Hoi, heel gek probleem hier.. Ik zit momenteel met twee Cisco SOHO routers waartussen een tunnel is opgezet en de route-regels zijn opgenomen.
Dit werkt. Beide routers kunnen elkaars LAN-IP pingen. Het pingen naar de systemen erachter is echter iets anders:
- Eerste keer een ping naar een systeem op het andere netwerk geeft 20% response.
- De overige keren: 0% response. Na pak hem beet een 10 minuten, krijg ik weer één ping voor elkaar ofzo..
Config Router A (Planet -> MxStream)
-----
!
version 12.3
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname <hostname>
!
enable secret 5 <password>
!
ip subnet-zero
ip name-server 195.121.1.34
ip name-server 195.121.1.66
ip dhcp excluded-address 192.168.20.1 192.168.20.50
!
ip dhcp pool CLIENT
import all
network 192.168.20.0 255.255.255.0
default-router 192.168.20.20
dns-server 192.168.10.10 195.121.1.66 195.121.1.34
lease 0 2
!
!
no aaa new-model
!
!
!
!
crypto isakmp policy 1
hash md5
authentication pre-share
crypto isakmp key 0 <de key> address aaa.bbb.ccc.ddd
!
!
crypto ipsec transform-set cm-transformset-1 ah-md5-hmac esp-des esp-md5-hmac
!
crypto map cm-cryptomap 1 ipsec-isakmp
set peer aaa.bbb.ccc.ddd
set transform-set cm-transformset-1
match address 100
!
!
!
!
interface Tunnel0
ip address 192.168.169.253 255.255.255.0
tunnel source Dialer0
tunnel destination aaa.bbb.ccc.ddd
crypto map cm-cryptomap
!
interface Ethernet0
ip address 192.168.20.20 255.255.255.0
ip nat inside
hold-queue 100 out
!
interface BRI0
no ip address
shutdown
!
interface ATM0
no ip address
no ip route-cache
no atm ilmi-keepalive
pvc 0 8/48
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl operating-mode auto
crypto map cm-cryptomap
!
interface Dialer0
ip address negotiated
ip access-group 102 in
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication pap callin
ppp pap sent-username <username> password 7 <password>
!
ip nat inside source list 101 interface Dialer0 overload
ip nat inside source static tcp 192.168.20.10 3389 interface Dialer0 3389
ip nat inside source static tcp 192.168.20.20 23 interface Dialer0 23
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer0 permanent
ip route 192.168.10.0 255.255.255.0 Tunnel0 permanent
no ip http server
no ip http secure-server
!
access-list 100 permit ip any any
access-list 101 permit ip any any
access-list 102 permit tcp host <beheerip_1> any eq telnet
access-list 102 permit tcp host <beheerip_2> any eq telnet
access-list 102 deny tcp any any eq telnet
access-list 102 permit ip any any
dialer-list 1 protocol ip permit
!
line con 0
exec-timeout 120 0
stopbits 1
line vty 0 4
exec-timeout 120 0
password 7 <password>
login
!
scheduler max-task-time 5000
!
!
end
Config Router B (Demon -> BBNed)
-----
!
version 12.3
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname <hostname>
!
enable secret 5 <password>
!
ip subnet-zero
!
!
no aaa new-model
!
!
!
!
crypto isakmp policy 1
hash md5
authentication pre-share
crypto isakmp key 0 <de key> address aaa.bbb.ccc.ddd
!
!
crypto ipsec transform-set cm-transformset-1 ah-md5-hmac esp-des esp-md5-hmac
!
crypto map cm-cryptomap local-address BVI1
crypto map cm-cryptomap 1 ipsec-isakmp
set peer aaa.bbb.ccc.ddd
set transform-set cm-transformset-1
match address 100
!
!
bridge irb
!
