Вы находитесь на странице: 1из 4

no ip domain-lookup banner motd * Solo Personal Autorizado * enable secret cisco line con 0 pass cisco login exi

line vty 0 4 pass cisco login exi ****************************** autentificacion PAP username R1 password cisco123 interface s0/0/0 encapsulation ppp ppp authentication pap ppp pap sent-username R2 password cisco123 end

username R2 password cisco123 interface s0/0/0 encapsulation ppp ppp authentication pap ppp pap sent-username R1 password cisco123 end el username es el remoto el sent-username es local autenticacoion chap username R3 password cisco123 interface s0/0/1 encapsulation ppp ppp authentication chap username R1 password cisco123 interface s0/0/1 encapsulation ppp ppp authentication chap el username es el remoto ************************************ estatica********************************* ip nat inside source static (ip-interna) (ip externa) interface serial 0/0/1 ip nat outside interface fa0/0 ip nat inside

dinamica********************************** ip nat pool MY-NAT-POOL* (rango de direciones) netmask (mask del rango) ip access-list standar NAT* permit (red que se traducira) ip nat inside source list NAT* pool MY-NAT-POOL* interface serial 0/0/1 ip nat outside interface fa0/0 ip nat inside SOBRECARGO*********************************** ip access-list standar NAT* permit (red que se traducira) ip nat inside source list NAT* interface (interfaz de salida) overload interface serial 0/0/1 ip nat outside interface fa0/0 ip nat inside o acces-list 1 permit :net: :mas: **************************************** frame relay frame-relay switchin interface serial 0/0/0 clock rate 64000 encapsulation frame-relay frame-relay intf-type dce frame-relay route (dlcilocal) interface (interfaz y dlci destino) no shutdow no kee por si acaso router interface serial 0/0/1 encapsulation frame-relay no frame-relay inverse-arp frame-relay map ip (destino) (dlci-local) broadcast no shut interface Serial0/0/0.2 point-to-point ip address 192.168.3.1 255.255.255.0 frame-relay interface-dlci (dlci-local) en r1 inter ser 0/0/0 encap frame no frame inver frame map ip :la ip del serial del r2: :dlci:

no shut en r2 inter ser 0/0/0 encap frame no frame inver frame map ip :la ip del serial del r2: :dlci: no shut *************************************** **TCP**** 21 FTP 23 TELNET 25 SMTP 80 HTTP 110 POP3 194 IRC 443 HTTPS **UDP** 69 TFTP 520 RIP **TCP & UDP**** 53 DNS 161 SNMP R1 access-list 101 deny tcp 192.168.10.0 0.0.0.255 any eq telnet access-list 101 deny udp 192.168.10.0 0.0.0.255 host 192.168.20.254 eq tftp access-list 101 permit ip any any access-list 102 permit udp 192.168.11.0 0.0.0.255 host 192.168.20.254 eq www access-list 102 deny ip 192.168.11.0 0.0.0.255 192.168.20.0 0.0.0.255 access-list 102 permit ip any any R3 access-list access-list access-list access-list 103 103 103 103 permit permit permit permit ip 192.168.30.128 0.0.0.127 192.168.10.0 0.0.0.255 ip 192.168.30.128 0.0.0.127 192.168.11.0 0.0.0.255 tcp 192.168.30.128 0.0.0.127 any eq www icmp 192.168.30.128 0.0.0.127 any

R2 access-list 115 permit tcp any host 192.168.20.254 eq www access-list 115 permit tcp any any established access-list 115 permit icmp any any echo-reply

****************************** vlan

inter range fas 0/5-10 sw mode acc sw acc vlan :y la vlan: en el rou inter fas0/0.10 encap do 10 ip add ****************************** DHCP ip dhcp exclued-add :la direecion desd dond: :y hasta aki: ip adhcp pool :vlan o name: ne :la ip: defaul :el gate: dns- :y la ip:

****************************** looc en el isp ip route :la direccion de la red pegada del serial: :mascara: serial 0/0/0 en el d a la par ip rou 0.0.0.0 0.0.0.0 y el serial del serial del isp ro o 1 default_infor origi

****************************** debug ip nat clear ip nat trans sho ip nat transla sho frame debu frame lmi sho fram pvc sho frame route out a los q va a convertir o salir ins a la red local o entrar

Вам также может понравиться