IoS nuovo problemi con ACL
Inviato: mar 12 feb , 2008 11:51 pm
Sto spesso su Irc e sto cercando una configurazione +ttosto solida gh
In questo modo non esce e non capisco il perchè è online solo quando applico "no access-list 131" naviga solo senza Acl :\ help me plz
In questo modo non esce e non capisco il perchè è online solo quando applico "no access-list 131" naviga solo senza Acl :\ help me plz
Codice: Seleziona tutto
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
logging buffered 51200 warnings
enable secret 5 $1$7eLG$1UqkJXFMJFgcqw9YazUMV0
!
no aaa new-model
!
crypto pki trustpoint TP-self-signed-3148253242
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3148253242
revocation-check none
rsakeypair TP-self-signed-3148253242
!
!
crypto pki certificate chain TP-self-signed-3148253242
certificate self-signed 01
3082023E 308201A7 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33313438 32353332 3432301E 170D3038 30323032 30363236
32325A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 31343832
35333234 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100A820 97781145 DB876612 41F90E8D 5A7B4E21 64379846 F8933CE4 3FD24AC7
5E16F588 24DC92F5 644A4809 19D00B5B C8F92FB0 09385CA0 CC4B98E7 BE35F459
2B4CCA90 7C6EB88C F60D4CB8 7C45A3C4 EEC9D1BB 5AFD1EB8 0A80BD87 E10307EC
40BFE09A 32ED4456 1151EF76 369C17D8 E6FC9C7D 3A6FE022 CC324C5B 5F858B83
D0B10203 010001A3 66306430 0F060355 1D130101 FF040530 030101FF 30110603
551D1104 0A300882 06526F75 74657230 1F060355 1D230418 30168014 162A8001
6487346F 3D01A8BC 74012B57 DCF19872 301D0603 551D0E04 16041416 2A800164
87346F3D 01A8BC74 012B57DC F1987230 0D06092A 864886F7 0D010104 05000381
81006375 93302374 FEB555BF 141AECE1 70DAF862 05D24527 9FBBFAF4 3CD19CFE
A5A53EF6 AF8E6547 F59467C8 124F746A EDED1AFD A0C77AB4 62C4C3F4 1C259327
7FF0A1F3 F059AF4C FA0E3FDC A48809B5 47FAA36D 209A7F16 CB81B9B0 7CC667A6
074A6118 C1F8267B E0B57467 C1BD1753 646FC31C 69755800 AA973FF7 AB760DBA 8FE0
quit
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.2.1
!
ip dhcp pool Lan
network 192.168.2.0 255.255.255.0
dns-server 212.216.112.112 212.216.172.62
default-router 192.168.2.1
!
!
ip cef
ip inspect name MYFW tcp
ip inspect name MYFW udp
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
no ip domain lookup
ip name-server 212.216.112.112
ip name-server 212.216.172.62
!
!
!
username admin privilege 15 secret 5 $1$j3dp$cohb2tWIYE9ZG.vaUpJ/S.
!
!
archive
log config
hidekeys
!
!
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
no ip route-cache cef
no ip route-cache
no atm ilmi-keepalive
pvc 8/35
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl operating-mode auto
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Dot11Radio0
no ip address
shutdown
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
!
interface Vlan1
ip address 192.168.2.1 255.255.255.0
ip access-group 120 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
no ip route-cache cef
no ip route-cache
ip tcp adjust-mss 1452
no ip mroute-cache
!
interface Dialer0
ip address negotiated
ip access-group 131 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip inspect MYFW out
ip nat outside
ip virtual-reassembly
encapsulation ppp
no ip route-cache cef
no ip route-cache
no ip mroute-cache
dialer pool 1
no cdp enable
ppp pap sent-username [email protected] password 7 xxxxxxxxxxxxxxxxxxx
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 23 interface Dialer0 overload
!
access-list 23 permit 192.168.2.2
access-list 120 permit ip any any
access-list 131 remark *** ACL ANTI-SPOOFING ***
access-list 131 deny ip host 0.0.0.0 any log
access-list 131 deny ip 127.0.0.0 0.255.255.255 any log
access-list 131 deny ip 192.0.2.0 0.0.0.255 any log
access-list 131 deny ip 224.0.0.0 31.255.255.255 any log
access-list 131 deny ip 10.0.0.0 0.255.255.255 any log
access-list 131 deny ip 172.16.0.0 0.15.255.255 any log
access-list 131 deny ip 192.168.0.0 0.0.255.255 any log
access-list 131 remark *** ACL PER CONTROLLARE TRAFFICO ICMP ***
access-list 131 permit icmp any any echo
access-list 131 permit icmp any any echo-reply
access-list 131 permit icmp any any time-exceeded
access-list 131 permit icmp any any unreachable
access-list 131 permit icmp any any administratively-prohibited
access-list 131 permit icmp any any packet-too-big
access-list 131 permit icmp any any traceroute
access-list 131 deny icmp any any
access-list 131 remark *** ACL PER BLOCCARE L'ACCESSO A VIRUS E ATTACCHI ***
access-list 131 deny tcp any any eq 135
access-list 131 deny udp any any eq 135
access-list 131 deny udp any any eq netbios-ns
access-list 131 deny udp any any eq netbios-dgm
access-list 131 deny tcp any any eq 139
access-list 131 deny udp any any eq netbios-ss
access-list 131 deny tcp any any eq 445
access-list 131 deny tcp any any eq 593
access-list 131 deny tcp any any eq 2049
access-list 131 deny udp any any eq 2049
access-list 131 deny tcp any any eq 2000
access-list 131 deny tcp any any range 6000 6010
access-list 131 deny udp any any eq 1433
access-list 131 deny udp any any eq 1434
access-list 131 deny udp any any eq 5554
access-list 131 deny udp any any eq 9996
access-list 131 deny udp any any eq 113
access-list 131 deny udp any any eq 3067
access-list 131 remark *** ACL PER BLOCCARE ACCESSI NON AUTORIZZATI ***
access-list 131 deny ip any any log
no cdp run
!
control-plane
!
banner login ^CC
!
line con 0
login local
no modem enable
line aux 0
line vty 0 4
access-class 23 in
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
end