!
interface Tunnel0
ip address 192.168.169.254 255.255.255.0
tunnel source BVI1
tunnel destination aaa.bbb.ccc.ddd
crypto map cm-cryptomap
!
interface Ethernet0
ip address 192.168.10.23 255.255.255.0
ip nat inside
hold-queue 100 out
!
interface ATM0
no ip address
no ip mroute-cache
atm ilmi-keepalive
pvc 0/35
encapsulation aal5snap
!
dsl operating-mode auto
crypto map cm-cryptomap
bridge-group 1
!
interface BVI1
ip address dhcp client-id Ethernet0
ip access-group 102 in
ip nat outside
!
ip nat inside source list 101 interface BVI1 overload
ip nat inside source static tcp 192.168.10.11 3389 interface BVI1 3399
ip nat inside source static tcp 192.168.10.11 8008 interface BVI1 8008
ip nat inside source static tcp 192.168.10.10 8010 interface BVI1 8010
ip nat inside source static tcp 192.168.10.10 25 interface BVI1 25
ip nat inside source static tcp 192.168.10.10 110 interface BVI1 110
ip nat inside source static tcp 192.168.10.10 1723 interface BVI1 1723
ip nat inside source static tcp 192.168.10.10 3389 interface BVI1 3389
ip nat inside source static tcp 192.168.10.23 23 interface BVI1 23
ip classless
ip route 0.0.0.0 0.0.0.0 BVI1 permanent
ip route 156.48.0.0 255.255.0.0 192.168.10.22
ip route 192.168.20.0 255.255.255.0 Tunnel0 permanent
no ip http server
no ip http secure-server
!
access-list 100 permit ip any any
access-list 101 permit ip any any
access-list 102 permit tcp host <beheerip_1> any eq telnet
access-list 102 permit tcp host <beheerip_2> any eq telnet
access-list 102 deny tcp any any eq telnet
access-list 102 permit tcp host <beheerip_1> any eq 3389
access-list 102 permit tcp host <beheerip_2> any eq 3389
access-list 102 deny tcp any any eq 3389
access-list 102 permit ip any any
bridge 1 protocol ieee
bridge 1 route ip
!
line con 0
exec-timeout 120 0
no modem enable
stopbits 1
line aux 0
line vty 0 4
exec-timeout 120 0
password 7 <password>
login
!
no scheduler max-task-time
!
end
Dit werkt. Beide routers kunnen elkaars LAN-IP pingen. Het pingen naar de systemen erachter is echter iets anders:
- Eerste keer een ping naar een systeem op het andere netwerk geeft 20% response.
- De overige keren: 0% response. Na pak hem beet een 10 minuten, krijg ik weer één ping voor elkaar ofzo..
Config Router A (Planet -> MxStream)
-----
!
version 12.3
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname <hostname>
!
enable secret 5 <password>
!
ip subnet-zero
ip name-server 195.121.1.34
ip name-server 195.121.1.66
ip dhcp excluded-address 192.168.20.1 192.168.20.50
!
ip dhcp pool CLIENT
import all
network 192.168.20.0 255.255.255.0
default-router 192.168.20.20
dns-server 192.168.10.10 195.121.1.66 195.121.1.34
lease 0 2
!
!
no aaa new-model
!
!
!
!
crypto isakmp policy 1
hash md5
authentication pre-share
crypto isakmp key 0 <de key> address aaa.bbb.ccc.ddd
!
!
crypto ipsec transform-set cm-transformset-1 ah-md5-hmac esp-des esp-md5-hmac
!
crypto map cm-cryptomap 1 ipsec-isakmp
set peer aaa.bbb.ccc.ddd
set transform-set cm-transformset-1
match address 100
!
!
!
!
interface Tunnel0
ip address 192.168.169.253 255.255.255.0
tunnel source Dialer0
tunnel destination aaa.bbb.ccc.ddd
crypto map cm-cryptomap
!
interface Ethernet0
ip address 192.168.20.20 255.255.255.0
ip nat inside
hold-queue 100 out
!
interface BRI0
no ip address
shutdown
!
interface ATM0
no ip address
no ip route-cache
no atm ilmi-keepalive
pvc 0 8/48
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl operating-mode auto
crypto map cm-cryptomap
!
interface Dialer0
ip address negotiated
ip access-group 102 in
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication pap callin
ppp pap sent-username <username> password 7 <password>
!
