
设备:cisco 1941# [% v7 ^1 T4 F- S, {6 b9 y
端口:fa0/1接ADSL fa0/0接内网
( V: s6 p- W+ ]IP网段: 内网192.168.1.0 分配VPN 192.168.199.0 _7 b2 G7 [2 c
配置8 i o& k b9 K5 l" T$ L
Building configuration...& K% s3 W3 e/ h1 Z$ {
Current configuration : 5533 bytes
) C# {% t5 b, S* X5 ?+ {9 E!7 |2 G6 I& u* Z, @) t
version 12.4' F- I H* p0 Z7 C0 m
service timestamps debug datetime msec
; e: R1 n/ T$ F2 a j0 E$ bservice timestamps log datetime msec. D! C, L: f' \3 U) J: f+ D1 K
no service password-encryption; E/ s2 y- ]6 |2 r; O
!
* u( G4 i, H; D6 z5 d. Xhostname wingo t2 F& r( n! x2 B
!8 K, o; y* W- a/ A5 J, ?1 a
boot-start-marker8 _& a2 m9 p. T
boot-end-marker
' J8 x/ S( V0 n1 a' i!# H ^4 A& @! ]6 U/ R! Y& Z ~
logging buffered 4096 debugging7 q0 p2 t) F9 H2 h+ q0 q: w/ d
enable secret 5 $1$/9kG$8nQUz5gffWzZbzoMh24Z//
/ R7 b7 L0 q& V& ?!$ W# @! n; M0 v/ u
aaa new-model
( _ d- f* L6 n: y) E; e!
+ j l+ G$ R: W3 Y/ e# ~4 m!
( r O: H8 h) h7 oaaa authentication login default local6 t: L0 n7 f6 `" l* Q1 o
aaa authentication ppp default local
$ L8 L8 V/ y" a& O |7 f8 W5 C4 kaaa authentication ppp vpdn group radius* H0 L% Q% l% @: a% ?, t
aaa authorization network default group radius " }6 a5 {# Q- |/ t- H5 ~
aaa accounting network default start-stop group radius2 K( ^" y$ B+ |# }8 V0 r# c6 N% S
!
2 |0 l6 P; q7 N9 A/ Oaaa session-id common) Q- p6 { u& X* ]) Z
clock timezone PCTime 8( S8 O& t4 b; R% M6 m! w! @0 j
ip cef7 R: {7 J: ^5 J: q. Z& e- ^" s
!2 k4 w" h( \0 o8 F
!
, l: Z9 a, {3 i( K: e6 A. U2 A!# ?4 L" E! i. t* o
!
% I. F: V' [- H# ?: J1 E1 kno ip domain lookup
- b. f) q7 o4 N. m+ N1 V* ?* Jip domain name yourdomain.com% r$ \/ K- _. @4 a; x2 s
ip auth-proxy max-nodata-conns 3
7 N/ f: N" a; t0 J6 Eip admission max-nodata-conns 3
# G% `; b, B) U$ Z. {vpdn enable6 b2 l+ b1 i0 i; b
!1 O2 j8 t& b/ W& E; u- m
vpdn-group 1! U( M+ @# c: ~$ w& n& l
! Default L2TP VPDN group
. V# J' L0 t( E3 Yaccept-dialin
: B* Z4 Z2 y3 s9 `. L' M protocol l2tp% s D0 r" [! S2 N
virtual-template 1
, ?. o' e$ I( m5 o# M4 Qno l2tp tunnel authentication, N3 ~9 N+ ]2 v T/ Z" D
!
3 A }; c/ @1 P0 t& C!0 P% E# T! y. I+ `: Y" A8 S6 a2 g
!
: z/ Q# `% W6 F7 G+ J: x& O' d. Z!6 h# P+ y T% j1 W
username wingo secret 5 $1$hPn3$DxSDpG7DBqI/Jpo86opzp0
) b/ R$ k% ~$ `! X* U* H& a) I+ _7 ?username poison privilege 15 secret 5 $1$lHU/$UG27fhUr4knGmskgXe0Xv/3 t. K- l5 H& S1 T( V
!, |6 q# t4 q. T2 T9 k( v
!+ d" c- Z% E& L8 a: _
!6 i( o" E; N3 \& M" b
!# t; g: C5 u: U7 H/ c$ x8 F6 G
!
4 y. b' \4 |$ E% c!3 P# w) m% j+ b
!
' u" M4 Y9 R; l+ [- }: K! V: S!
