leggendo qui sul foro mi sembra che si consigliasse per il corretto funzionamento dei software della rete e per una sicurezza discreta il discorso citato nel subject.
adesso riporto parte della mia config ( che e' quella di default riguardo gli ICMP)
e vi chiedo come si puo' modificare in modo che funga nel modo descritto in precedenza: tenendo conto che sul pc 192.168.1.2 girano emule e un server ftp (il mulo potrebbe aver bisogno dei ping??)
come al solito: grazie


Codice: Seleziona tutto
no ip http server
no ip http secure-server
ip nat translation timeout 3600
ip nat translation tcp-timeout 3600
ip nat translation max-entries 6000
ip nat inside source list 102 interface Dialer1 overload
ip nat inside source static tcp 192.168.1.2 6881 interface Dialer1 6881
ip nat inside source static tcp 192.168.1.2 4662 interface Dialer1 4662
ip nat inside source static udp 192.168.1.2 4672 interface Dialer1 4672
ip nat inside source static tcp 192.168.1.5 22 interface Dialer1 22
ip nat inside source static tcp 192.168.1.2 21 interface Dialer1 21
!
!
logging trap debugging
logging 192.168.1.2
access-list 23 permit 192.168.1.0 0.0.0.255
access-list 102 permit ip 192.168.1.0 0.0.0.255 any
access-list 111 permit tcp any any eq ftp
access-list 111 permit tcp any any eq 22
access-list 111 permit udp any any eq 4672
access-list 111 permit tcp any any eq 4662
access-list 111 permit tcp any any eq 6881
access-list 111 permit icmp any any administratively-prohibited
access-list 111 permit icmp any any echo
access-list 111 permit icmp any any echo-reply
access-list 111 permit icmp any any packet-too-big
access-list 111 permit icmp any any time-exceeded
access-list 111 permit icmp any any traceroute
access-list 111 permit icmp any any unreachable
access-list 111 permit udp any eq domain any
access-list 111 permit esp any any
access-list 111 permit udp any any eq isakmp
access-list 111 permit gre any any
access-list 111 permit tcp any any established
access-list 111 deny ip any any log
dialer-list 1 protocol ip permit
!
control-plane
!