dovrei configurare una connessione Alice buisiness adaptive con 8 ip statici su un cisco 877, premetto che ho un po d'esperienza (grazie anche a questo forum) con le configurazione su ip dinamici infatti era mia intenzione adattare la mia attuale conf. di un 857 dimanico a un 877 statico.
intanto non avendo mai avuto a che fare con le buisiness non ho capito che me ne faccio di 8 ip, in teoria a me serve una semplice linea per internet tipo casa (solo che alle aziende vendono solo questa) che mi permetta di navigare.
la telecom mi ha lasciato un foglio con scritto:
la mia conf dinamico:IP punto punto 88.57.***.108
subnet 255.255.255.0
remoto 88.57.***.254
IP Lan 94.83.***.145
subnet 255.255.255.248
ip disponibili 94.83.***.146 a 150
ho seguito la conf di wizard ma non mi funziona..version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname C877
!
boot-start-marker
boot-end-marker
!
logging buffered 52000
enable secret 5 *****************************
!
aaa new-model
!
!
aaa authentication login local_authen local
aaa authorization exec local_author local
!
!
aaa session-id common
clock timezone MET 1
clock summer-time MEDT recurring last Sun Mar 2:00 last Sun Oct 3:00
!
crypto pki trustpoint TP-self-signed-2397556458
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2397556458
revocation-check none
rsakeypair TP-self-signed-2397556458
!
!
crypto pki certificate chain TP-self-signed-2397556458
certificate self-signed 01
30820244 308201AD A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32333937 35353634 3538301E 170D3038 31303032 31313333
32385A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 33393735
35363435 3830819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100C978 3F37F253 85CCE831 AD22BC6E 99E3CD6F F3DEB800 3A7C7B42 287C1F1A
48AFE96F DC9BA803 D59F2C0F B0271978 7BD9249E D7239E79 0006A1AD B879DECE
007EAFF8 6D582DAA 2CD5C555 A680B841 E9EF4FF9 9A80F6C1 2D65E440 5FADA930
9F5E7B79 A1A53BC4 3E84FA08 6ED75219 8596F6D8 452A0F19 B1EB3B00 08B5D4D7
DB490203 010001A3 6C306A30 0F060355 1D130101 FF040530 030101FF 30170603
551D1104 10300E82 0C433835 37572E4D 41545249 58301F06 03551D23 04183016
8014D888 BD391A45 8405CF28 ACFBFB55 25A68AD0 9D6A301D 0603551D 0E041604
14D888BD 391A4584 05CF28AC FBFB5525 A68AD09D 6A300D06 092A8648 86F70D01
01040500 03818100 33A5A16C F7A8E4DC BB7F7257 172B0E67 860DC8DA 0A13DE3D
266496C7 43F73189 35B1511E B0C112CD 04A88A7A 0E22A684 4DB41FF1 4619E16A
A4AD83A8 759F199B 70717F5F 84B108DE B91FA92F C124BF94 783F069C E2C9CB87
D7BED6E1 D6E01E2C DC662FF9 86F61E73 BF23F050 4EB4093E 8456461A 027628B4
E7BD4EA2 949F4A1G
quit
!
!
!
ip cef
ip inspect log drop-pkt
ip inspect name Firewall cuseeme
ip inspect name Firewall dns
ip inspect name Firewall ftp
ip inspect name Firewall h323
ip inspect name Firewall https
ip inspect name Firewall icmp
ip inspect name Firewall imap
ip inspect name Firewall pop3
ip inspect name Firewall rcmd
ip inspect name Firewall realaudio
ip inspect name Firewall rtsp
ip inspect name Firewall esmtp
ip inspect name Firewall sqlnet
ip inspect name Firewall streamworks
ip inspect name Firewall tftp
ip inspect name Firewall tcp
ip inspect name Firewall udp
ip inspect name Firewall vdolive
no ip bootp server
ip domain name MATRIX
ip name-server 85.37.17.39
ip name-server 85.38.28.71
ip ddns update method sdm_ddns1
HTTP
add http://*****:*****@members.dyndns.org/n ... h>&myip=<a>
remove http://*****:*****@members.dyndns.org/n ... h>&myip=<a>
!
!
!
!
username Admin privilege 15 secret 5 ************************
!
!
archive
log config
hidekeys
!
!
!
bridge irb
!
!
interface Null0
no ip unreachables
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip route-cache flow
no atm ilmi-keepalive
dsl operating-mode adsl2+
!
interface ATM0.1 point-to-point
description
no ip redirects
no ip unreachables
no ip proxy-arp
pvc 8/35
pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
description
!
interface FastEthernet1
description
!
interface FastEthernet2
description
!
interface FastEthernet3
description
!
