Ho un problema noioso con un CISCO 1801 (è il primo di questa serie che configuro). Con altri modelli (small business) non ho avuto problemi e la configurazione via web ha sempre soddisfatto le mie esigenze.
Su questo modello devo evidentemente intervenire sulla configurazione più a basso livello. Ok, proviamoci.
Il problema è questo: la configurazione che sono riuscito ad implementare tramite CCP mi garantisce la connessione ad internet ma le prestazioni in upload sono da modem 56Kb, il download invece va egregiamente.
La topologia è e deve restare la seguente:
Il cliente ha un ISP che non permette la sostituzione del modem/router quindi la connessione ad internet è realizzata mediante il router loro.
Il CISCO si collega al router ADSL mediante la porta FE0.
Come detto il download va egregiamente (almeno per l'ADSL di cui dispongo). L'upload è talmente scarso che anche solo una email di 50KB non esce.
Ho pensato fosse il firewall, ho resettato tutto e riprovato mille volte, sempre lo stesso risultato.
Posto la configurazione e spero che riusciate ad individuare il problema:
Codice: Seleziona tutto
version 15.0
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname miaazienda
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging buffered 51200
logging console critical
enable secret 5 $1$AdfghdfghdfS4S1.lME1OhpavY0
!
no aaa new-model
!
!
!
clock timezone PCTime 1
clock summer-time PCTime date Mar 30 2003 2:00 Oct 26 2003 3:00
!
crypto pki trustpoint TP-self-signed-3829866787
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3829866787
revocation-check none
rsakeypair TP-self-signed-3829866787
!
!
crypto pki certificate chain TP-self-signed-3829866787
certificate self-signed 01
30820248 308201B1 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33383239 38333337 3837301E 170D3131 31323136 30373433
31365A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
[..cut..]
551D1104 14301282 10434545 492E6365 6569736E 632E636F 6D301F06 03551D23
04183016 8014BED3 D6BA6937 CB0AB66A 6DEA45B0 A82C39A1 AC49301D 0603551D
0E041604 14BED3D6 BA6937CB 0AB66A6D EA45B0A8 2C39A1AC 49300D06 092A8648
86F70D01 01040500 03818100 45A36842 1ADCB127 94EACF58 A3723922 7316942D
E1C82817 5B772F0E 57FFBE36 E3771DBC 0FEE4E17 89867DF4 FE4EDAE9 716F2AEC
1CE6B0ED 04E0A800 41CD172C 090F52EA E13A61A0 B09FE637 F0B9105C 19202DA7
4FFD2CA7 68A9F520 D7375447 10A5D20A 241CCF15 F993CA43 18DBD847 EADD0729
E2B0340A F64BB356 09206C4C
quit
dot11 syslog
no ip source-route
!
!
ip dhcp excluded-address 10.10.10.1
!
ip dhcp pool ccp-pool1
import all
network 10.10.10.0 255.255.255.0
dns-server 8.8.8.8
default-router 10.10.10.1
!
!
ip cef
no ip bootp server
ip domain name miaazienda.com
ip name-server 8.8.8.8
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
license udi pid CISCO1801/K9 sn FGL1tghhjjk27LZ
username miaazienda privilege 15 secret 5 $sdffgsdfgFleYp8.nqgqynS8VXnl0
!
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
!
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
shutdown
no atm ilmi-keepalive
!
!
interface BRI0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
encapsulation hdlc
shutdown
!
!
interface FastEthernet0
description $ES_WAN$$FW_OUTSIDE$
ip address 192.168.100.146 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
interface FastEthernet1
!
!
interface FastEthernet2
!
!
interface FastEthernet3
!
!
interface FastEthernet4
!
!
interface FastEthernet5
!
!
interface FastEthernet6
!
!
interface FastEthernet7
!
!
interface FastEthernet8
!
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-FE 1$$ES_LAN$$FW_INSIDE$
ip address 10.10.10.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1452
!
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
!
ip nat inside source list 1 interface FastEthernet0 overload
ip route 0.0.0.0 0.0.0.0 192.168.100.100
!
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark CCP_ACL Category=2
access-list 1 permit 10.10.10.0 0.0.0.255
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner exec ^CCCC
% Password expiration warning.
-----------------------------------------------------------------------
Cisco Configuration Professional (Cisco CP) is installed on this device
and it provides the default username "cisco" for one-time use. If you have
already used the username "cisco" to login to the router and your IOS image
supports the "one-time" user option, then this username has already expired.
You will not be able to login to the router with this username after you exit
this session.
It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.
username <myuser> privilege 15 secret 0 <mypassword>
Replace <myuser> and <mypassword> with the username and password you want to
use.
-----------------------------------------------------------------------
^C
banner login ^CCCCAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet ssh
line vty 5 15
privilege level 15
login local
transport input telnet ssh
!
scheduler allocate 4000 1000
scheduler interval 500
end