<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Config] Need help getting VPN traffic to access LAN space in Cisco</title>
<link>http://www.dslreports.com/forum/r22618246</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 13:20:54 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 13:20:54 EDT</lastBuildDate>

<item>
<title>Re: [Config] Need help getting VPN traffic to access LAN space</title>
<link>http://www.dslreports.com/forum/remark,22650563</link>
<description><![CDATA[<A HREF="/useremail/u/1499766"><b>phantasm11b</b></A> : SSH is fixed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22650563</guid>
<pubDate>Fri, 03 Jul 2009 16:25:45 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Need help getting VPN traffic to access LAN space</title>
<link>http://www.dslreports.com/forum/remark,22649901</link>
<description><![CDATA[<A HREF="/useremail/u/1499766"><b>phantasm11b</b></A> : I didn't notice your reply until now. Sorry for not responding. Here is where it is at:<br><br>Ok. Restarting this thread. I've been working with a member here on the configuration for my router, specifically the VPN. He's been very helpful but with this being a holiday weekend I would not expect him to be online much. As suggested by tubbynet I have not tried adding local-lan to the config. I will try this though.<br><br>Problems:<br>1. When users authenticateon my VPN I see these errors:<br><br>&raquo;<A HREF="http://pastebin.com/m657cf2d7" >pastebin.com/m657cf2d7</A><br><br><textarea name="code" class="text" cols=50 rows=10>Jul &nbsp;3 12:50:34.352 EDT: ISAKMP (0/2004): Unknown Attr: CONFIG_MODE_UNKNOWN (0x700C)&#012;1.Jul &nbsp;3 12:50:34.352 EDT: ISAKMP (0/2004): Unknown Attr: MODECFG_HOSTNAME (0x700A)&#012;2.Jul &nbsp;3 12:50:34.496 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;3.&nbsp; &nbsp; {esp-aes 256 esp-md5-hmac comp-lzs }&#012;4.Jul &nbsp;3 12:50:34.496 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;5.Jul &nbsp;3 12:50:34.496 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;6.&nbsp; &nbsp; {esp-aes 256 esp-sha-hmac comp-lzs }&#012;7.Jul &nbsp;3 12:50:34.496 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;8.Jul &nbsp;3 12:50:34.496 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;9.&nbsp; &nbsp; {esp-aes esp-md5-hmac comp-lzs }&#012;10.Jul &nbsp;3 12:50:34.500 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;11.Jul &nbsp;3 12:50:34.500 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;12.&nbsp; &nbsp; {esp-aes esp-sha-hmac comp-lzs }&#012;13.Jul &nbsp;3 12:50:34.500 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;14.Jul &nbsp;3 12:50:34.500 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;15.&nbsp; &nbsp; {esp-aes 256 esp-md5-hmac }&#012;16.Jul &nbsp;3 12:50:34.500 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;17.Jul &nbsp;3 12:50:34.500 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;18.&nbsp; &nbsp; {esp-aes 256 esp-sha-hmac }&#012;19.Jul &nbsp;3 12:50:34.500 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;20.Jul &nbsp;3 12:50:34.500 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity: &#012;21.&nbsp; &nbsp; {esp-aes esp-md5-hmac }&#012;22.Jul &nbsp;3 12:50:34.500 EDT: ISAKMP:(2004): IPSec policy invalidated proposal with error 256&#012;23.TheDarkSide#&#012;24.Jul &nbsp;3 12:50:34.508 EDT: %CRYPTO-5-SESSION_STATUS: Crypto tunnel is UP &nbsp;. &nbsp;Peer xxx.xxx.xxx.xxx &nbsp; &nbsp; &nbsp; Id: xxxxx&#012;</textarea><!--end code block--><br>2. Users cannot access LAN assets, particularly 192.168.1.2 (Cisco 2619 &#150; lab router).<br><br>3. SSH does not work in either direction. I've disabled the inbound_wan ACL and ssh works. I re-enable it and it does not, however no entries are shown against the ACL when someone tries to connect. The large number of blocked networks have not been an issue until today. SSH worked yesterday, today it does not. What changed? A lot. Lol.