ip nat inside source list 101 interface Dialer0 overload
ip nat inside source static tcp 192.168.20.10 3389 interface Dialer0 3389
ip nat inside source static tcp 192.168.20.20 23 interface Dialer0 23
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer0 permanent
ip route 192.168.10.0 255.255.255.0 Tunnel0 permanent
no ip http server
no ip http secure-server
!
access-list 100 permit ip any any
access-list 101 permit ip any any
access-list 102 permit tcp host <beheerip_1> any eq telnet
access-list 102 permit tcp host <beheerip_2> any eq telnet
access-list 102 deny tcp any any eq telnet
access-list 102 permit ip any any
dialer-list 1 protocol ip permit
!
line con 0
exec-timeout 120 0
stopbits 1
line vty 0 4
exec-timeout 120 0
password 7 <password>
login
!
scheduler max-task-time 5000
!
!
end
Config Router B (Demon -> BBNed)
-----
!
version 12.3
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname <hostname>
!
enable secret 5 <password>
!
ip subnet-zero
!
!
no aaa new-model
!
!
!
!
crypto isakmp policy 1
hash md5
authentication pre-share
crypto isakmp key 0 <de key> address aaa.bbb.ccc.ddd
!
!
crypto ipsec transform-set cm-transformset-1 ah-md5-hmac esp-des esp-md5-hmac
!
crypto map cm-cryptomap local-address BVI1
crypto map cm-cryptomap 1 ipsec-isakmp
set peer aaa.bbb.ccc.ddd
set transform-set cm-transformset-1
match address 100
!
!
bridge irb
!
!
interface Tunnel0
ip address 192.168.169.254 255.255.255.0
tunnel source BVI1
tunnel destination aaa.bbb.ccc.ddd
crypto map cm-cryptomap
!
interface Ethernet0
ip address 192.168.10.23 255.255.255.0
ip nat inside
hold-queue 100 out
!
interface ATM0
no ip address
no ip mroute-cache
atm ilmi-keepalive
pvc 0/35
encapsulation aal5snap
!
dsl operating-mode auto
crypto map cm-cryptomap
bridge-group 1
!
interface BVI1
ip address dhcp client-id Ethernet0
ip access-group 102 in
ip nat outside
!
ip nat inside source list 101 interface BVI1 overload
ip nat inside source static tcp 192.168.10.11 3389 interface BVI1 3399
ip nat inside source static tcp 192.168.10.11 8008 interface BVI1 8008
ip nat inside source static tcp 192.168.10.10 8010 interface BVI1 8010
ip nat inside source static tcp 192.168.10.10 25 interface BVI1 25
ip nat inside source static tcp 192.168.10.10 110 interface BVI1 110
ip nat inside source static tcp 192.168.10.10 1723 interface BVI1 1723
ip nat inside source static tcp 192.168.10.10 3389 interface BVI1 3389
ip nat inside source static tcp 192.168.10.23 23 interface BVI1 23
ip classless
ip route 0.0.0.0 0.0.0.0 BVI1 permanent
ip route 156.48.0.0 255.255.0.0 192.168.10.22
ip route 192.168.20.0 255.255.255.0 Tunnel0 permanent
no ip http server
no ip http secure-server
!
access-list 100 permit ip any any
access-list 101 permit ip any any
access-list 102 permit tcp host <beheerip_1> any eq telnet
access-list 102 permit tcp host <beheerip_2> any eq telnet
access-list 102 deny tcp any any eq telnet
access-list 102 permit tcp host <beheerip_1> any eq 3389
access-list 102 permit tcp host <beheerip_2> any eq 3389
access-list 102 deny tcp any any eq 3389
access-list 102 permit ip any any
bridge 1 protocol ieee
bridge 1 route ip
!
line con 0
exec-timeout 120 0
no modem enable
stopbits 1
line aux 0
line vty 0 4
exec-timeout 120 0
password 7 <password>
login
!
no scheduler max-task-time
!
end
[ Voor 3% gewijzigd door Zoetjuh op 05-05-2004 16:40 . Reden: Security update :D ]