Pagina 1 di 2

Urgente a dir poco... Cisco 857 con Alice 7 mega ip dinamico

Inviato: gio 27 mag , 2010 11:45 am
da raffa82
Ciao a tutti voi,
il mio problema e' configurare un cisco 857 su linea Alice ADSL 7 mega a ip dinamico (la classica linea di base).
Premessa: mai avuta esperienza sui Cisco, quindi i tentativi li ho fatti con SDM Express e SDM installata, per lo + usando il wizard.
Ecco i dati raggiunti dal mio non breve sbattimento:
- la spia CD del router si accende, lampeggia per un po e poi resta fissa, praticamente con tutti i tentativi fatti.
- la spia ppp si e' accesa solo usando incapsulamento PPPoE e indirizzo ip wan assegnato con DHCP (il tutto sempre da SDM Express).
- Usando il wizard setto sempre il NAT


Ad ogni tentativo faccio un reset del router e uso SDM Express Wizard per la configurazione iniziale, i passaggi che seguo sono questi (con i valori del tentativo + plausibile in teoria, secondo anche i pochi dati che ho avuto chiamando telecom):
1. pagina iniziale: lascio "hostname" e "domain name" come di default, (yourname / yourdomain.com )ho pensato che e' irrilevante nel mio caso. Inserisco i miei username e password.
2. lan interface: lascio di default l'ip del router a 10.10.10.1
3. dhcp server: setto il range 10.10.10.2 - 10.10.10.254 . Inserisco i due dns di interbusiness 151.99.125.2 e 151.99.125.3 . Dico infine che i client non useranno questi server dns con il dhcp ma che useranno l'ip del router come dns server.
4. WAN CONFIGURATION:
- Encapsulation: PPPoE
- VPI: 8
- VCI: 35
- Address type: IP Negotiated
- Authentication Type: seleziono entrambi CHAP e PAP
- Username a password: aliceadsl per tutti e due
5. Internet (WAN) - Advanced Options: lascio come di default, ovvero lascio selezionato "Create Default Route" e "Use This Interface as Forwarding Interface"
6. Internet (WAN) - Private IP Address: lascio anche qui di default, ovvero lascio selezionato "Enable NAT", non aggiungo nessun mapping nella finestra dei port address mappings.
7. Firewall: seleziono che non voglio usare il firewall per ora (gia' troppi problemi cosi')
8. Security configuration: lascio come di default, ovvero tutto selezionato

Al che salvo tutto e accedo alla Cisco SDM, recupero quindi la configurazione cosi ottenuta che e' questa:

Building configuration...

Current configuration : 5527 bytes
!
! Last configuration change at 10:41:30 PCTime Thu May 27 2010 by ca
! NVRAM config last updated at 10:39:05 PCTime Thu May 27 2010 by cisco
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname yourname
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$nYGp$JJdEYPdRt3GSei0ncmo22.
!
no aaa new-model
clock timezone PCTime 0
!
crypto pki trustpoint TP-self-signed-1553173071
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1553173071
revocation-check none
rsakeypair TP-self-signed-1553173071
!
!
crypto pki certificate chain TP-self-signed-1553173071
certificate self-signed 01
3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31353533 31373330 3731301E 170D3032 30333031 30323534
35315A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 35353331
37333037 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100B9CE 20366D28 AFC314FA B1762A04 364AD944 B09EB059 BFFF5E1B 674641C3
9463ACDF 3DA669DA 18129450 0EE3175C B31950DC 0C01B4FA 3927D8B9 3140405A
EACBB8FD 21202307 479999FD BD3CFC3D 1762FCC0 6DACDDBF D530813A 8C864F75
FED49796 12F911E2 3A3424AF 0E10CB9F C0471BC2 F52C7AF8 292DDFA3 A5B13398
76250203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D
301F0603 551D2304 18301680 147AF5F4 A2533019 61CC618C D20AFADC 1808A5C1
7C301D06 03551D0E 04160414 7AF5F4A2 53301961 CC618CD2 0AFADC18 08A5C17C
300D0609 2A864886 F70D0101 04050003 8181007C F9D813B0 299BEBBA 69E26BA1
FB7540E8 AA44874F 362D4157 A78C9C9F 019B4854 85E0E78B D807495C 7D487131
DC0714BD 89137331 ED39B0BD E620A241 33B9B221 4C5E8015 D68A6673 4597CA35
38C5C49B FD392F8E F104E375 3A46753A 3FCFF163 86AEF830 88583AD5 D4CCF073
F2717DB0 9B39EB6B 1224542D 90DC0FC6 BFDA81
quit
dot11 syslog
no ip source-route
no ip dhcp use vrf connected
ip dhcp excluded-address 10.10.10.1
!
ip dhcp pool sdm-pool1
import all
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
!
!
ip cef
no ip bootp server
ip domain name yourdomain.com
ip name-server 151.99.125.2
ip name-server 151.99.125.3
!
!
!
username ca privilege 15 secret 5 $1$MGae$4tqsHB881nWxfbjefzlgl0
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 10.10.10.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1412
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname aliceadsl
ppp chap password 7 045A070F0C244D4A1A15
ppp pap sent-username aliceadsl password 7 00051F0F075E0A021C2D
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface Dialer0 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 10.10.10.0 0.0.0.255
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end