<br><br>Here's the configuration as it stands.Everything works with the exception of what is mentioned above.<br><br><textarea name="code" class="text" cols=50 rows=10> &#012;!&#012;! Last configuration change at 12:34:26 EDT Fri Jul 3 2009 by xxxxxxxxxxxxx&#012;! NVRAM config last updated at 12:57:13 EDT Fri Jul 3 2009 by xxxxxxxxxxxxx&#012;!&#012;version 12.4&#012;no service pad&#012;service timestamps debug datetime msec localtime show-timezone&#012;service timestamps log datetime msec localtime show-timezone&#012;service password-encryption&#012;!&#012;hostname xxxxxxxxxxxxx&#012;!&#012;boot-start-marker&#012;boot-end-marker&#012;!&#012;logging buffered 4096 notifications&#012;!&#012;aaa new-model&#012;!&#012;!&#012;aaa authentication login default local&#012;aaa authorization exec default local &#012;aaa authorization network groupauthor local &#012;!&#012;!&#012;aaa session-id common&#012;clock timezone EDT -5&#012;clock summer-time EDT recurring&#012;!&#012;crypto pki trustpoint TP-self-signed-117880434&#012; enrollment selfsigned&#012; subject-name cn=IOS-Self-Signed-Certificate-117880434&#012; revocation-check none&#012; rsakeypair TP-self-signed-117880434&#012;!&#012;!&#012;crypto pki certificate chain TP-self-signed-117880434&#012; certificate self-signed 01 nvram:IOS-Self-Sig#1.cer&#012;!&#012;dot11 ssid xxxxxxxxxxxxx&#012;   vlan 1&#012;   authentication open &#012;   authentication key-management wpa&#012;   guest-mode&#012;   wpa-psk ascii 7 xxxxxxxxxxxxx&#012;!&#012;ip cef&#012;!&#012;!&#012;no ip dhcp use vrf connected&#012;ip dhcp excluded-address 192.168.1.1 192.168.1.10&#012;!&#012;ip dhcp pool Home&#012;   network 192.168.1.0 255.255.255.0&#012;   dns-server 65.32.5.111 65.32.5.112 &#012;   default-router 192.168.1.1 &#012;!&#012;!&#012;ip domain name tds.net-freaks.com&#012;ip inspect name MyFw cuseeme&#012;ip inspect name MyFw ftp&#012;ip inspect name MyFw h323&#012;ip inspect name MyFw icmp&#012;ip inspect name MyFw netshow&#012;ip inspect name MyFw rcmd&#012;ip inspect name MyFw realaudio&#012;ip inspect name MyFw rtsp&#012;ip inspect name MyFw esmtp&#012;ip inspect name MyFw sqlnet&#012;ip inspect name MyFw streamworks&#012;ip inspect name MyFw tftp&#012;ip inspect name MyFw tcp&#012;ip inspect name MyFw udp&#012;ip inspect name MyFw vdolive&#012;ip auth-proxy max-nodata-conns 3&#012;ip admission max-nodata-conns 3&#012;!&#012;multilink bundle-name authenticated&#012;!&#012;!&#012;username xxxxxxxxxxxxx privilege 15 password 7 xxxxxxxxxxxxx&#012;username xxxxxxxxxxxxx privilege 15 password 7 xxxxxxxxxxxxx&#012;! &#012;crypto logging session&#012;!&#012;crypto isakmp policy 3&#012; encr aes 256&#012; authentication pre-share&#012; group 2&#012;!&#012;crypto isakmp client configuration group HomeVPN&#012; key xxxxxxxxxxxxx&#012; dns xxxxxxxxxxxxx xxxxxxxxxxxxx&#012; pool VPN-Pool&#012; acl VPN-Traffic&#012; netmask 255.255.255.0&#012;!&#012;!&#012;crypto ipsec transform-set myset esp-aes esp-sha-hmac &#012;!&#012;crypto dynamic-map dynmap 10&#012; set transform-set myset &#012; reverse-route&#012;!&#012;!&#012;crypto map clientmap client authentication list userauthen&#012;crypto map clientmap isakmp authorization list groupauthor&#012;crypto map clientmap client configuration address respond&#012;crypto map clientmap 10 ipsec-isakmp dynamic dynmap &#012;!&#012;archive&#012; log config&#012;  hidekeys&#012;!&#012;!&#012;ip ssh maxstartups 2&#012;ip ssh time-out 15&#012;ip ssh logging events&#012;!&#012;bridge irb&#012;!&#012;!&#012;interface FastEthernet0&#012; load-interval 30&#012; shutdown&#012; spanning-tree portfast&#012;!