"Così faccio anche un po' di esperienza", mi sono detto.
Voglio sostituire un 662H con un SR520... ho studiato un po' in giro, mi sono messo di buzzo buono e pensavo di essere a buon punto.
Ho buttato giù una configurazione basata su un post che ho trovato qui, oggi l'ho provata e ovviamente non funziona una cippa.
Non pinga i dns, non pinga il point-to-point, niente di niente.
Per ora non vorrei fare niente di trascendentale, mi basta far uscire l'intera LAN in internet con uno dei 6 ip pubblici assegnatimi.
Mi date una mano a capire dove sbaglio? (immagino che nella config ci siano parecchie cose che non servono, ma per non saper né leggere né scrivere ho toccato solo quello di cui credevo di aver capito qualcosa)
Codice: Seleziona tutto
Current configuration : 6226 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SR520
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
no logging buffered
enable secret 5 $1$zaaf$uZBmDFBsofIMVZv09tMnt/
!
no aaa new-model
clock timezone PCTime 1
clock summer-time PCTime date Mar 30 2003 2:00 Oct 26 2003 3:00
!
crypto pki trustpoint TP-self-signed-3423622799
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3423622799
revocation-check none
rsakeypair TP-self-signed-3423622799
!
!
crypto pki certificate chain TP-self-signed-3423622799
certificate self-signed 01
3082023D 308201A6 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33343233 36323237 3939301E 170D3032 30333031 30303036
33345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 34323336
32323739 3930819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100E9A6 E76B8424 7445BF4E 358DAC91 F08A89CF 66D9CADE C1C019C3 B2676666
0B27CE1D B1A09F7B 619402F1 96DD1810 93792CC3 CD36B7CE 6E138A7C EA25EEC0
B187F065 CA415F1B 02A975BA A300B55D 90B4929E A86D8A9B E3DDF25F 3FC814AC
90138831 6D538BCB 318AD86D 28EBD90C F04E12F7 7846E48B 94FA72E6 E7DC55DA
9DED0203 010001A3 65306330 0F060355 1D130101 FF040530 030101FF 30100603
551D1104 09300782 05535235 3230301F 0603551D 23041830 168014D7 7060E2C0
69923857 BDCBD22A CB5D6716 812EEA30 1D060355 1D0E0416 0414D770 60E2C069
923857BD CBD22ACB 5D671681 2EEA300D 06092A86 4886F70D 01010405 00038181
00C36A5E F83ACF6C 36DBF9D8 A40F24F8 52F82D0C 4CD71A7D 3262E5FB F9C85AC0
DC071384 182D22F6 2AE0F708 8AA6A59D 5F078ADB 6B17EFB6 909E9208 92FC7800
C606C93B 25DC857D 6BB62EFB 46A560B6 BD2F17DB C73964AC 7AB6F057 5496A302
CD2363B8 77D11F7C 1E9414ED 17675B76 623BDDD3 02E64E89 F4D52A76 3D4FBE69 88
quit
dot11 syslog
ip source-route
!
!
!
!
ip cef
ip name-server 151.99.125.3
ip name-server 8.8.8.8
!
no ipv6 cef
multilink bundle-name authenticated
!
!
username admin privilege 15 secret 5 $1$yqj.$sNxUEIzKodIr7vet2YKwp0
!
!
!
archive
log config
logging enable
logging size 600
hidekeys
!
!
!
class-map type inspect match-any SDM-Voice-permit
match protocol h323
match protocol skinny
match protocol sip
class-map type inspect match-any sdm-cls-icmp-access
match protocol icmp
match protocol tcp
match protocol udp
class-map type inspect match-any sdm-cls-insp-traffic
match protocol cuseeme
match protocol dns
match protocol ftp
match protocol h323
match protocol https
match protocol icmp
match protocol imap
match protocol pop3
match protocol netshow
match protocol shell
match protocol realmedia
match protocol rtsp
match protocol smtp extended
match protocol sql-net
match protocol streamworks
match protocol tftp
match protocol vdolive
match protocol tcp
match protocol udp
class-map type inspect match-all sdm-invalid-src
match access-group 100
class-map type inspect match-all sdm-protocol-http
match protocol http
!
!
policy-map type inspect sdm-permit-icmpreply
class type inspect sdm-cls-icmp-access
inspect
class class-default
pass
policy-map type inspect sdm-inspect
class type inspect sdm-invalid-src
drop log
class type inspect sdm-cls-insp-traffic
inspect
class type inspect sdm-protocol-http
inspect
class type inspect SDM-Voice-permit
pass
class class-default
pass
policy-map type inspect sdm-inspect-voip-in
class type inspect SDM-Voice-permit
pass
class class-default
drop
policy-map type inspect sdm-permit
class class-default
drop
!
zone security out-zone
zone security in-zone
zone-pair security sdm-zp-self-out source self destination out-zone
service-policy type inspect sdm-permit-icmpreply
zone-pair security sdm-zp-out-self source out-zone destination self
service-policy type inspect sdm-permit
zone-pair security sdm-zp-in-out source in-zone destination out-zone
service-policy type inspect sdm-inspect
zone-pair security sdm-zp-out-in source out-zone destination in-zone
service-policy type inspect sdm-inspect-voip-in
!
!
!
interface ATM0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
ip address <indirizzo-punto-punto-fornito-da-telecom> 255.255.255.252
ip access-group 131 in
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly
zone-member security out-zone
no ip mroute-cache
snmp trap ip verify drop-rate
pvc 8/35
oam-pvc manage
oam retry 5 5 1
encapsulation aal5snap
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description LAN 192.168.0.0/24
ip address 192.168.0.3 255.255.255.0
ip accounting output-packets
ip flow ingress
ip nat inside
ip virtual-reassembly
no ip mroute-cache
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 ATM0.1
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat pool NAT-1 <primo-ip-pubblico> <primo-ip-pubblico> netmask 255.255.255.248
ip nat inside source list 100 pool NAT-1 overload
!
access-list 100 permit ip 192.168.0.0 0.0.0.255 any
access-list 131 deny ip any any
access-list 131 permit tcp any host 192.168.0.11 eq 143
access-list 131 permit tcp any host 192.168.0.11 eq smtp
!
!
!
!
!
control-plane
!
^C
!
line con 0
login local
no modem enable
line aux 0
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
end