!
interface Vlan1
description
no ip address
bridge-group 1
!
interface Dialer0
description
ip ddns update hostname *****.gotdns.com
ip ddns update sdm_ddns1
ip address negotiated
ip access-group 101 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1492
ip inspect Firewall out
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip route-cache flow
dialer pool 1
dialer idle-timeout 3600 either
dialer-group 1
no cdp enable
ppp authentication pap callin
ppp pap sent-username *****@alice.it password 7 *******************
!
interface BVI1
description Bridge Virtual Interface$FW_INSIDE$
ip address 192.168.0.221 255.255.255.0
ip access-group 102 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface Dialer0 overload
ip nat inside source static tcp 192.168.0.211 80 interface Dialer0 80
!
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.0.0 0.0.0.255
access-list 2 remark HTTP Access-class list
access-list 2 remark SDM_ACL Category=1
access-list 2 permit 192.168.0.0 0.0.0.255
access-list 2 deny any
access-list 100 remark VTY Access-class list
access-list 100 remark SDM_ACL Category=1
access-list 100 permit ip 192.168.0.0 0.0.0.255 any
access-list 100 deny ip any any
access-list 101 remark Traffic allowed to enter the router from the Internet
access-list 101 deny ip 0.0.0.0 0.255.255.255 any
access-list 101 deny ip 10.0.0.0 0.255.255.255 any
access-list 101 deny ip 127.0.0.0 0.255.255.255 any
access-list 101 deny ip 169.254.0.0 0.0.255.255 any
access-list 101 deny ip 172.16.0.0 0.15.255.255 any
access-list 101 deny ip 192.0.2.0 0.0.0.255 any
access-list 101 deny ip 192.168.0.0 0.0.255.255 any
access-list 101 deny ip 198.18.0.0 0.1.255.255 any
access-list 101 deny ip 224.0.0.0 0.15.255.255 any
access-list 101 deny ip any host 255.255.255.255
access-list 101 permit udp host 85.37.17.39 eq domain any
access-list 101 permit udp host 85.38.28.71 eq domain any
access-list 101 permit tcp host 204.13.248.112 eq www any log
access-list 101 permit udp host 207.46.232.182 eq ntp any
access-list 101 permit udp host 192.43.244.18 eq ntp any
access-list 101 permit tcp any any eq www
access-list 101 permit gre any any
access-list 101 deny icmp any any echo
access-list 101 deny ip any any log
access-list 102 remark Traffic allowed to enter the router from the Ethernet
access-list 102 permit ip any host 192.168.0.221
access-list 102 deny ip any host 192.168.0.255
access-list 102 deny udp any any eq tftp log
access-list 102 deny ip any 0.0.0.0 0.255.255.255 log
access-list 102 deny ip any 10.0.0.0 0.255.255.255 log
access-list 102 deny ip any 127.0.0.0 0.255.255.255 log
access-list 102 deny ip any 169.254.0.0 0.0.255.255 log
access-list 102 deny ip any 172.16.0.0 0.15.255.255 log
access-list 102 deny ip any 192.0.2.0 0.0.0.255 log
access-list 102 deny ip any 192.168.0.0 0.0.255.255 log
access-list 102 deny ip any 198.18.0.0 0.1.255.255 log
access-list 102 deny udp any any eq 135 log
access-list 102 deny tcp any any eq 135 log
access-list 102 deny udp any any eq netbios-ns log
access-list 102 deny udp any any eq netbios-dgm log
access-list 102 deny tcp any any eq 445 log
access-list 102 permit ip 192.168.0.0 0.0.0.255 any
access-list 102 permit ip any host 255.255.255.255
access-list 102 deny ip any any log
dialer-list 1 protocol ip permit
no cdp run
!
control-plane
!
bridge 1 protocol ieee
bridge 1 route ip
banner login ^C.::.::. Cisco Systems, Inc
Cisco 877 - IOS 124-15.T7
Authorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login authentication local_authen
no modem enable
transport output telnet
line aux 0
login authentication local_authen
transport output telnet
line vty 0 4
access-class 100 in
authorization exec local_author
login authentication local_authen
transport input telnet ssh
!
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
sntp server 207.46.232.182
sntp server 192.43.244.18
end
http://www.ciscoforums.it/viewtopic.php?t=9410
non ho capito ma la dialer la devo mettere???
e gli ip che mi hanno fornito dove li inserisco nella conf.. dovrei configurare questa ip statica tipo home solo che a differenza l'ip esterno non cambierebbe
mi date una mano..
Grazie