MagistrAnatol
![](http://forum.ru-board.com/board/avatars/p149.gif)
Silver Member | Редактировать | Профиль | Сообщение | ICQ | Цитировать | Сообщить модератору народ, вот конфа Код: version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname c1841br ! boot-start-marker boot-end-marker ! logging buffered 51200 warnings ! aaa new-model ! ! aaa authentication login default local aaa authorization exec default local ! aaa session-id common clock timezone KYIV 2 clock summer-time KYIV recurring last Sun Mar 2:00 last Sun Oct 3:00 clock calendar-valid ip cef ! ! ! ! no ip domain lookup ip domain name ... ip host members.dyndns.org 204.13.248.112 ip auth-proxy max-nodata-conns 3 ip admission max-nodata-conns 3 ip ddns update method dyndns HTTP add ... remove ... interval maximum 28 0 0 0 interval minimum 28 0 0 0 ! vpdn enable ! vpdn-group 1 ! Default PPTP VPDN group accept-dialin protocol pptp virtual-template 1 ! ! ! crypto pki trustpoint TP-self-signed-261599588 enrollment selfsigned subject-name cn=IOS-Self-Signed-Certificate-261599588 revocation-check none rsakeypair TP-self-signed-261599588 ! ! crypto pki certificate chain .... quit username ... privilege 15 secret 5 ... username .. privilege 15 secret 5 .. username .. privilege 15 secret 5 .. username .. password 0 ... ! ! ! ! ! bba-group pppoe global ! ! interface Tunnel0 bandwidth 1024 ip address 192.168.202.3 255.255.255.0 no ip redirects ip mtu 1400 ip hold-time eigrp 1 35 ip nhrp authentication nhrp ip nhrp map 192.168.202.1 217.77.210.202 ip nhrp map multicast 217.77.210.202 ip nhrp network-id 1 ip nhrp nhs 192.168.202.1 ip nhrp registration no-unique tunnel source Dialer1 tunnel mode gre multipoint tunnel key 0 ! interface FastEthernet0/0 description Eth-Link-BR-network ip address 10.31.4.1 255.255.255.0 ip nat inside ip virtual-reassembly ip tcp adjust-mss 1360 duplex auto speed auto ! interface FastEthernet0/1 description Link-to-ADSL-Internet-modem ip address ... duplex auto speed auto pppoe enable group global pppoe-client dial-pool-number 1 ! interface Virtual-Template1 ip unnumbered FastEthernet0/0 peer default ip address pool vpn_pool no keepalive ppp encrypt mppe auto ppp authentication pap chap ms-chap ! interface Dialer1 mtu 1492 ip ddns update hostname ... ip ddns update dyndns ip address negotiated ip nat outside ip virtual-reassembly encapsulation ppp no ip mroute-cache dialer pool 1 dialer-group 1 ppp authentication pap callin ppp pap ... ! router eigrp 1 redistribute connected network 192.168.202.0 distribute-list 25 out distribute-list 24 in no auto-summary ! ip local pool vpn_pool 10.31.4.200 10.31.4.230 ip forward-protocol nd ip route 0.0.0.0 0.0.0.0 Dialer1 ! ! no ip http server ip http access-class 23 ip http authentication local ip http secure-server ip http timeout-policy idle 60 life 86400 requests 10000 ip nat inside source list 170 interface Dialer1 overload ip nat inside source static tcp 10.31.4.11 9966 interface Dialer1 9966 ip nat inside source static tcp 10.31.4.11 5651 interface Dialer1 5651 ip nat inside source static tcp 10.31.4.12 26666 interface Dialer1 26666 ip nat inside source static tcp 10.31.4.11 16666 interface Dialer1 16666 ip nat inside source static tcp 10.31.4.10 5655 interface Dialer1 5655 ip nat inside source static tcp 10.31.4.10 5670 interface Dialer1 5670 ! access-list 23 permit 192.168.72.24 access-list 23 permit 213.227.248.68 access-list 23 permit 10.31.0.0 0.0.0.255 access-list 23 permit 10.31.4.0 0.0.0.255 access-list 23 permit 217.77.210.200 0.0.0.7 access-list 23 permit 192.168.202.0 0.0.0.255 access-list 24 permit 192.168.0.0 0.0.255.255 access-list 24 permit 10.31.0.0 0.0.255.255 access-list 25 permit 192.168.202.3 access-list 25 permit 192.168.107.0 0.0.0.255 access-list 25 permit 10.31.4.0 0.0.0.255 access-list 70 permit 192.168.107.1 access-list 70 permit 192.168.107.10 access-list 70 permit 192.168.107.12 access-list 170 permit ip host 10.31.4.11 any access-list 170 permit ip host 10.31.4.12 any access-list 170 permit ip host 10.31.4.10 any access-list 170 permit ip host 10.31.4.14 any access-list 170 permit ip host 10.31.4.18 any access-list 170 permit ip host 10.31.4.5 any access-list 170 permit ip host 10.31.4.201 any | Одна притырянная прога пытается выйти в нет через прокси вышестоящей организации, через тунель. Можно как-то ее насильно заставить идти в нет не через впн вышестоящей, а через мой интернет?? ip nat outside source static tcp 217.20.163.54 interface Dialer1 даже не записывается в конфигурацию Run script (Циска (10.31.4.1)): Successfully completed executing commands. Logon ----------------------------------------------------------------------- Welcom to Bratskoe PAO Mykolaev GAZ ----------------------------------------------------------------------- User Access Verification Username: antarey Password: show version Cisco IOS Software, 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(25), RELEASE SOFTWARE |