&#012;interface FastEthernet1&#012; description Cisco Lab Interface&#012; load-interval 30&#012; duplex full&#012; speed 10&#012;!&#012;interface FastEthernet2&#012; description Blu Ray Player&#012; load-interval 30&#012;!&#012;interface FastEthernet3&#012; description Linux box&#012; load-interval 30&#012; duplex full&#012;!&#012;interface FastEthernet4&#012; description WAN Interface&#012; ip address dhcp&#012; ip access-group inbound_wan in&#012; ip nat outside&#012; ip inspect MyFw out&#012; ip virtual-reassembly&#012; load-interval 30&#012; duplex auto&#012; speed auto&#012; no cdp enable&#012; crypto map clientmap&#012;!&#012;interface Dot11Radio0&#012; no ip address&#012; no dot11 extension aironet&#012; !&#012; encryption vlan 1 mode ciphers tkip &#012; !&#012; ssid xxxxxxxxxxxxx&#012; !&#012; speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0&#012; station-role root&#012; no cdp enable&#012;!&#012;interface Dot11Radio0.1&#012; encapsulation dot1Q 1 native&#012; bridge-group 1&#012; bridge-group 1 subscriber-loop-control&#012; bridge-group 1 spanning-disabled&#012; bridge-group 1 block-unknown-source&#012; no bridge-group 1 source-learning&#012; no bridge-group 1 unicast-flooding&#012;!&#012;interface Vlan1&#012; description Internal network&#012; no ip address&#012; ip nat inside&#012; ip virtual-reassembly&#012; bridge-group 1&#012; bridge-group 1 spanning-disabled&#012;!&#012;interface BVI1&#012; description Bridge for LAN interfaces&#012; ip address 192.168.1.1 255.255.255.0&#012; ip nat inside&#012; ip virtual-reassembly&#012;!&#012;ip local pool VPN-Pool 10.10.29.101 10.10.29.105&#012;ip forward-protocol nd&#012;ip route 0.0.0.0 0.0.0.0 FastEthernet4&#012;!&#012;!&#012;no ip http server&#012;no ip http secure-server&#012;ip nat inside source route-map outbound_route_map interface FastEthernet4 overload&#012;!&#012;ip access-list extended VPN-Traffic&#012; permit tcp 10.10.29.0 0.0.0.255 eq telnet host 192.168.1.2 eq telnet&#012;ip access-list extended inbound_wan&#012; remark Block RIPE NCC&#012; deny   ip 62.0.0.0 0.255.255.255 any&#012; deny   ip 77.0.0.0 0.255.255.255 any&#012; deny   ip 78.0.0.0 1.255.255.255 any&#012; deny   ip 80.0.0.0 7.255.255.255 any&#012; deny   ip 88.0.0.0 3.255.255.255 any&#012; deny   ip 92.0.0.0 1.255.255.255 any&#012; deny   ip 109.0.0.0 0.255.255.255 any&#012; deny   ip 141.0.0.0 0.255.255.255 any&#012; deny   ip 145.0.0.0 0.255.255.255 any&#012; deny   ip 151.0.0.0 0.255.255.255 any&#012; deny   ip 178.0.0.0 0.255.255.255 any&#012; deny   ip 188.0.0.0 0.255.255.255 any&#012; deny   ip 193.0.0.0 0.255.255.255 any&#012; deny   ip 194.0.0.0 1.255.255.255 any&#012; deny   ip 212.0.0.0 1.255.255.255 any&#012; remark Block APNIC&#012; deny   ip 43.0.0.0 0.255.255.255 any&#012; deny   ip 58.0.0.0 1.255.255.255 any&#012; deny   ip 60.0.0.0 1.255.255.255 any&#012; deny   ip 110.0.0.0 1.255.255.255 any&#012; deny   ip 112.0.0.0 7.255.255.255 any&#012; deny   ip 120.0.0.0 3.255.255.255 any&#012; deny   ip 124.0.0.0 1.255.255.255 any&#012; deny   ip 133.0.0.0 0.255.255.255 any&#012; deny   ip 153.0.0.0 0.255.255.255 any&#012; deny   ip 171.0.0.0 0.255.255.255 any&#012; deny   ip 180.0.0.0 0.255.255.255 any&#012; deny   ip 183.0.0.0 0.255.255.255 any&#012; deny   ip 202.0.0.0 1.255.255.255 any&#012; deny   ip 210.0.0.0 1.255.255.255 any&#012; deny   ip 218.0.0.0 1.255.255.255 any&#012; deny   ip 220.0.0.0 1.255.255.255 any&#012; remark Block LACNIC&#012; deny   ip 186.0.0.0 1.255.255.255 any&#012; deny   ip 189.0.0.0 0.255.255.255 any&#012; deny   ip 190.0.0.0 1.255.255.255 any&#012; deny   ip 200.0.0.0 1.255.255.255 any&#012; remark Block AfriNIC&#012; deny   ip 41.0.0.0 0.255.255.255 any&#012; deny   ip 154.0.0.0 0.255.255.255 