to talk to someone over the internet. I am guessing that my three options
    are skype and yahoo or microsoft messenger. How do I set up yahoo or microsoft
    messengerso that I can talk online.
    I have downloaded yahoo messenger and skype.
    And I can send typing messages with yahoo or microsoft messenger already. I
    purchased a usb headset - do i just contact the person now with their email
    and talk?
    martini

    Hello martini
    Skype should work for you. See their great Help web pages for all your questions on making Skype work or work better. Skype even offers dedicated Skype discussions and free technical support for your Skype-specific questions.
    Yahoo! Messenger for Mac doesn't do audio. That is just how Yahoo writes the software. We cannot change that.
    Mac-to-Mac, iChat AV (part of your Mac OS X software) is usually best, whether for text, audio, video, or all. If you are concerned about connecting with PC friends, iChat can connect via Jabber applications for text chat and with any PC that is using an AIM server client application for video and audio. For help getting started with iChat and for suggestions about headsets, see this current thread:
      http://discussions.apple.com/message.jspa?messageID=5442877#5442877
    A USB headset that work with your Mac should be fine, but, if you already have added speakers and a mic to your system, they should work for iChat AV and Skype. With either application, I almost never need to resort to headphones to limit echo or feedback on my G5 tower Mac.
    If you are looking for other chat alternative software applications, you can consider the apps in the Chatting and Conferencing section of this page:
      http://www.ralphjohnsuk.dsl.pipex.com/EZJim/EZJimpage7.html
    Skype and the other apps identified as "Cross Platform" will be easiest to use for contacts that use PCs.
    Microsoft Messenger (MSM) (and the older MSN Messenger) for Mac (MSMM) are text only apps. You cannot use iSight (or any camera) with MSMM for Mac. MSMM (for Mac) will connect with MSM whether on PCs or on other Macs, but for text ONLY.
    There are two alternative clients of the MSMM server that allow Mac video chat (but no audio) with PC Microsoft/MSN Messenger users:
    • Mercury Messenger for Mac and
    • aMSN for Mac OS X
    Either offers the same functions. Use whichever you find more reliable or easier to use.
    EZ Jim
    PowerBook 1.67 GHz   Mac OS X (10.4.10)    G5 DP 1.8  External iSight

  • HT4623 iPhone stop letting me make calls, texts and use the Internet. Can power off and turn back on only to be able to use it for a few minuets and it seems to only happen at home.

    April 02 I got home about 9am and was trying to use my phone to send a text and notice that I was unable to send one. I kept getting the red ! telling me that my text wasn't sent so I tried making a call without success. I kept getting call failed. So I attempt to look something in the Internet and I would either get the busy icon or the network timed out message.  So I thought my service had been disconnected for some reason so I called AT&T to explain what was going on and to find out if my service had been interrupted without me knowing about it and the cust rep had me power down the phone and turn it back on and test it out and it appeared to be working until I got back home and it started all over again. I found myself having to power it off and on just so I could do things with it. Today I come to realize that this problem seem to only happen when I am home. I don't know what has changed at my home to cause this to be happening. I don't know what to do to fix this problem. Do anyone know what it could be.

    Settings > General > Reset > Reset Network Settings.
    If the problem continues, contact the carrier to report the issue again and insist they investigate network issues in your area.

  • NSLU2, how to make my files accessible in the internet

    I just bought nslu2 in order to have my files accesible in the internet but i havents find this kind of option in the administration web interfaced menu. 
    Can you help me?

    When you open the set-up page of NSLU2 click on Administration tab then cllick on the subtab System and look for Location...In Location check the option Enable FTP Server...

  • What are the settings i need to make MI Server available over the internet?

    Hello Everyone,
        I want MI Client to synchronize with MI Server through the internet. Can i any body tell me what all settings i need for that?
        Thanks in advance.

    hi
    IF you are working on a corporate network, i guess you have to contact your network pple to do this job.
    I don't know the exact procedure but it goes like - configuring a reverse proxy and registering your computer with your domain proxy et all..
    Google this book <b>"Internet Security and Firewalls by Sepna Vaid, V V Preetham"</b> it will give you info about networks, firewalls etc. 
    Regards
    ak

  • Should my DNS server be talking to the internet?

    I have the DNS service running on my OSX server in order to use Open Directory and server-based home folders. To use these server-based home folders I have to put the IP address of the server in the "DNS Server" entry on all the machines in Network Preferences.
    Because the workstations here would seem to be going to the file server for DNS, do I need to open ports on my router or something so that the server can provide this info? I'm having some weird email issues with emails not arriving in a timely manner (inter-office via the internet, some arrive days late) and slow response times in Safari (page takes a while to start loading, and then loads very quickly once server found) so I'm wondering if this is what's causing it.
    Any hints appreciated. Thanks!

    If you only use your own DNS on both server and LAN clients (you should with your setup of using the same domainname internally - a bit "ugly" but it works) you need to also setup any external services IP numbers such as any mail and web servers (and others).
    It wasn't me who set it up like this, but I'm stuck with it! What do you mean when you say to "setup any external services IP numbers"? DO you mean I need to tell the server where to find the mail server so that it finds it more easily? Where do I put them? And would it just be the mail server address, i.e. I assume I don't need to put in every website we want to access? No, that would be silly... but then... who knows.
    I would add forwarders (your ISP DNSes) to /etc/named.conf and turn off IPv6.
    In theory I know about these unix style text files, but do I need to be logged in as root to see them? I can't see the /etc directory and searching for named.conf brings up nothing. Also, I turned off IPv6 on the server and shortly after someone with a server based home folder got a message sayiing that they'd lost connection to all the mounted volumes on that server with "disconnect all". Turning IPv6 back on made that message go away so I don't want to play with that again for the time being!
    Is there a way to set these things up without resorting to editing text files? I'm an old-skool mac user and so it's a bit scary. I should have made that clear from the beginning. Thanks!

Maybe you are looking for

  • 10.5.7=restart=white screen=hard reset

    I know some of the threads have been about people not being able to get their display back. My issue is that when I choose restart from the apple menu, I end up with a white blank screen that stays that way until I hard reset my macbook (pressing pow

  • Iphone 5 wont turn on, charge or connect to itunes

    My daughters iphone 5 is about 18 months old, she's recently had problems with the battery draining from 100% - 0% in a matter of a couple of hours even when not in use. Last week the battery drained and wouldn't charge, i tried everything i could th

  • PAL or NTSC for international distribution?

    Hi everybody, we have a 5 hrs film shot and edited in Premiere Pro CS6 in HD pal, 50fps, 16:9  intended for international distribution on 2 double layer DVDs. How should we best author it to guarantee worldwide compatibility and best possible quality

  • Anonymous calls, Unknown Callers and 10 number limit on call blocking feature

    I have FIOS Digital Voice. I hope that someone can give me information to help me out - because like many others here, right now I am regretting having this and have it unplugged more than plugged in - for a service I am paying for. My number is unli

  • Cannot successfully update any vaults

    I just upgraded to Aperture 3 and since then have not been able to successfully update any of my vaults. The library became too large for the external drive that housed my A Vault so I added a new vault on a separate drive that has ample room. When I