A questo punto la spia CD e' accesa e' fissa, la spia PPP e' spenta. Il computer non naviga.
Spero tanto possiate darmi una mano.
Grazie

Re: Urgente a dir poco... Cisco 857 con Alice 7 mega ip dina

Inviato: gio 27 mag , 2010 6:17 pm
da valerio1976
raffa82 ha scritto: Premessa: mai avuta esperienza sui Cisco, quindi i tentativi li ho fatti con SDM Express e SDM installata, per lo + usando il wizard.
Ecco i dati raggiunti dal mio non breve sbattimento:
- la spia CD del router si accende, lampeggia per un po e poi resta fissa, praticamente con tutti i tentativi fatti.
- la spia ppp si e' accesa solo usando incapsulamento PPPoE e indirizzo ip wan assegnato con DHCP (il tutto sempre da SDM Express).
- Usando il wizard setto sempre il NAT


Ad ogni tentativo faccio un reset del router e uso SDM Express Wizard per la configurazione iniziale, i passaggi che seguo sono questi (con i valori del tentativo + plausibile in teoria, secondo anche i pochi dati che ho avuto chiamando telecom):
1. pagina iniziale: lascio "hostname" e "domain name" come di default, (yourname / yourdomain.com )ho pensato che e' irrilevante nel mio caso. Inserisco i miei username e password.
2. lan interface: lascio di default l'ip del router a 10.10.10.1
3. dhcp server: setto il range 10.10.10.2 - 10.10.10.254 . Inserisco i due dns di interbusiness 151.99.125.2 e 151.99.125.3 . Dico infine che i client non useranno questi server dns con il dhcp ma che useranno l'ip del router come dns server.
4. WAN CONFIGURATION:
- Encapsulation: PPPoE
- VPI: 8
- VCI: 35
- Address type: IP Negotiated
- Authentication Type: seleziono entrambi CHAP e PAP
- Username a password: aliceadsl per tutti e due
5. Internet (WAN) - Advanced Options: lascio come di default, ovvero lascio selezionato "Create Default Route" e "Use This Interface as Forwarding Interface"
6. Internet (WAN) - Private IP Address: lascio anche qui di default, ovvero lascio selezionato "Enable NAT", non aggiungo nessun mapping nella finestra dei port address mappings.
7. Firewall: seleziono che non voglio usare il firewall per ora (gia' troppi problemi cosi')
8. Security configuration: lascio come di default, ovvero tutto selezionato

Al che salvo tutto e accedo alla Cisco SDM, recupero quindi la configurazione cosi ottenuta che e' questa:

Building configuration...