any&#012; deny   ip 196.0.0.0 1.255.255.255 any&#012; remark Block unallocated&#012; deny   ip 240.0.0.0 7.255.255.255 any&#012; deny   ip 248.0.0.0 7.255.255.255 any&#012; remark Block RFC 1918 address space&#012; permit udp any eq bootps any eq bootpc&#012; deny   ip 10.0.0.0 0.255.255.255 any&#012; deny   ip 127.0.0.0 0.255.255.255 any&#012; deny   ip 172.16.0.0 0.15.255.255 any&#012; deny   ip 192.168.0.0 0.0.255.255 any&#012; deny   ip host 255.255.255.255 any&#012; permit tcp any eq 22 any eq 22&#012; permit udp any eq 22 any eq 22&#012; permit udp any eq ntp any eq ntp&#012; permit udp any any eq isakmp&#012; permit udp any any eq non500-isakmp&#012; permit icmp any any echo&#012; permit icmp any any echo-reply&#012; permit icmp any any time-exceeded&#012; permit icmp any any unreachable&#012; permit udp any eq domain any&#012; deny   ip any any log&#012;ip access-list extended outbound_route_map&#012; deny   ip 192.168.1.0 0.0.0.255 10.10.29.0 0.0.0.255&#012; deny   ip 10.10.29.0 0.0.0.255 192.168.1.0 0.0.0.255&#012; permit ip 192.168.1.0 0.0.0.255 any&#012; permit ip 10.10.29.0 0.0.0.255 any&#012;!&#012;!&#012;!&#012;!&#012;route-map outbound_route_map permit 1&#012; match ip address outbound_route_map&#012;!&#012;!&#012;control-plane&#012;!&#012;bridge 1 protocol ieee&#012;bridge 1 route ip&#012;!&#012;line con 0&#012; exec-timeout 5 0&#012; logging synchronous&#012; no modem enable&#012; transport output all&#012;line aux 0&#012; transport output all&#012;line vty 0 3&#012; exec-timeout 5 0&#012; logging synchronous&#012; transport input telnet&#012; transport output all&#012;line vty 4&#012; exec-timeout 5 0&#012; logging synchronous&#012; transport input ssh&#012; transport output all&#012;!&#012;scheduler max-task-time 5000&#012;ntp logging&#012;ntp clock-period 17175054&#012;ntp server xxxxxxxxxxxxx&#012;ntp server xxxxxxxxxxxxx prefer&#012;end&#012;</textarea><!--end code block--><br><small>--<br>"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22649901</guid>
<pubDate>Fri, 03 Jul 2009 13:45:23 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Need help getting VPN traffic to access LAN space</title>
<link>http://www.dslreports.com/forum/remark,22649873</link>
<description><![CDATA[<A HREF="/useremail/u/1520629"><b>tubbynet</b></A> : are you split-tunneling the vpn connection or are you tunneling everything?<br><br>have you tried adding "include-local-lan" under your crypto group?<br><br>if you are denying nat in the route-map by subnet, then you shouldn't need to deny each individual host...<br><br>when trying to ping the 1.2 device, are you getting timeouts or replies from a public ip address?  have you tried traceing the route to ensure that you are going out the vpn interface and not the public interwebz?<br><br>q.<br><small>--<br>"...if I in my north room dance naked, grotesquely before my mirror waving my shirt round my head and singing softly to myself..."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22649873</guid>
<pubDate>Fri, 03 Jul 2009 13:38:33 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Need help getting VPN traffic to access LAN space</title>
<link>http://www.dslreports.com/forum/remark,22624019</link>
