Поднят тунель между 871(c870-advipservicesk9-mz.124-24.T4.bin) и 2801 (c2801-advsecurityk9-mz.124-3h.bin). На 2801-й циске есть проброска портов на внутренние айпишники, которые должны быть доступны по этим же портам для другой стороны тунеля.871# ping 192.168.1.245 source vlan 13
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.245, timeout is 2 seconds:
Packet sent with a source address of 192.168.13.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/8/8 ms
871#telnet 192.168.1.245 25 /source-interface vlan 13
Trying 192.168.1.245, 25 ...
% Connection timed out; remote host not responding
если убрать ip nat inside source static tcp 192.168.1.245 25 217.2.1.1 25 extendable телнет проходит
при неудачном телнете по 25-м порту со стороны 2801 видим, что по тунелю проходит интересующий трафик, а потом насколько я понимаю натиться
2801#sh access-lists NAT
Extended IP access list NAT
5 deny ip host 192.168.1.245 192.168.13.0 0.0.0.255
15 deny ip 192.168.1.0 0.0.0.255 192.168.13.0 0.0.0.255 (8234 matches)
100 permit ip 192.168.1.0 0.0.0.255 any (14149 matches)
2801#sh access-lists INT_TRAFFIC
Extended IP access list INT_TRAFFIC
50 permit ip host 192.168.1.245 192.168.13.0 0.0.0.255 (3 matches)
100 permit ip 192.168.1.0 0.0.0.255 192.168.13.0 0.0.0.255 (6892 matches)
871:
interface FastEthernet4
ip address 188.1.2.2 255.255.255.248
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
crypto map VPN_MAP
!
vlan 13
interface Vlan13
ip address 192.168.13.1 255.255.255.0
ip nat inside
ip virtual-reassembly
ip nat inside source list NAT interface FastEthernet4 overload
!
ip access-list extended INT_TRAFFIC
permit ip 192.168.13.0 0.0.0.255 host 192.168.1.245
permit ip 192.168.13.0 0.0.0.255 192.168.1.0 0.0.0.255
ip access-list extended NAT
deny ip 192.168.13.0 0.0.0.255 192.168.1.0 0.0.0.255
permit ip 192.168.13.0 0.0.0.255 any
2801:
interface FastEthernet0/0.2
encapsulation dot1Q 2
ip address 192.168.1.250 255.255.255.0
ip nat inside
ip virtual-reassembly
no snmp trap link-status
!
interface FastEthernet0/1
description $ETH-WAN$
ip address 217.2.1.1 255.255.255.248
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
crypto map VPN_MAP
ip nat inside source list NAT interface FastEthernet0/1 overload
ip nat inside source static tcp 192.168.1.245 25 217.2.1.1 25 extendable
ip nat inside source static tcp 192.168.1.245 110 217.2.1.1 110 extendable
ip nat inside source static tcp 192.168.1.245 3000 217.2.1.1 3000 extendable
ip nat inside source static tcp 192.168.1.51 10000 217.2.1.1 10000 extendable
!
ip access-list extended INT_TRAFFIC
permit ip host 192.168.1.245 192.168.13.0 0.0.0.255 log
permit ip 192.168.1.0 0.0.0.255 192.168.13.0 0.0.0.255
ip access-list extended NAT
deny ip 192.168.1.0 0.0.0.255 192.168.13.0 0.0.0.255
permit ip 192.168.1.0 0.0.0.255 any
Заранее спасибо за помощь;)