Building configuration...
Current configuration : 2648 bytes
!
version 15.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname tsykm
!
boot-start-marker
boot-end-marker
!
!
enable secret 5
!
no aaa new-model
!
!
!
!
!
!
!
!
!
!
!
ip dhcp excluded-address 172.19.142.1 172.19.142.10
!
ip dhcp pool pool-tsykm
import all
network 172.19.142.0 255.255.255.0
default-router 172.19.142.1
dns-server 172.16.2.1 172.16.2.2
!
!
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
cts logging verbose
!
!
license udi pid CISCO1921/K9
!
!
username admin privilege 15 secret 5
!
redundancy
!
!
!
!
!
!
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
lifetime 1000
crypto isakmp key xxx address 1.1.1.1
!
!
crypto ipsec transform-set pix-set esp-3des esp-md5-hmac
mode tunnel
!
!
!
crypto map pix 10 ipsec-isakmp
set peer 1.1.1.1
set transform-set pix-set
match address 101
!
!
!
!
!
interface Embedded-Service-Engine0/0
no ip address
shutdown
!
interface GigabitEthernet0/0
ip address 172.19.142.1 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/1
no ip address
duplex auto
speed auto
pppoe enable group global
pppoe-client dial-pool-number 1
!
interface Dialer0
ip address negotiated
ip mtu 1452
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap pap callin
ppp chap hostname a18987592365
ppp chap password 0 abc123
ppp pap sent-username a18987592365 password 0 abc123
crypto map pix
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip route 0.0.0.0 0.0.0.0 Dialer0
!
dialer-list 1 protocol ip permit
!
!
snmp-server community Read@tsydss25 RO
snmp-server host 10.16.254.211 version 2c Read@tsydss25
access-list 101 permit ip 172.19.142.0 0.0.0.255 172.16.0.0 0.0.255.255
access-list 101 permit ip host 172.19.142.1 host 10.16.254.211
access-list 101 permit ip 172.19.142.0 0.0.0.255 host 10.16.253.247
access-list 102 permit ip 172.17.0.0 0.0.255.255 any
access-list 102 permit ip 172.18.0.0 0.0.255.255 any
access-list 102 permit ip 172.19.0.0 0.0.255.255 any
access-list 102 permit ip 172.16.168.0 0.0.1.255 any
access-list 102 permit ip 10.16.254.0 0.0.0.255 any
access-list 102 deny ip any any
!
control-plane
!
!
!
line con 0
line aux 0
line 2
no activation-character
no exec
transport preferred none
transport output pad telnet rlogin lapb-ta mop udptn v120 ssh
stopbits 1
line vty 0 4
privilege level 15
login local
transport input ssh
!
scheduler allocate 20000 1000
!
end
暂无评论