Codice: Seleziona tutto
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname sede_master
!
boot-start-marker
boot-end-marker
!
!
aaa new-model
!
!
aaa authentication login vpnauth local
aaa authorization network vpngroup local
!
aaa session-id common
!
resource policy
!
!
!
ip cef
ip domain name domain.local
ip name-server 151.99.125.3
!
!
!
username zzzzzzzzzz password 7 rrrrrrrrrrrrrrrrr
!
!
class-map match-all qos-voip-map
match access-group 111
!
!
policy-map qos-voip-policy
class qos-voip-map
priority 80
!
!
!
crypto isakmp policy 3
encr 3des
hash md5%0
authentication pre-share
group 2
A lifetime 28800
!
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
lifetime 28800
crypto isakmp key XXXXXXXXXXXX address XXXXXXXXXXXX no-xauth
crypto isakmp key XXXXXXXXXXXX address XXXXXXXXXXXX no-xauth
!
crypto isakmp client configuration group ZYX2MUVPN
key XXXXXXXXXXXX
dns 151.99.125.3
domain write
pool localVPNpool
acl 103
save-password
!
!
crypto ipsec transform-set VPN2MUVPN esp-3des esp-md5-hmac
crypto ipsec transform-set VPN2SEDE1 esp-3des esp-md5-hmac
crypto ipsec transform-set VPN2SEDE2 esp-3des esp-md5-hmac
!
crypto dynamic-map VPNDYNMAP 9
set transform-set VPN2MUVPN
reverse-route
!
!
crypto map VPNMAP client authentication list vpnauth
crypto map VPNMAP isakmp authorization list vpngroup
crypto map VPNMAP client configuration address respond
crypto map VPNMAP 9 ipsec-isakmp dynamic VPNDYNMAP
crypto map VPNMAP 10 ipsec-isakmp
set peer XXXXXXXXXXXX
set transform-set VPN2SEDE1
match address 103
crypto map VPNMAP 11 ipsec-isakmp
set peer XXXXXXXXXXXX
set transform-set VPN2SEDE2
match address 102
!
!
!
interface Loopback0
no ip address
!
interface Ethernet0
ip address 192.168.0.254 255.255.255.0
ip nat inside
ip virtual-reassembly
hold-queue 100 out
!
interface Ethernet0.1
shutdown
!
interface Ethernet2
no ip address
shutdown
hold-queue 100 out
!
interface ATM0
no ip address
ip nat outside
ip virtual-reassembly
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
ip address XXXXXXXXXXXX 255.255.255.248
ip nat outside
ip virtual-reassembly
no snmp trap link-status
crypto map VPNMAP
pvc 8/35
oam-pvc manage
oam retry 3 5 1
encapsulation aal5snap
!
!
interface ATM0.2 point-to-point
no snmp trap link-status
!
interface FastEthernet1
duplex auto
speed auto
!
interface FastEthernet2
duplex auto
speed auto
!
interface FastEthernet3
duplex auto
speed auto
!
interface FastEthernet4
duplex auto
speed auto
!
ip local pool localVPNpool 192.168.50.1 192.168.50.100
ip route 0.0.0.0 0.0.0.0 ATM0.1
no ip http server
no ip http secure-server
!
ip nat inside source list 100 interface ATM0.1 overload
!
access-list 100 deny ip 192.168.0.0 0.0.0.255 192.168.100.0 0.0.0.255
access-list 100 deny ip 192.168.0.0 0.0.0.255 192.168.200.0 0.0.0.255
access-list 100 deny ip 192.168.0.0 0.0.0.255 192.168.50.0 0.0.0.255
access-list 100 permit ip 192.168.0.0 0.0.0.255 any
access-list 101 permit tcp XXXXXXXXXXXX 0.0.0.7 any eq 22
access-list 101 permit tcp XXXXXXXXXXXX 0.0.0.7 any eq 22
access-list 101 permit tcp XXXXXXXXXXXX 0.0.0.7 any eq 22
access-list 101 permit tcp XXXXXXXXXXXX 0.0.0.7 any eq 22
access-list 102 permit ip 192.168.0.0 0.0.0.255 192.168.200.0 0.0.0.255 log
access-list 103 permit ip 192.168.0.0 0.0.0.255 192.168.100.0 0.0.0.255 log
access-list 110 permit ip 192.168.0.0 0.0.0.255 192.168.50.0 0.0.0.255
access-list 111 permit ip host 192.168.0.251 host 192.168.100.2
access-list 111 permit ip host 192.168.0.251 host 192.168.200.2
access-list 111 permit ip host 192.168.100.2 host 192.168.0.251
access-list 111 permit ip host 192.168.200.2 host 192.168.0.251
!
control-plane
!
banner login ^C
-----------------------------------------------
Ogni accesso non autorizzato e' proibito
Unauthorized access is prohibited
-----------------------------------------------
^C
!
line con 0
no modem enable
line aux 0
line vty 0 4
access-class 101 in
!
scheduler max-task-time 5000
end
Io posso identificare gli indirizzi Ip dei vari centralini e sulla rete non ho switch gestibili ma solo dei cagatori da 10euri.
Ho pensato quindi che l'unico sistema è quello di gestire la precedenza. Mi sono fatto un ACL, la 111, per gli apparati interessati e ho creato :
Codice: Seleziona tutto
class-map match-all qos-voip-map
match access-group 111
!
!
policy-map qos-voip-policy
class qos-voip-map
priority 80
Grazie per eventuali suggerimenti.