NAT pubblico privato
Inviato: mer 10 mag , 2006 5:06 pm
ciao a tutti, vi posto la mia configurazione:
service timestamps log datetime localtime
service password-encryption
service udp-small-servers
username xxxxxx password xxxxxxxx
no service tcp-small-servers
!
hostname t-
!
enable secret 5 xxxxxxxxxxxxxxx
!
ip subnet-zero
no ip source-route
ip domain-name interbusiness.it
ip name-server 151.99.125.2
!
!
!
!
no ip dhcp pool CLIENT
no ip dhcp excluded-address 10.10.10.1
no access-list 23
!
!
!
interface Ethernet0
ip address 88.xxx.yyy.zzz 255.255.255.248
ip access-group 102 out
no shut
!
!
interface ATM0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
no shut
!
!
interface ATM0.1 point-to-point
ip address 88.ddd.eee.fff 255.255.255.252
ip access-group 103 out
ip access-group 104 in
no ip directed-broadcast
bandwidth 128
pvc 8/35
oam-pvc manage 10
oam retry 5 5 1
encapsulation aal5snap
no shut
!
!
ip route 0.0.0.0 0.0.0.0 Atm0.1
ip route 151.99.0.0 255.255.0.0 Atm0.1
ip route 88.xxx.yyy.0 255.255.255.0 Atm0.1
!
!
logging buffered
ip classless
!
access-list 18 permit 151.99.126.0 0.0.0.255
access-list 19 permit 151.99.126.0 0.0.0.255
access-list 30 permit 151.99.252.8
access-list 30 permit 88.ddd.eee.fff
access-list 30 permit 151.99.6.2
access-list 30 permit 151.99.9.6
access-list 30 permit 151.99.126.0 0.0.0.255
access-list 102 deny ip 88.ddd.eee.fff 0.0.0.7 any
access-list 102 permit tcp any 88.ddd.eee.fff 0.0.0.7 established
access-list 102 permit ip any 88.ddd.eee.fff 0.0.0.7
access-list 103 permit udp 88.ddd.eee.fff 0.0.0.7 151.99.125.0 0.0.0.31 eq domain
access-list 103 permit tcp 88.ddd.eee.fff 0.0.0.7 151.99.125.0 0.0.0.31 gt 1023
access-list 103 permit tcp 88.ddd.eee.fff 0.0.0.7 host 151.99.126.5 eq www
access-list 103 permit icmp 88.ddd.eee.fff 0.0.0.7 151.99.0.0 0.0.127.255
access-list 103 permit icmp 88.ddd.eee.fff 0.0.0.7 195.31.0.0 0.0.127.255
access-list 103 permit ip 88.ddd.eee.fff 0.0.0.7 151.99.0.96 0.0.0.31
access-list 103 permit ip 88.ddd.eee.fff 0.0.0.7 151.99.125.0 0.0.0.31
access-list 103 deny ip 88.ddd.eee.fff 0.0.0.7 151.99.0.0 0.0.127.255
access-list 103 deny ip 88.ddd.eee.fff 0.0.0.7 195.31.0.0 0.0.127.255
access-list 103 permit ip 88.ddd.eee.fff 0.0.0.7 any
access-list 104 deny tcp any any eq 2065
access-list 104 permit ip any any
tacacs-server host 151.99.126.2
tacacs-server last-resort password
tacacs-server extended
tacacs-server notify connections
tacacs-server notify enable
snmp-server community public RO 18
snmp-server community private RW 19
snmp-server host 151.99.126.2 private
!
!
!
line con 0
login local
line vty 0 4
access-class 30 in
login tacacs
exit
se sulla scheda di rete del mio pc metto un ip pubblico assegnatomi navigo tranquillo.
Vorrei fare in modo, pero' che la eth0 del router sia identificata anche con un ip privato, in modo da mettere su tutti i pc della rete che voglio fare accedere ad internet l' ip privato del router come gateway.
Grazie
service timestamps log datetime localtime
service password-encryption
service udp-small-servers
username xxxxxx password xxxxxxxx
no service tcp-small-servers
!
hostname t-
!
enable secret 5 xxxxxxxxxxxxxxx
!
ip subnet-zero
no ip source-route
ip domain-name interbusiness.it
ip name-server 151.99.125.2
!
!
!
!
no ip dhcp pool CLIENT
no ip dhcp excluded-address 10.10.10.1
no access-list 23
!
!
!
interface Ethernet0
ip address 88.xxx.yyy.zzz 255.255.255.248
ip access-group 102 out
no shut
!
!
interface ATM0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
no shut
!
!
interface ATM0.1 point-to-point
ip address 88.ddd.eee.fff 255.255.255.252
ip access-group 103 out
ip access-group 104 in
no ip directed-broadcast
bandwidth 128
pvc 8/35
oam-pvc manage 10
oam retry 5 5 1
encapsulation aal5snap
no shut
!
!
ip route 0.0.0.0 0.0.0.0 Atm0.1
ip route 151.99.0.0 255.255.0.0 Atm0.1
ip route 88.xxx.yyy.0 255.255.255.0 Atm0.1
!
!
logging buffered
ip classless
!
access-list 18 permit 151.99.126.0 0.0.0.255
access-list 19 permit 151.99.126.0 0.0.0.255
access-list 30 permit 151.99.252.8
access-list 30 permit 88.ddd.eee.fff
access-list 30 permit 151.99.6.2
access-list 30 permit 151.99.9.6
access-list 30 permit 151.99.126.0 0.0.0.255
access-list 102 deny ip 88.ddd.eee.fff 0.0.0.7 any
access-list 102 permit tcp any 88.ddd.eee.fff 0.0.0.7 established
access-list 102 permit ip any 88.ddd.eee.fff 0.0.0.7
access-list 103 permit udp 88.ddd.eee.fff 0.0.0.7 151.99.125.0 0.0.0.31 eq domain
access-list 103 permit tcp 88.ddd.eee.fff 0.0.0.7 151.99.125.0 0.0.0.31 gt 1023
access-list 103 permit tcp 88.ddd.eee.fff 0.0.0.7 host 151.99.126.5 eq www
access-list 103 permit icmp 88.ddd.eee.fff 0.0.0.7 151.99.0.0 0.0.127.255
access-list 103 permit icmp 88.ddd.eee.fff 0.0.0.7 195.31.0.0 0.0.127.255
access-list 103 permit ip 88.ddd.eee.fff 0.0.0.7 151.99.0.96 0.0.0.31
access-list 103 permit ip 88.ddd.eee.fff 0.0.0.7 151.99.125.0 0.0.0.31
access-list 103 deny ip 88.ddd.eee.fff 0.0.0.7 151.99.0.0 0.0.127.255
access-list 103 deny ip 88.ddd.eee.fff 0.0.0.7 195.31.0.0 0.0.127.255
access-list 103 permit ip 88.ddd.eee.fff 0.0.0.7 any
access-list 104 deny tcp any any eq 2065
access-list 104 permit ip any any
tacacs-server host 151.99.126.2
tacacs-server last-resort password
tacacs-server extended
tacacs-server notify connections
tacacs-server notify enable
snmp-server community public RO 18
snmp-server community private RW 19
snmp-server host 151.99.126.2 private
!
!
!
line con 0
login local
line vty 0 4
access-class 30 in
login tacacs
exit
se sulla scheda di rete del mio pc metto un ip pubblico assegnatomi navigo tranquillo.
Vorrei fare in modo, pero' che la eth0 del router sia identificata anche con un ip privato, in modo da mettere su tutti i pc della rete che voglio fare accedere ad internet l' ip privato del router come gateway.
Grazie