2 T2 D; o; d( [; m N9 C8 [interface FastEthernet0/0% L4 y" y5 D" ?! q$ q# b* c
description to LAN$ETH-LAN$: n6 E. x: e' j: }! T: W
ip address 192.168.1.1 255.255.255.06 h. X) ]) L9 f8 ]! M9 U0 l* S% b: y% Q
ip nbar protocol-discovery" t* _. \& p1 \- |, Z0 z
ip flow ingress2 C8 i% u" T3 b
ip flow egress
4 m- M5 ^" i7 E. r( Uip nat inside
& F: i' R1 h6 uip virtual-reassembly
; ]! \7 b6 L* h0 Fip route-cache flow* q# W0 X. W J6 i2 W ~( s2 V- U
no ip mroute-cache
/ B( w! N* o7 T$ ?duplex auto, m4 P1 h& w, c x, u
speed auto
) G8 B8 }* W7 a, j/ o0 E7 ~% ] T!
9 c0 q% \& O# m8 b& i: P$ Rinterface FastEthernet0/14 J* [- X9 j5 |# S* ~* O O" z
bandwidth 2048
3 h' N3 T8 H! Z4 j) v( Jno ip address
. _' s' ~! Q( k" a+ M! xduplex auto
- _, `4 _ [9 ~% l! w, b xspeed auto' P3 z' q* `& o# N+ S6 D3 n! z) c
pppoe enable group global* c1 t, i! q5 U
pppoe-client dial-pool-number 14 J) {3 h6 ]% G O5 q( `; a' i, b+ t
!
/ \9 X) f3 I9 M4 A; g6 Q. d# Sinterface Virtual-Template1' i* i1 u) b3 c; f m8 P
ip unnumbered FastEthernet0/1
' |. Y0 }9 `4 W, G5 W4 \: epeer default ip address pool vpn-pool* F/ f7 m* e; H* k4 `# J6 o
ppp authentication chap vpdn
& U6 b; C3 }, @) Q9 V8 \ O!/ t$ ~2 h) F5 R) Q: l5 i
interface Dialer1 Y" s0 C5 o; Q$ \! e) _* S
bandwidth 2048
* x1 B5 Q8 X1 T: Sip address negotiated
, \* R1 k: H4 u0 J5 ~$ Yip mtu 1492. d( o6 B- j+ _& w" @, Q1 a. X2 ~6 i/ Z, Y
ip nat outside/ M; c6 {) I& \2 U
ip virtual-reassembly; C ]' A$ p# f/ D1 }, ?
encapsulation ppp
+ o2 p: m$ p% \7 Pno ip mroute-cache
$ b o' V, O% Z0 e, z# F" W; Edialer pool 1
! K& U5 x& x7 u; l* d6 U0 Hppp authentication pap callin% S c$ x" T/ B) v1 p6 A' y1 X. ^
ppp pap sent-username ****** password 0 *******/ b4 x5 ]* _( o- {8 H# ?
!
+ e$ A9 a5 d2 ]9 zrouter eigrp 100; j3 X2 G2 n0 m$ X0 s& ~% K
network 192.168.1.00 |8 s! l" j3 m5 a
network 192.168.199.0: Z( H# ?+ x6 \8 F. K* |
auto-summary4 U* J: V, a/ b: ?
!3 q% R# y3 Q) F b0 m3 m6 K
ip local pool vpn-pool 192.168.199.2 192.168.199.3
; _1 c* q2 H8 Z1 s' L& S; ^ip route 0.0.0.0 0.0.0.0 Dialer1
n; {, H' z4 @$ g0 H! & F. \2 L1 t7 Z2 B( d$ W. X. R
!
* R! C6 ?0 }; t' dip nat inside source list 1 interface Dialer1 overload
7 ~& O, d" w9 j. q. y!+ B5 \: Q+ M8 A! }
!( P) q) a, c8 z7 Q; `
access-list 1 permit 192.168.1.0 0.0.0.255
8 ?% d6 y2 {/ n1 X3 s8 P!3 p+ J, |/ B/ P' |
radius-server host ***.***.***.*** auth-port 1812 acct-port 1813 key ******
, |* s' L9 t# {!
* ?+ i! }& I) a7 Bcontrol-plane3 @& Z: T: v( p/ ^9 g2 i
!
8 e" c. [: r$ P. G!0 _0 ~: k; S P; M8 L1 D
banner login ^CThis is wingo router cisco 1841^C
+ M2 ?; G8 G2 I0 K!! U' v3 |$ Q; V' h
line con 0/ P% e" a3 s) ? P
line aux 03 A6 V' N- u+ O1 x
line vty 0 4* | ]/ r, ?) l" ~5 @
privilege level 151 z' ?: N: ~6 l T# l2 ~' n% f
password wingo8 M4 }, s0 g4 h2 _1 Y5 I0 [8 _" q
transport input telnet
+ X) P$ Y' k2 j* l# Y& h!
$ y' z, P$ B1 b& T# {scheduler allocate 20000 1000% h6 w9 f' M' E3 w8 y" n
end
+ ]4 S R3 M: i3 V: {问题是远程PC用VPN连接入VPN服务器之后只可以PING得通192.168.1.1。但PING不通内网其他的机器!还有就是VPN服务都不能PING得通远程PC! |
|