Ho inserito le seguenti rige:
Codice: Seleziona tutto
ip nat inside source static tcp [ip pc interno] 3389 [ip statico pubblico] 3389 extendable
Codice: Seleziona tutto
access-list 111 permit icmp any any administratively-prohibited
access-list 111 permit icmp any any echo
access-list 111 permit icmp any any echo-reply
access-list 111 permit icmp any any packet-too-big
access-list 111 permit icmp any any time-exceeded
access-list 111 permit icmp any any traceroute
access-list 111 permit icmp any any unreachable
access-list 111 permit udp any any eq ntp
access-list 111 permit tcp any any eq 139
access-list 111 permit tcp any any eq 3389
access-list 111 permit udp any any eq netbios-ns
access-list 111 permit udp any any eq netbios-dgm
access-list 111 permit tcp any any established
access-list 111 permit udp any eq domain any
Però non mi funziona .
dove sbaglio ?????????
TIA
P.S. l'interfaccia verso l'esterno è atm0.1 ...devo specificare quella...?
Ho anche le seguenti regole di inspect:
Codice: Seleziona tutto
ip inspect name FW ftp
ip inspect name FW h323
ip inspect name FW smtp
ip inspect name FW udp
ip inspect name FW fragment maximum 256 timeout 1
ip inspect name FW tftp
ip inspect name FW tcp
ip audit notify log
ip audit po max-events 100