VPN Cisco 1721
Inviato: lun 23 lug , 2007 11:14 pm
Ciao,
ho configurato il mio router 1721 in modo da potermi collegare tramite VPN alla lan che c'è dietro, il problema e che dopo essermi regolarmente autenticato, riesco a pingare solo il primo IP che provo a pingare, sucate il gioco di parole, mi spiego meglio subito dopo essermi loggato da dos provo a pingare il 192.168.1.200 e mi risponde regolarmente se porvo a pingare il 192.168.1.254(router) non riesco a pingarlo sul .200 vi è un server ftp e vnc non riesco ad'accedervi in nessuno dei due modi.
la cosa ancora piu' strana è che come GW dell'interfaccia VPN sul pc client ho lo stesso ip della macchina, mi date una mano pls ??
ecco la conf:
Building configuration...
Current configuration : 3339 bytes
!
! Last configuration change at 23:32:39 MET Mon Jul 23 2007 by XXXXXXXXX
!
version 12.3
no parser cache
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname XXXXXXXXX
!
boot-start-marker
boot system flash:c1700-k9o3sy7-mz.123-21.bin
boot-end-marker
!
logging buffered 4096 debugging
enable secret 5 XXXXXXXXXXXXXXXXXXXXXXXXXXX
!
memory-size iomem 25
clock timezone MET 1
clock summer-time MET recurring
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
aaa new-model
!
!
aaa authentication login home_vpn local
aaa authorization network vpn_group local
aaa session-id common
ip subnet-zero
no ip source-route
!
!
no ip domain lookup
ip domain name open1
ip dhcp excluded-address 192.168.1.240 192.168.1.254
!
ip dhcp pool Open1
network 192.168.1.0 255.255.255.0
domain-name Open1
dns-server 213.140.2.43 213.140.2.49
default-router 192.168.1.254
!
ip cef
ip audit po max-events 100
!
!
username XXXXXXXXX password 0 XXXXXXXXX
username XXXXXXXXX password 0 XXXXXXXXX
!
!
crypto isakmp policy 3
encr 3des
authentication pre-share
group 2
!
crypto isakmp client configuration group home_vpn
key XXXXXXXXX
dns 213.140.2.43
domain open1
pool clientmap
!
!
crypto ipsec transform-set vpn_home esp-3des esp-md5-hmac
!
crypto dynamic-map dynmap 10
set transform-set vpn_home
reverse-route
!
!
crypto map clientmap client authentication list home_vpn
crypto map clientmap isakmp authorization list vpn_group
crypto map clientmap client configuration address respond
crypto map clientmap 10 ipsec-isakmp dynamic dynmap
!
!
interface Ethernet0
description #### Collegamento WAN ####
ip address XXXXXXXXX 255.255.255.0
ip nat outside
half-duplex
crypto map clientmap
!
interface FastEthernet0
description #### Collegamento LAN ####
ip address 192.168.1.254 255.255.255.0
ip nat inside
speed 100
full-duplex
!
router rip
passive-interface default
no passive-interface FastEthernet0
network 192.168.1.0
no auto-summary
!
ip local pool clientmap 10.24.4.57 10.24.4.59 group baba
ip nat inside source list 1 interface Ethernet0 overload
ip nat inside source list 101 interface Ethernet0 overload
ip nat inside source static tcp 192.168.1.200 139 XXXXXXXXX 139 extendable
ip nat inside source static tcp 192.168.1.200 5900 XXXXXXXXX 8000 extendable
ip nat inside source static tcp 192.168.1.200 4663 XXXXXXXXX 4663 extendable
ip nat inside source static udp 192.168.1.200 4673 XXXXXXXXX 4673 extendable
ip nat inside source static tcp 192.168.1.200 21 XXXXXXXXX 21 extendable
ip nat inside source static tcp 192.168.1.100 3724 XXXXXXXXX 3724 extendable
ip nat inside source static tcp 192.168.1.100 6881 XXXXXXXXX 6881 extendable
ip nat inside source static tcp 192.168.1.100 6112 XXXXXXXXX 6112 extendable
ip classless
ip route 0.0.0.0 0.0.0.0 XXXXXXXXX
no ip http server
no ip http secure-server
!
!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 101 permit ip 192.168.1.0 0.0.0.255 10.24.4.0 0.0.0.255
access-list 111 deny ip 192.168.1.0 0.0.0.255 10.24.4.0 0.0.0.255
access-list 111 permit ip any any
!
tftp-server flash:c1700-k9o3sy7-mz.123-21.bin
!