Current configuration : 5527 bytes
!
! Last configuration change at 10:41:30 PCTime Thu May 27 2010 by ca
! NVRAM config last updated at 10:39:05 PCTime Thu May 27 2010 by cisco
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname yourname
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$nYGp$JJdEYPdRt3GSei0ncmo22.
!
no aaa new-model
clock timezone PCTime 0
!
crypto pki trustpoint TP-self-signed-1553173071
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1553173071
revocation-check none
rsakeypair TP-self-signed-1553173071
!
!
crypto pki certificate chain TP-self-signed-1553173071
certificate self-signed 01
3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31353533 31373330 3731301E 170D3032 30333031 30323534
35315A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 35353331
37333037 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100B9CE 20366D28 AFC314FA B1762A04 364AD944 B09EB059 BFFF5E1B 674641C3
9463ACDF 3DA669DA 18129450 0EE3175C B31950DC 0C01B4FA 3927D8B9 3140405A
EACBB8FD 21202307 479999FD BD3CFC3D 1762FCC0 6DACDDBF D530813A 8C864F75
FED49796 12F911E2 3A3424AF 0E10CB9F C0471BC2 F52C7AF8 292DDFA3 A5B13398
76250203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D
301F0603 551D2304 18301680 147AF5F4 A2533019 61CC618C D20AFADC 1808A5C1
7C301D06 03551D0E 04160414 7AF5F4A2 53301961 CC618CD2 0AFADC18 08A5C17C
300D0609 2A864886 F70D0101 04050003 8181007C F9D813B0 299BEBBA 69E26BA1
FB7540E8 AA44874F 362D4157 A78C9C9F 019B4854 85E0E78B D807495C 7D487131
DC0714BD 89137331 ED39B0BD E620A241 33B9B221 4C5E8015 D68A6673 4597CA35
38C5C49B FD392F8E F104E375 3A46753A 3FCFF163 86AEF830 88583AD5 D4CCF073
F2717DB0 9B39EB6B 1224542D 90DC0FC6 BFDA81
quit
dot11 syslog
no ip source-route
no ip dhcp use vrf connected
ip dhcp excluded-address 10.10.10.1
!
ip dhcp pool sdm-pool1
import all
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
!
!
ip cef
no ip bootp server
ip domain name yourdomain.com
ip name-server 151.99.125.2
ip name-server 151.99.125.3
!
!
!
username ca privilege 15 secret 5 $1$MGae$4tqsHB881nWxfbjefzlgl0
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 10.10.10.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1412
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname aliceadsl
ppp chap password 7 045A070F0C244D4A1A15
ppp pap sent-username aliceadsl password 7 00051F0F075E0A021C2D
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface Dialer0 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 10.10.10.0 0.0.0.255
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end

A questo punto la spia CD e' accesa e' fissa, la spia PPP e' spenta. Il computer non naviga.
Spero tanto possiate darmi una mano.
Grazie
ma scusa l'ignoranza ma che vuoi fare ?

Inviato: ven 28 mag , 2010 8:26 am
da raffa82
Vorrei poter navigare con i pc connessi al cisco.
I pc prendono prendono gli indirizzi ip con il dhcp del cisco ma non vanno online.
Solo secondariamente, e se possibile, volevo anche configurare un DDNS nel cisco, anche questo non saprei come fare.
Ricordo che e' la prima volta che metto mani su un cisco.

Inviato: ven 28 mag , 2010 9:17 am
da Wizard
Nn mi sembra di vedere grossi errori nella config, prova a fare un "sh ip int brief" per vedere se la dialer prende un ip etc

Crea un account alice e usa quello per autenticarti e non il default

Inviato: ven 28 mag , 2010 10:12 am
da raffa82
Wizard ha scritto:Nn mi sembra di vedere grossi errori nella config, prova a fare un "sh ip int brief" per vedere se la dialer prende un ip etc

Crea un account alice e usa quello per autenticarti e non il default
Grazie mille wizard per l'occhiata!

