Current configuration : 6972 bytes
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ROUTER
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging buffered 51200
logging console critical
enable secret 5 $1$gFp9$nZGEOrAK095.lbPoUPqZi1
!
no aaa new-model
clock timezone PCTime 1
clock summer-time PCTime date Mar 30 2003 2:00 Oct 26 2003 3:00
!
crypto pki trustpoint TP-self-signed-286133521
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-286133521
revocation-check none
rsakeypair TP-self-signed-286133521
!
!
crypto pki certificate chain TP-self-signed-286133521
certificate self-signed 01
30820249 308201B2 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32383631 33333532 31301E17 0D303831 31313731 38353433
385A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3238 36313333
35323130 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
D839A81B D7D77012 DD8D02DF 7B7DC861 76DF4CA8 F80AB87B 54AFE407 383778D0
BD9D2982 0D0A4FF6 54B0FA86 33262172 21E0CD65 CE3679F4 944CF118 4DE71C90
57458BB8 25806A81 949C5F38 CBD26C30 8D511EA6 A7AE4435 BEB4550D 567D8DBD
quit
dot11 syslog
no ip source-route
ip cef
!
!
!
!
no ip bootp server
ip domain name SHAREZONE.IT
ip name-server 62.94.0.41
ip name-server 62.94.0.42
!
multilink bundle-name authenticated
!
!
username admin privilege 15 secret 5 $1$vYtg$dmp2aNyo8qB.hA5oS2nyT.
!
!
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $FW_OUTSIDE$$ES_WAN$
pvc 8/35
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 192.168.2.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1452
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname
[email protected]
ppp chap password 7 040D5F12032B444A1349
ppp pap sent-username
[email protected] password 7 07597558420311010D42
crypto map SDM_CMAP_2
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source route-map SDM_RMAP_1 interface Dialer0 overload
ip nat inside source static tcp 192.168.2.250 80 62.94.192.153 80 extendable
e
!
ip access-list extended Share
remark SDM_ACL Category=2
remark IPSec Rule
deny ip 192.168.2.0 0.0.0.255 168.66.10.0 0.0.0.255
permit ip any any
ip access-list extended WEB
remark Sito SHAREZONE
remark SDM_ACL Category=2
permit tcp any eq www host 192.168.2.251 eq www
!
logging trap debugging
access-list 101 remark SDM_ACL Category=4
access-list 101 remark IPSec Rule
access-list 101 permit ip 192.168.2.0 0.0.0.255 168.66.10.0 0.0.0.255
dialer-list 1 protocol ip permit
no cdp run
!
!
!
route-map SDM_RMAP_1 permit 1
manca la parte vpn che non ho messo per sicurezza e la parte certificato
per il catalyst visto che tanto lo devo riconfigurare tutto
eventualmente gli posso mandare i comandi