Sono tornato al punto di partenza; lasciando la vlan di default ovvero la 1, riesco a pingare gli apparati collegati alle 4 porte della scheda ma non riesco a pingare la porta eth integrata nel router o ip esterni. Non passa nemmeno il dhcp.
Dove sbaglio?
interface FastEthernet0/0
description Interfaccia rete LAN
ip address 192.168.10.254 255.255.255.0
ip nat inside
ip virtual-reassembly
speed auto
!
interface FastEthernet1/1
!
interface FastEthernet1/2
!
interface FastEthernet1/3
!
interface FastEthernet1/4
!
interface Vlan1
ip address 10.1.1.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
interface Dialer0
ip address negotiated
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
ppp authentication chap callin
ppp chap hostname XXXXXXXXt
ppp chap password 7 XXXXXXX
ppp pap sent-username XXXXXXXX password 7 XXXXXXXXX
crypto map VPN
!
ip local pool POOL_ROADWARRIOR 192.168.11.1 192.168.11.20
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
no ip http server
no ip http secure-server
!
ip nat inside source list ACL_NAT interface Dialer0 overload
ip nat inside source static udp 192.168.10.101 5617 interface Dialer0 5617
ip nat inside source static tcp 192.168.10.101 37857 interface Dialer0 37857
ip nat inside source static udp 192.168.10.100 32505 interface Dialer0 32505
ip nat inside source static tcp 192.168.10.100 32476 interface Dialer0 32476
!
ip dns server
!
!
ip access-list extended ACL_NAT
deny ip 192.168.10.0 0.0.0.255 192.168.11.0 0.0.0.255
deny ip 192.168.10.0 0.0.0.255 10.10.10.0 0.0.0.255
permit ip 192.168.10.0 0.0.0.255 any
permit ip 10.1.1.0 0.0.0.255 any
ip access-list extended ACL_ROADWARRIOR
permit ip 192.168.10.0 0.0.0.255 192.168.11.0 0.0.0.255
ip access-list extended ACL_VPN
permit ip 192.168.10.0 0.0.0.255 10.10.10.0 0.0.0.255
ip access-list extended SSH
permit ip 192.168.10.0 0.0.0.255 any
permit ip 192.168.11.0 0.0.0.255 any
permit ip host 80.249.33.107 any
permit ip 10.10.10.0 0.0.0.255 any