Il punto e' che in questo modo la spia cd si accende e resta fissa, la spia ppp resta spenta, e il pc non naviga.

Quando dici di crearmi un account alice intendi un semplice account di posta elettronica ad esempio? be immagino di si.

Ok provero' creando questo account, speriamo bene. Grazie ancora.

Inviato: ven 28 mag , 2010 11:33 am
da valerio1976
ciao secondo me manca un po di roba

interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
encapsulation aal5mux ppp dialer <-----questo

ppp chap hostname aliceadsl
ppp chap password 7 045A070F0C244D4A1A15 <----QUESTA DOVREBBE ESSERE UGUALE A
ppp pap sent-username aliceadsl password 7 00051F0F075E0A021C2D <---QUESTA



ciao

Inviato: ven 28 mag , 2010 12:11 pm
da raffa82
Grazie mille Valerio. Provero' con le tue modifiche.
Nel frattempo mi sono accorto che quando collego il pc al router non viene assegnato alcun dns dal dhcp, quindi tramite SDM sono andato a settare come dns l'indirizzo del router, spero che cosi il dns del router possa permettere ai pc di trovare le altre macchine nella rete locale.
Inoltre ho modificato l'ip del router in 192.168.123.1 , e il pool del dhcp in 192.168.123.2 - 192.168.123.200. Infine ho creato l'account di posta alice ed ho inserito i parametri di accesso nell'autenticazione adsl, cosi' come ha detto wizard.

Ho quindi aperto il file di configurazione cosi ottenuto ed ho applicato le tue 2 modifiche.
Provero' oggi pomeriggio.

Ecco il risultato di tutte le modifiche
Building configuration...

Current configuration : 5635 bytes
!
! Last configuration change at 10:55:50 PCTime Fri May 28 2010 by ca
! NVRAM config last updated at 10:36:30 PCTime Fri May 28 2010 by cisco
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname admin
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$5L7J$3bZk4zsBYBs386eRu8jdv0
!
no aaa new-model
clock timezone PCTime 0
!
crypto pki trustpoint TP-self-signed-1553173071
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1553173071
revocation-check none
rsakeypair TP-self-signed-1553173071
!
!
crypto pki certificate chain TP-self-signed-1553173071
certificate self-signed 01
3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31353533 31373330 3731301E 170D3032 30333031 30323534
35335A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 35353331
37333037 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ABD7 C961C898 80F31BAF 11C11CE0 C23B8A04 9F6DC15F 4ED7829B 9E58A8BE
0D9E8E84 5D95D2A4 D87385FF 8E1AAEA5 E8C1D625 D3E1FAF4 4F069BF6 04554455
0F8825B6 FC374C69 25B8768D C1BA1668 1674E563 EF2F5B6D 7326C0CA 88F97674
49B912E5 2D718C09 39A6132D FA1EC58A 40F218B4 782D551D 7E07F4FA CECAE68E
AA8F0203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D
301F0603 551D2304 18301680 14F17676 A20F6DAA 1F9A54CD 6D09213E 06CAD107
B9301D06 03551D0E 04160414 F17676A2 0F6DAA1F 9A54CD6D 09213E06 CAD107B9
300D0609 2A864886 F70D0101 04050003 81810085 28393BBF 0D5583E1 A7C56D5C
FED4A293 293600DD 44866594 B8081817 3AAA549F 7F846685 655F7F8A 227EB71C
FEB60766 681431C2 FD1A55EA 6705255C 2A4973A6 72E5A91C 1C969AB7 1859B186
B908A841 4A2749D2 5EDCBF1C 9D92F67B 2D8D96D1 7FD2A3C4 FEC677B3 47696E0C
44F63FD0 4ADEE73C 6DB562AB EA97BAA8 651FAE
quit
dot11 syslog
no ip source-route
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.123.1
ip dhcp excluded-address 192.168.123.201 192.168.123.254
!
ip dhcp pool sdm-pool1
import all
network 192.168.123.0 255.255.255.0
default-router 192.168.123.1
dns-server 192.168.123.1
!
!
ip cef
no ip bootp server
ip domain name admin.com
ip name-server 212.216.112.112
ip name-server 212.216.172.62
!
!
!
username ca privilege 15 secret 5 $1$uF9e$ckxmIvCJwoiKr2l6wdqls/
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
encapsulation aal5mux ppp dialer
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 192.168.123.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1412
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname [email protected]
ppp chap password 7 010703144B02151B20
ppp pap sent-username [email protected] password 7 010703144B02151B20
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface Dialer0 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.123.0 0.0.0.255
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end


