moved a working network, now it doesn't work



Our office moved from one facility to another (different cities).

We took a working lan from one site, and reconstituted it at the new
site. Now it only sort of works. (BTW, all linux machines)

I have a 2611 router w/VPN module, 12.2(8r) IOS:

1) fast0/0 connects to the internet (straight up, no firewall)
2) fast0/1 connects to our internal network


interface FastEthernet0/0
ip address 64.0.0.228 255.255.255.248
ip nat outside
no ip route-cache
no ip mroute-cache
speed auto
duplex auto
crypto map nolan
!
interface FastEthernet0/1
ip address 192.168.25.1 255.255.255.0
ip nat inside
speed auto
duplex auto
!
ip route 0.0.0.0 0.0.0.0 64.0.0.225


from the router console, I can ping anything I would like (yahoo
google 4.2.2.1)
from the internal network (192.168.25.47) I can ping 192.168.25.XXX
without trouble

Output of netstat is :

Destination Gateway Genmask Flags MSS Window irtt Iface
192.168.25.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
0.0.0.0 192.168.25.1 0.0.0.0 UG 0 0 0 eth0

I cannot ping anything outside (for example 4.2.2.1) . And, anytime I
try to traceroute locally (besides the router), I get very weird
results:

traceroute to 192.168.25.180 (192.168.25.180), 30 hops max, 40 byte
packets
1 * * *
2 * * *
3 * * *
4 * * *
5 * * *
6 192.168.25.180 1.544 ms 1.581 ms 1.564 ms

traceroute 4.2.2.1 to the internet returns nothing

traceroute to 4.2.2.1 (4.2.2.1), 30 hops max, 40 byte packets
1 ausrouter (192.168.25.1) 2.965 ms 4.437 ms 4.936 ms
2 * * *
3 * * *
4 * * *
5 * * *
6 * * *
7 * * *
.....
30 * * *

I've run wireshark on this network and it doesn't appear to ever hit
the router (192.168.25.1)
I've done the same test on a functionally identical network (machine
192.168.35.120, router 192.168.35.1) and find that I get a TTL
exceeded from 192.168.35.1 after the 4th attempt

The strangest part? This worked for a couple of days two weeks ago but
someone power cycled before a write mem and so it can't be retrieved.
My only recollection from those edits was that I changed the speed and
duplex of the 0/0 and 0/1 (but I can't be sure)
.



Relevant Pages

  • Re: moved a working network, now it doesnt work
    ... ip nat outside ... from the internal network I can ping 192.168.25.XXX ... try to traceroute locally (besides the router), ... Can you source a ping from the router to the internet (type ...
    (comp.dcom.sys.cisco)
  • Re: moved a working network, now it doesnt work
    ... router I can ping the internet with no problem. ... From one of your Linux machines can you ping the FA 0/1 interface ...
    (comp.dcom.sys.cisco)
  • Iptables or misconfiguration?
    ... I'm building up a router with IPTABLES. ... internal network from the internet. ... machines communicate with the router. ... When I try to ping some 192.168.0. ...
    (comp.unix.admin)
  • Re: Networking problem
    ... machine 2# HP Z8000 laptop xp media center on board lan and 802.11 windows firewall off. ... router linksys befw11s4 ... Network activity lights flash on the router on the port in use. ... I finally got it to the point that from the desktop i can ping the ip ...
    (microsoft.public.windowsxp.general)
  • SECURITY RISK: ZyXEL ADSL Router 642R - WAN filter bypass from internal network
    ... Subject: SECURITY RISK: ZyXEL ADSL Router 642R - WAN filter bypass from internal network ...
    (Bugtraq)