
Purtroppo il 77h non offre funzionalità firewall, per cui questa soluzione è esclusa... Qualcuno ha qualche suggerimento?
Grazie!!!
Moderatore: Federico.Lagni
non avrà firewall di livello sessione, ma filtering di livello 3 dovrà pur averlo! una acl su atm0.1 (o dialer, a seconda della conf) e la cosa è fatta.Purtroppo il 77h non offre funzionalità firewall
SHOW STARTUP-CONFIG:
Using 3832 out of 131072 bytes
!
version 12.3
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname XXXXXXXXXXXXXXXXXX
!
boot-start-marker
boot-end-marker
!
enable secret 5 XXXXXXXXXXXXXXXXXX
!
ip subnet-zero
ip dhcp excluded-address 10.10.10.1
!
ip dhcp pool CLIENT
import all
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
lease 0 2
!
username XXXXXXXXXXXXXXXXXX password 7 XXXXXXXXXXXXXXXXXX
!
!
!
interface Ethernet0
ip address 10.10.10.1 255.255.255.0
ip nat inside
no ip mroute-cache
hold-queue 100 out
!
interface ATM0
no ip address
no ip mroute-cache
atm vc-per-vp 64
no atm ilmi-keepalive
dsl operating-mode auto
hold-queue 224 in
pvc 8/35
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface Dialer1
ip address negotiated
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap pap callin
ppp chap hostname XXXXXXXXXXXXXXXXXX
ppp chap password 7 XXXXXXXXXXXXXXXXXX
ppp pap sent-username XXXXXXXXXXXXXXXXXX password 7 XXXXXXXXXXXXXXXXXX
B4705100A
ppp ipcp dns request
ppp ipcp wins request
!
ip nat inside source list 102 interface Dialer1 overload
ip nat inside source static udp 10.10.10.3 XXXXX interface Dialer1 XXXXX
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
ip http server
!
access-list 23 permit 10.10.10.0 0.0.0.255
access-list 102 permit ip 10.10.10.0 0.0.0.255 any
dialer-list 1 protocol ip permit
!
line con 0
exec-timeout 120 0
stopbits 1
line vty 0 4
access-class 23 in
exec-timeout 120 0
login local
length 0
!
scheduler max-task-time 5000
end
SHOW IP INTERFACE:
ATM0 is up, line protocol is up
Internet protocol processing disabled
Dialer1 is up, line protocol is up
Internet address is XXX.XXX.XXX.XXX/XX
Broadcast address is 255.255.255.255
Address determined by IPCP
MTU is 1500 bytes
Helper address is not set
Directed broadcast forwarding is disabled
Outgoing access list is not set
Inbound access list is not set
Proxy ARP is enabled
Local Proxy ARP is disabled
Security level is default
Split horizon is enabled
ICMP redirects are always sent
ICMP unreachables are always sent
ICMP mask replies are never sent
IP fast switching is enabled
IP fast switching on the same interface is enabled
IP CEF switching is disabled
IP Feature Fast switching turbo vector
IP multicast fast switching is enabled
IP multicast distributed fast switching is disabled
IP route-cache flags are Fast
Router Discovery is disabled
IP output packet accounting is disabled
IP access violation accounting is disabled
TCP/IP header compression is disabled
RTP/IP header compression is disabled
Policy routing is disabled
Network address translation is enabled, interface in domain outside
WCCP Redirect outbound is disabled
WCCP Redirect inbound is disabled
WCCP Redirect exclude is disabled
BGP Policy Mapping is disabled
Ethernet0 is up, line protocol is up
Internet address is 10.10.10.1/24
Broadcast address is 255.255.255.255
Address determined by non-volatile memory
MTU is 1500 bytes
Helper address is not set
Directed broadcast forwarding is disabled
Outgoing access list is not set
Inbound access list is not set
Proxy ARP is enabled
Local Proxy ARP is disabled
Security level is default
Split horizon is enabled
ICMP redirects are always sent
ICMP unreachables are always sent
ICMP mask replies are never sent
IP fast switching is enabled
IP fast switching on the same interface is disabled
IP CEF switching is disabled
IP Feature Fast switching turbo vector
IP multicast fast switching is disabled
IP multicast distributed fast switching is disabled
IP route-cache flags are Fast
Router Discovery is disabled
IP output packet accounting is disabled
IP access violation accounting is disabled
TCP/IP header compression is disabled
RTP/IP header compression is disabled
Policy routing is disabled
Network address translation is enabled, interface in domain inside
WCCP Redirect outbound is disabled
WCCP Redirect inbound is disabled
WCCP Redirect exclude is disabled
BGP Policy Mapping is disabled
Virtual-Access1 is up, line protocol is up
Internet protocol processing disabled
Virtual-Access2 is up, line protocol is up
Peer address is 192.168.100.1
Dialer interface is Dialer1
Codice: Seleziona tutto
access-list 105 deny tcp any any 80
access-list 105 permit ip any any
Codice: Seleziona tutto
interface dialer1
ip access-group 105 in
Codice: Seleziona tutto
access-list 105 deny tcp any any eq 80
Codice: Seleziona tutto
access-list 23 permit 10.10.10.0 0.0.0.255
access-list 102 permit ip 10.10.10.0 0.0.0.255 any
access-list 105 deny tcp any any eq 80
dialer-list 1 protocol ip permit
Codice: Seleziona tutto
access-list 23 permit 10.10.10.0 0.0.0.255
access-list 102 permit ip 10.10.10.0 0.0.0.255 any
access-list 105 permit ip any any
access-list 105 deny tcp any any eq 80
dialer-list 1 protocol ip permit
Codice: Seleziona tutto
access-list 105 deny tcp any any eq 80
access-list 105 permit ip any any
e nemmenoaccess-list 105 deny tcp any any eq 80
E comunque, l'hai applicata all'interfaccia?access-list 105 permit ip any any
access-list 105 deny tcp any any eq 80
Codice: Seleziona tutto
access-list 105 deny tcp any any eq 80
access-list 105 permit ip any any
Codice: Seleziona tutto
interface dialer1
ip access-group 105 in
Codice: Seleziona tutto
interface Dialer1
ip address negotiated
ip access-group 105 in
ip nat outside
encapsulation ppp
[...]
!
access-list 23 permit 10.10.10.0 0.0.0.255
access-list 102 permit ip 10.10.10.0 0.0.0.255 any
access-list 105 permit ip any any
access-list 105 deny tcp any any
access-list 105 deny tcp any any eq www
dialer-list 1 protocol ip permit
!
line con 0
exec-timeout 120 0
stopbits 1
line vty 0 4
access-class 23 in
exec-timeout 120 0
login local
length 0
!
scheduler max-task-time 5000
end
Codice: Seleziona tutto
access-list 105 permit ip any any
access-list 105 deny tcp any any
access-list 105 deny tcp any any eq www
Codice: Seleziona tutto
access-list 105 deny tcp any any eq www
access-list 105 permit ip any any