Inviato: ven 28 mag , 2010 12:33 pm
da raffa82
Ehi ma...un secondo. ho caricato la configurazione sopra nel cisco tramite SDM, sono andato a controllare che effettivamente fosse uguale a quello che ho messo io, e invece di trovarmi questo:
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
encapsulation aal5mux ppp dialer
!
!
interface FastEthernet0
!
Mi sono trovato questo:
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
encapsulation aal5mux ppp dialer
!
!
interface FastEthernet0
!
Cioe' mi ha tolto la riga:
pppoe-client dial-pool-number 1

:shock:

Inviato: ven 28 mag , 2010 1:04 pm
da valerio1976
raffa82 ha scritto:Ehi ma...un secondo. ho caricato la configurazione sopra nel cisco tramite SDM, sono andato a controllare che effettivamente fosse uguale a quello che ho messo io, e invece di trovarmi questo:
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
encapsulation aal5mux ppp dialer
!
!
interface FastEthernet0
!
Mi sono trovato questo:
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
encapsulation aal5mux ppp dialer
!
!
interface FastEthernet0
!
Cioe' mi ha tolto la riga:
pppoe-client dial-pool-number 1

:shock:
ma sarà perchè io mi incasino con sdm ...ma non fai prima con la console ???

Inviato: ven 28 mag , 2010 2:51 pm
da raffa82
Ahime' non saprei cosa scriverci in console, non conosco proprio i comandi dei cisco!
In ogni caso pensavo: la riga che mi hai detto di aggiungere, cioe':
encapsulation aal5mux ppp dialer
specifica quale' l'incapsulamento, giusto? La riga precedente, cioe':
pppoe-client dial-pool-number 1
specifica anch'essa l'incapsulamento?
Non e' che viene tolta quella preesistente, ovvero la seconda, perche' non possono esistere due tipi diversi di incapsulamento sulla stessa scheda?

Eventualmente quali sarebbero i comandi per usare la configurazione che dici?

Io, sempre con SDM, ho avuto problemi a cambiare l'incapsulamento della scheda in quanto dovevo eliminare la sua configurazione e ricrearla da zero. Per non rischiare, ogni volta che dovevo cambiare l'incapsulamento durante i miei tentativi, facevo un reset del router e proseguivo con la prima configurazione con SDM Express. Da qui sceglievo l'incapsulamento.
Ho voluto usare questo sistema anche stavolta, come tentativo, scegliendo l'incapsulamento "PPPoA(aal5mux)", e questo e' il config che ne e' venuto fuori:
Building configuration...

