Cisco 877 - Config. ip pubblico e routing su singola eth
Inviato: mar 15 lug , 2008 9:54 am
Il router e' un Cisco 877-K9: mantenendo questa configurazione (funzionante), dovrei configurare una sola eth con uno degli ip pubblici assegnati (che per ora nella configurazione non compaiono), mantenendo le altre sulla rete privata, e indirizzare correttamente tutto il traffico da e per questo ip pubblico su questa porta. Tutto questo per connetterla direttamente ad un centralino VoIp
Non mi e' molto chiaro dov'e' dichiarato quali eth vengono associate alla VLan esistente: prende automaticamente quelle per cui non viene specificata nessuna configurazione sotto alla riga (ad esempio) "interface FastEthernet3"?
Potete darmi qualche dritta sulle righe di configurazione della interfaccia, e sul routing?
Questa e' la parte centrale della configurazione, ho tagliato solo le cose completamente irrilevanti in testa e in coda:
------------------------------------------------------------
ip subnet-zero
no ip source-route
ip cef
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.5.1 192.168.5.24
ip dhcp excluded-address 192.168.5.36 192.168.5.254
!
ip dhcp pool pool1
import all
network 192.168.5.0 255.255.255.0
default-router 192.168.5.1
!
!
ip tcp synwait-time 10
no ip bootp server
ip domain name ***********
ip name-server 208.67.222.222
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
crypto pki trustpoint TP-self-signed-***********
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-***********
revocation-check none
rsakeypair TP-self-signed-***********
!
!
crypto pki certificate chain TP-self-signed-***********
certificate self-signed 01
***********
quit
username *********** privilege 15 secret 5 ***********
!
!
!
!
!
interface ATM0
description Adsl ***********
no ip address
no ip route-cache cef
no ip route-cache
no ip mroute-cache
no atm ilmi-keepalive
bundle-enable
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description Wind
ip address X.X.X.90 255.255.255.192
ip nat outside
no ip route-cache
no ip mroute-cache
no snmp trap link-status
pvc 8/35
encapsulation aal5snap
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description Private Lan
ip address 192.168.5.1 255.255.255.0
no ip redirects
ip nat inside
ip pim sparse-dense-mode
no ip route-cache cef
no ip route-cache
no ip mroute-cache
!
ip route 0.0.0.0 0.0.0.0 X.X.X.65
!
no ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 101 interface ATM0.1 overload
!
logging trap debugging
access-list 3 permit 161.27.15.0 0.0.0.255
access-list 101 permit ip 192.168.5.0 0.0.0.255 any
!
--
Samuele
Non mi e' molto chiaro dov'e' dichiarato quali eth vengono associate alla VLan esistente: prende automaticamente quelle per cui non viene specificata nessuna configurazione sotto alla riga (ad esempio) "interface FastEthernet3"?
Potete darmi qualche dritta sulle righe di configurazione della interfaccia, e sul routing?
Questa e' la parte centrale della configurazione, ho tagliato solo le cose completamente irrilevanti in testa e in coda:
------------------------------------------------------------
ip subnet-zero
no ip source-route
ip cef
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.5.1 192.168.5.24
ip dhcp excluded-address 192.168.5.36 192.168.5.254
!
ip dhcp pool pool1
import all
network 192.168.5.0 255.255.255.0
default-router 192.168.5.1
!
!
ip tcp synwait-time 10
no ip bootp server
ip domain name ***********
ip name-server 208.67.222.222
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
crypto pki trustpoint TP-self-signed-***********
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-***********
revocation-check none
rsakeypair TP-self-signed-***********
!
!
crypto pki certificate chain TP-self-signed-***********
certificate self-signed 01
***********
quit
username *********** privilege 15 secret 5 ***********
!
!
!
!
!
interface ATM0
description Adsl ***********
no ip address
no ip route-cache cef
no ip route-cache
no ip mroute-cache
no atm ilmi-keepalive
bundle-enable
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description Wind
ip address X.X.X.90 255.255.255.192
ip nat outside
no ip route-cache
no ip mroute-cache
no snmp trap link-status
pvc 8/35
encapsulation aal5snap
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description Private Lan
ip address 192.168.5.1 255.255.255.0
no ip redirects
ip nat inside
ip pim sparse-dense-mode
no ip route-cache cef
no ip route-cache
no ip mroute-cache
!
ip route 0.0.0.0 0.0.0.0 X.X.X.65
!
no ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 101 interface ATM0.1 overload
!
logging trap debugging
access-list 3 permit 161.27.15.0 0.0.0.255
access-list 101 permit ip 192.168.5.0 0.0.0.255 any
!
--
Samuele