<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Cisco 871 &amp; Easy Vpn Server </title>
    <link>https://opennet.ru/openforum/vsluhforumID6/22955.html</link>
    <description>Понимаю что тема избита, но почитав  по ней здесь + cisco.com так и не могу дать ума Easy VPN Server (Cisco 871) + Cisco VPN client v.5 (winXP) (over UDP)&lt;br&gt;Соединение успешно устанавливается, но доступа к внутренним ресурсам сети не получаю.&lt;br&gt;Не пингуется даже внутренний интерфейс маршрутизатора (из клиента).&lt;br&gt;tracert на клиенте (WinXP) даёт сразу таймауты.&lt;br&gt;С циски клиент тоже не доступен.&lt;br&gt; Настрока в клиенте &quot;Allow local lan access&quot; установлена.&lt;br&gt;конфиг:&lt;br&gt;!&lt;br&gt;version 12.4&lt;br&gt;no service pad&lt;br&gt;service tcp-keepalives-in&lt;br&gt;service tcp-keepalives-out&lt;br&gt;service timestamps debug datetime msec localtime show-timezone&lt;br&gt;service timestamps log datetime msec localtime show-timezone&lt;br&gt;service password-encryption&lt;br&gt;service sequence-numbers&lt;br&gt;!&lt;br&gt;hostname cisco&lt;br&gt;!&lt;br&gt;boot-start-marker&lt;br&gt;boot-end-marker&lt;br&gt;!&lt;br&gt;security authentication failure rate 3 log&lt;br&gt;security passwords min-length 6&lt;br&gt;logging buffered 4096 debugging&lt;br&gt;no logging console&lt;br&gt;enable secret 5 xxxxx&lt;br&gt;!&lt;br&gt;aaa new-model&lt;br&gt;!&lt;br&gt;!&lt;br&gt;aaa authentication login default local&lt;br&gt;aaa authentica</description>

<item>
    <title>Cisco 871 &amp; Easy Vpn Server  (engalichev)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/22955.html#3</link>
    <pubDate>Fri, 05 Aug 2011 18:46:11 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.49 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.1.9 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.1.7 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.1.6 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.24 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.30 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.254 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.252 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.140 any &lt;br&gt;&amp;gt; access-list 109 permit ip host 192.168.10.154 any &lt;br&gt;&lt;br&gt;nat улетают +1&lt;br&gt;&lt;br&gt;</description>
</item>

<item>
    <title>Cisco 871 &amp; Easy Vpn Server  (4x)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/22955.html#2</link>
    <pubDate>Fri, 05 Aug 2011 13:18:01 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.49 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.1.9 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.1.7 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.1.6 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.24 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.30 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.254 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.252 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.140 &lt;br&gt;&amp;gt; access-list 1 permit 192.168.10.154 &lt;br&gt;&lt;br&gt;Кажется, в НАТ улетает пакеты,  а не тебе. Примерно так надо (весь конфиг не смотрел):&lt;br&gt;&lt;br&gt;ip nat inside source list 109 interface FastEthernet4 overload &lt;br&gt;&lt;br&gt;access-list 109 deny   ip 192.168.1.0 0.0.0.255 192.168.5.0 0.0.0.255&lt;br&gt;access-list 109 deny   ip 192.168.10.0 0.0.0.255 192.168.5.0 0.0.0.255&lt;br&gt;access-list 109 permit ip host 192.168.10.49 any&lt;br&gt;access-list 109 permit ip host 192.168.1.9 any&lt;br&gt;access-list 109 permit ip host 192.168.1.7 any&lt;br&gt;access-list 109 permit ip host 192.168.1.6 any&lt;br&gt;access-list 109 permit ip host 192.168.10.24 any&lt;br&gt;access-list 109 permit ip host 192.168.10.30 any&lt;br&gt;access-list 109 </description>
</item>

<item>
    <title>Cisco 871 &amp; Easy Vpn Server  (Аноним)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/22955.html#1</link>
    <pubDate>Thu, 04 Aug 2011 17:42:16 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;  privilege level 15 &lt;br&gt;&amp;gt;  transport input telnet ssh &lt;br&gt;&amp;gt; !&lt;br&gt;&amp;gt; scheduler max-task-time 5000 &lt;br&gt;&amp;gt; scheduler allocate 4000 1000 &lt;br&gt;&amp;gt; scheduler interval 500 &lt;br&gt;&amp;gt; ntp clock-period 17175146 &lt;br&gt;&amp;gt; ntp server 192.168.10.254 &lt;br&gt;&amp;gt; end &lt;br&gt;&amp;gt; заранее спасибо за помощь!!&lt;br&gt;&lt;br&gt;Professional Level от Cisco?&lt;br&gt;</description>
</item>

</channel>
</rss>