Current configuration : 5612 bytes
!
! Last configuration change at 13:48:37 PCTime Fri May 28 2010 by ca
! NVRAM config last updated at 13:40:16 PCTime Fri May 28 2010 by cisco
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname admin
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$bHAB$vCi.oia.zDBHqfMTVUyEp/
!
no aaa new-model
clock timezone PCTime 0
!
crypto pki trustpoint TP-self-signed-1553173071
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1553173071
revocation-check none
rsakeypair TP-self-signed-1553173071
!
!
crypto pki certificate chain TP-self-signed-1553173071
certificate self-signed 01
3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31353533 31373330 3731301E 170D3130 30353238 31313434
32365A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 35353331
37333037 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100B540 4BD4225D 4B0436FA A823B0AA CB048F5E 847BE97C FBE52F36 0033B76F
A303F631 4B82AC91 105A6E72 6A932C55 50DEE59B 140A00A9 D26879F9 E000350B
1E8B6BBA 59634613 B4B14BA2 365BF807 20AE5196 A86069A7 F8E5C9C2 5C9B6C0B
D1F2E445 08B60948 6A0FCADB 0251D8E4 DD978362 2C891A08 0F6BCF24 BA326972
9B5D0203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D
301F0603 551D2304 18301680 140C79F3 5E6D2C4C 66A40A5B DDCB2518 4F577875
14301D06 03551D0E 04160414 0C79F35E 6D2C4C66 A40A5BDD CB25184F 57787514
300D0609 2A864886 F70D0101 04050003 81810016 3032D8E7 CB1B2472 3B23DB0F
B7531610 D61312DD DBB5BB84 4841D027 3BC47FEE DF5E148E 60D66CCA 4F4CA5A4
C29D0DC6 89A382A1 D7A620FD 81882CAF 87AAEE09 1FA3ABFB 696AF35F E78A9613
B79A78C6 B3D21D2B 409640E4 6C58BE80 A352E24B 66439C96 E13EA278 3F4C17D1
159D1BE2 698ADB53 2B42F4EB E24CCF2A 8319DC
quit
dot11 syslog
no ip source-route
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.123.201 192.168.123.254
!
ip dhcp pool sdm-pool1
import all
network 192.168.123.0 255.255.255.0
default-router 192.168.123.1
dns-server 192.168.123.1
!
!
ip cef
no ip bootp server
ip domain name yourdomain.com
ip name-server 212.216.112.112
ip name-server 212.216.172.62
!
!
!
username ca privilege 15 secret 5 $1$tH52$SRh/loMM6fkN2iz6i1b5w0
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 192.168.123.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1452
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname [email protected]
ppp chap password 7 044F0E161F285F5A08
ppp pap sent-username [email protected] password 7 111D1C15071B181805
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface Dialer0 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.123.0 0.0.0.255
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end
Che dici va bene? O devo ricaricare il precedente e lavorare su quello?
Anche stavolta ho inserito manualmente da SDM l'indirizzo del router come DNS. Spero che sia una scelta giusta e che mi consenta di pingare gli altri pc in rete.

Inviato: ven 28 mag , 2010 7:01 pm
da valerio1976
ma manca l'incapsulamento

oltre alle password che sono diverse, ma sopratutto non c'è il nat

Inviato: sab 29 mag , 2010 8:23 am
da valerio1976
valerio1976 ha scritto:ma manca l'incapsulamento

oltre alle password che sono diverse, ma sopratutto non c'è il nat
scusa ho detto una c...a il nat c'è lol quando ho visto la tua conf cme dire dormivo un pochetto :)


scusa di nuovo

Inviato: sab 29 mag , 2010 9:23 am
da raffa82
Be ragazzi che dire....funge :D . Siate voi benedetti.
Alla fine ho dovuto utilizzare l'incapsulamento PPPoE , postero' fra poco il config funzionante ....sto un attimino smanettando da sdm per far funzionare dyndns, ma per ora nulla non si aggiorna....

Inviato: sab 29 mag , 2010 9:28 am
da valerio1976
raffa82 ha scritto:Be ragazzi che dire....funge :D . Siate voi benedetti.
Alla fine ho dovuto utilizzare l'incapsulamento PPPoE , postero' fra poco il config funzionante ....sto un attimino smanettando da sdm per far funzionare dyndns, ma per ora nulla non si aggiorna....
DDNS non so come si configura con sdm LOL cmq nulla di che ti registri sul sito e inserisci i dati :)

Inviato: sab 29 mag , 2010 10:38 am
da raffa82
Allora...devo dire che da SDM in effetti ho avuto problemi a configurare il dyndns. Al che sono andato nel file di configurazione e ho fatto delle modifiche alle righe del dyndns per farlo andare, e ora va.
Posto quindi la configurazione completamente funzionante per Alice 7 Mega a IP dinamico (la classica linea flat di base) e con ddns:

Building configuration...

