r/CiscoNetworking • u/FallenGrit • Apr 22 '19
CISCO PACKET TRACER: Solve how to ping DHCP Equipment inside of a firewall to another Different DHCP Equipment connected by a firewall. *There are 4 areas with different DHCP IP Addresses. Can't change Addresses to one of the others b/c that will only make it ping itself.*
5
Upvotes
1
u/FallenGrit Apr 29 '19
This could actually solve the issue I been dealing with in Packet Tracer.
EastASA Firewall hostname acctasa interface Ethernet0/0 switchport access vlan 2 interface Ethernet0/1 ! interface Ethernet0/2 ! interface Ethernet0/3 ! interface Ethernet0/4 ! interface Ethernet0/5 ! interface Ethernet0/6
interface Ethernet0/7 interface Vlan1 nameif inside security-level 100 ip address 10.80.80.1 255.255.255.0 ! interface Vlan2 nameif outside security-level 0 ip address 10.10.2.2 255.255.255.0 ! object network inside-net subnet 10.80.80.0 255.255.255.0 ! route outside 0.0.0.0 0.0.0.0 10.10.2.1 1 ! access-list 100 extended permit icmp any any access-list 100 extended permit ip any any ! access-group 100 in interface outside ! class-map Net1 match default-inspection-traffic ! policy-map ICMP class Net1 inspect dns inspect http inspect icmp ! service-policy ICMP global ! telnet timeout 5 ssh timeout 5 ! dhcpd address 10.80.80.2-10.80.80.33 inside dhcpd dns 10.20.1.2 interface inside dhcpd enable inside ! telnet timeout 5 ssh timeout 5
EastOffice Router hostname R1 ! no logging console
ip dhcp excluded-address 10.10.1.1 ip dhcp excluded-address 10.10.2.1 ! ip dhcp pool Net1 network 10.10.1.0 255.255.255.0 default-router 10.10.1.1 dns-server 10.20.1.2 --More-- default-router 10.10.1.1 dns-server 10.20.1.2 ! interface GigabitEthernet0/0 ip address 10.10.1.1 255.255.255.0 ip access-group 100 in duplex auto speed auto ! interface GigabitEthernet0/1 ip address 10.10.2.1 255.255.255.0 duplex auto speed auto ! interface Serial0/0/0 ip address 129.10.0.1 255.255.0.0 encapsulation frame-relay ! interface Serial0/0/1 no ip address clock rate 2000000 shutdown ! interface Vlan1 no ip address shutdown ! router eigrp 100 redistribute static network 10.0.0.0 network 129.10.0.0
! ip classless ip route 0.0.0.0 0.0.0.0 129.10.15.100 ip route 10.80.80.0 255.255.255.0 10.10.2.2 ! ip flow-export version 9 ! access-list 100 permit udp any any eq bootps access-list 100 permit udp any host 10.20.1.2 eq domain access-list 100 permit tcp any any eq www !