!
line con 0
line aux 0
line vty 0 4
exec-timeout 0 0
!
sntp server XXXXXXXXX
sntp server XXXXXXXXX
sntp server XXXXXXXXX
end
HELP ME PLS con questa è la 3° notte che non dormo :PpPp
Grazie.
ho configurato il mio router 1721 in modo da potermi collegare tramite VPN alla lan che c'è dietro, il problema e che dopo essermi regolarmente autenticato, riesco a pingare solo il primo IP che provo a pingare, sucate il gioco di parole, mi spiego meglio subito dopo essermi loggato da dos provo a pingare il 192.168.1.200 e mi risponde regolarmente se porvo a pingare il 192.168.1.254(router) non riesco a pingarlo sul .200 vi è un server ftp e vnc non riesco ad'accedervi in nessuno dei due modi.
la cosa ancora piu' strana è che come GW dell'interfaccia VPN sul pc client ho lo stesso ip della macchina, mi date una mano pls ??
ecco la conf:
Building configuration...
Current configuration : 3339 bytes
!
! Last configuration change at 23:32:39 MET Mon Jul 23 2007 by XXXXXXXXX
!
version 12.3
no parser cache
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname XXXXXXXXX
!
boot-start-marker
boot system flash:c1700-k9o3sy7-mz.123-21.bin
boot-end-marker
!
logging buffered 4096 debugging
enable secret 5 XXXXXXXXXXXXXXXXXXXXXXXXXXX
!
memory-size iomem 25
clock timezone MET 1
clock summer-time MET recurring
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
aaa new-model
!
!
aaa authentication login home_vpn local
aaa authorization network vpn_group local
aaa session-id common
ip subnet-zero
no ip source-route
!
!
no ip domain lookup
ip domain name open1
ip dhcp excluded-address 192.168.1.240 192.168.1.254
!
ip dhcp pool Open1
network 192.168.1.0 255.255.255.0
domain-name Open1
dns-server 213.140.2.43 213.140.2.49
default-router 192.168.1.254
!
ip cef
ip audit po max-events 100
!
!
username XXXXXXXXX password 0 XXXXXXXXX
username XXXXXXXXX password 0 XXXXXXXXX
!
!
crypto isakmp policy 3
encr 3des
authentication pre-share
group 2
!
crypto isakmp client configuration group home_vpn
key XXXXXXXXX
dns 213.140.2.43
domain open1
pool clientmap
!
!
crypto ipsec transform-set vpn_home esp-3des esp-md5-hmac
!
crypto dynamic-map dynmap 10
set transform-set vpn_home
reverse-route
!
!
crypto map clientmap client authentication list home_vpn
crypto map clientmap isakmp authorization list vpn_group
crypto map clientmap client configuration address respond
crypto map clientmap 10 ipsec-isakmp dynamic dynmap
!
!
interface Ethernet0
description #### Collegamento WAN ####
ip address XXXXXXXXX 255.255.255.0
ip nat outside
half-duplex
crypto map clientmap
!
interface FastEthernet0
description #### Collegamento LAN ####
ip address 192.168.1.254 255.255.255.0
ip nat inside
speed 100
full-duplex
!
router rip
passive-interface default
no passive-interface FastEthernet0
network 192.168.1.0
no auto-summary
!
ip local pool clientmap 10.24.4.57 10.24.4.59 group baba
ip nat inside source list 1 interface Ethernet0 overload
ip nat inside source list 101 interface Ethernet0 overload
ip nat inside source static tcp 192.168.1.200 139 XXXXXXXXX 139 extendable
ip nat inside source static tcp 192.168.1.200 5900 XXXXXXXXX 8000 extendable
ip nat inside source static tcp 192.168.1.200 4663 XXXXXXXXX 4663 extendable
ip nat inside source static udp 192.168.1.200 4673 XXXXXXXXX 4673 extendable
ip nat inside source static tcp 192.168.1.200 21 XXXXXXXXX 21 extendable
ip nat inside source static tcp 192.168.1.100 3724 XXXXXXXXX 3724 extendable
ip nat inside source static tcp 192.168.1.100 6881 XXXXXXXXX 6881 extendable
ip nat inside source static tcp 192.168.1.100 6112 XXXXXXXXX 6112 extendable
ip classless
ip route 0.0.0.0 0.0.0.0 XXXXXXXXX
no ip http server
no ip http secure-server
!
!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 101 permit ip 192.168.1.0 0.0.0.255 10.24.4.0 0.0.0.255
access-list 111 deny ip 192.168.1.0 0.0.0.255 10.24.4.0 0.0.0.255
access-list 111 permit ip any any
!
tftp-server flash:c1700-k9o3sy7-mz.123-21.bin
!
!
line con 0
line aux 0
line vty 0 4
exec-timeout 0 0
!
sntp server XXXXXXXXX
sntp server XXXXXXXXX
sntp server XXXXXXXXX
end
HELP ME PLS con questa è la 3° notte che non dormo :PpPp
Grazie.