Current configuration : 5727 bytes
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname admin
!
boot-start-marker
boot-end-marker
!
logging buffered 51200
logging console critical
enable secret 5 $1$sCcN$EliPhgFeylSk1eHEheeUS0
!
no aaa new-model
clock timezone PCTime 0
!
crypto pki trustpoint TP-self-signed-1553173071
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1553173071
revocation-check none
rsakeypair TP-self-signed-1553173071
!
!
crypto pki certificate chain TP-self-signed-1553173071
certificate self-signed 01
3082024C 308201B5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31353533 31373330 3731301E 170D3130 30353238 31313434
32325A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 35353331
37333037 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
81008939 7C337B5D 24043965 C88C4343 C33072DC 84C4F53D DFCA8807 076F6A31
4A21E2DF 4CE19D4D 763FA870 4618F613 B3B1ACCF 183016F8 1B9F9DF1 E5C1EE6A
879F5A98 E0B3863B 92CC7433 16C73546 7E2302A9 725B1802 1CF3D837 A9D31451
C6C2E531 5C58A6C1 3576E39F A0BC3015 0CE25CFC 4762F71F D4203E90 7DAAC28D
72090203 010001A3 74307230 0F060355 1D130101 FF040530 030101FF 301F0603
551D1104 18301682 1461646D 696E2E79 6F757264 6F6D6169 6E2E636F 6D301F06
03551D23 04183016 8014B16B DE7B742D B0A18E04 0DD0F721 4C14C338 E069301D
0603551D 0E041604 14B16BDE 7B742DB0 A18E040D D0F7214C 14C338E0 69300D06
092A8648 86F70D01 01040500 03818100 140E8CDD D6EE1A2E AE6A56CE 36CAAB43
EE73A5DA E6673439 20AAB562 C2BE2BFF 3662C800 B42F79F0 A76459A0 FD5D3F16
3F5C9C1A 50595544 6E399706 7C8F794D 5E16DD3B 5A129459 7F11EE14 05C4B03C
152589A1 BA1678B5 29EDBAA8 3183255C 7FB25F83 846B2FB1 BEEE8D3D 80F05B89
9A4C5F31 6D895BD2 44034F0F 08266E77
quit
dot11 syslog
no ip source-route
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.123.1
ip dhcp excluded-address 192.168.123.201 192.168.123.254
!
ip dhcp pool sdm-pool1
import all
network 192.168.123.0 255.255.255.0
dns-server 212.216.112.112 212.216.172.62
default-router 192.168.123.1
!
!
ip cef
no ip bootp server
ip domain name yourdomain.com
ip name-server 212.216.112.112
ip name-server 212.216.172.62
ip ddns update method sdm_ddns1
HTTP
add http://XXXXX:[email protected]/n ... rg&myip=<a>
!
!
!
!
username ca privilege 15 secret 5 $1$oZxr$RbzmhGMXsoAUbKaj6q4681
!
!
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
description $ES_WAN$$FW_OUTSIDE$
pvc 8/35
pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 192.168.123.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
ip tcp adjust-mss 1412
!
interface Dialer0
ip ddns update hostname giudim.dyndns.org
ip ddns update sdm_ddns1
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname [email protected]
ppp chap password 7 131112021B05173E2A
ppp pap sent-username [email protected] password 7 06120A315C471A0D04
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface Dialer0 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.123.0 0.0.0.255
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
banner exec ^CC
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Router and Security Device Manager (SDM) is installed on this device and
it provides the default username "cisco" for one-time use. If you have already
used the username "cisco" to login to the router and your IOS image supports the
"one-time" user option, then this username has already expired. You will not be
able to login to the router with this username after you exit this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------
^C
banner login ^CCAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end
Grazie a tutti voi!