<description><![CDATA[<A HREF="/useremail/u/1499766"><b>phantasm11b</b></A> : So here's the current state of my outbound_route_map. With this the 192.168.1.1 is accessible but the .1.2 is not.<br><br><textarea name="code" class="text" cols=50 rows=10>Extended IP access list outbound_route_map&#012;    10 deny ip host 192.168.1.2 host 172.29.100.1&#012;    20 deny ip host 192.168.1.2 host 172.29.100.2&#012;    30 deny ip host 192.168.1.2 host 172.29.100.3&#012;    40 deny ip host 192.168.1.2 host 172.29.100.4&#012;    50 deny ip host 192.168.1.2 host 172.29.100.5&#012;    60 deny ip host 192.168.1.1 host 172.29.100.1&#012;    70 deny ip host 192.168.1.1 host 172.29.100.2&#012;    80 deny ip host 192.168.1.1 host 172.29.100.3 (7 matches)&#012;    90 deny ip host 192.168.1.1 host 172.29.100.4&#012;    100 deny ip host 192.168.1.1 host 172.29.100.5&#012;    110 permit ip 192.168.1.0 0.0.0.255 any (59 matches)&#012;    120 permit ip 172.29.100.0 0.0.0.255 any (33 matches)&#012;</textarea><!--end code block--><br><small>--<br>"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22624019</guid>
<pubDate>Sun, 28 Jun 2009 13:56:58 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Need help getting VPN traffic to access LAN space</title>
<link>http://www.dslreports.com/forum/remark,22619743</link>
<description><![CDATA[<A HREF="/useremail/u/1499766"><b>phantasm11b</b></A> : Perhaps the issue is with the route map? Maybe I should add a statement permitting the 172.29.100.x access to 192.168.1.2? Hm. I'll try that.<br><small>--<br>"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22619743</guid>
<pubDate>Sat, 27 Jun 2009 09:18:30 EDT</pubDate>
</item>

<item>
<title>[Config] Need help getting VPN traffic to access LAN space</title>
<link>http://www.dslreports.com/forum/remark,22618246</link>
<description><![CDATA[<A HREF="/useremail/u/1499766"><b>phantasm11b</b></A> : Ok. The VPN works and I can connect but not one is able to access the IP 192.168.1.2. I think I need an IP route statement but am unsure how to route it since the LAN ports are in the BVI. Could someone give me a hand please?<br><br><textarea name="code" class="text" cols=50 rows=10> &#012;!&#012;! Last configuration change at 20:57:25 EDT Fri Jun 26 2009 by drek&#012;! NVRAM config last updated at 20:01:25 EDT Fri Jun 26 2009 by drek&#012;!&#012;version 12.4&#012;no service pad&#012;service timestamps debug datetime msec localtime show-timezone&#012;service timestamps log datetime msec localtime show-timezone&#012;service password-encryption&#012;!&#012;hostname TheDarkSide&#012;!&#012;boot-start-marker&#012;boot-end-marker&#012;!&#012;logging buffered 4096 notifications&#012;!&#012;aaa new-model&#012;!&#012;!&#012;aaa authentication login default local&#012;aaa authorization exec default local &#012;aaa authorization network groupauthor local &#012;!&#012;!&#012;aaa session-id common&#012;clock timezone EDT -5&#012;clock summer-time EDT recurring&#012;!&#012;crypto pki trustpoint TP-self-signed-117880434&#012; enrollment selfsigned&#012; subject-name cn=IOS-Self-Signed-Certificate-117880434&#012; revocation-check none&#012; rsakeypair TP-self-signed-117880434&#012;!&#012;!&#012;crypto pki certificate chain TP-self-signed-117880434&#012; certificate self-signed 01&#012; xxxxxxxxxxxxxxxxxxxx&#012;  quit&#012;!&#012;dot11 ssid BenFranklin&#012;   vlan 1&#012;   authentication open &#012;   authentication key-management wpa&#012;   guest-mode&#012;   wpa-psk ascii 7 xxxxxxxxxxxxxxxxxxxxx&#012;!&#012;ip cef&#012;!&#012;!&#012;no ip dhcp use vrf connected&#012;ip dhcp excluded-address 192.168.1.1 192.168.1.10&#012;!&#012;ip dhcp pool VLAN1&#012;   import all&#012;   network 192.168.1.0 255.255.255.0&#012;   default-router 192.168.1.1 &#012;   dns-server xxxxxxxxxxxxxxxxxx &#012;!&#012;!&#012;ip domain name TheDarkSide.net&#012;ip inspect name SDM_LOW cuseeme&#012;ip inspect name SDM_LOW ftp&#012;ip inspect name SDM_LOW h323&#012;ip inspect name SDM_LOW icmp&#012;ip inspect name SDM_LOW netshow&#012;ip inspect name SDM_LOW rcmd&#012;ip inspect name SDM_LOW realaudio&#012;ip inspect name SDM_LOW rtsp&#012;ip inspect name SDM_LOW esmtp&#012;ip inspect name SDM_LOW sqlnet&#012;ip inspect name SDM_LOW streamworks&#012;ip inspect name SDM_LOW tftp&#012;ip inspect name SDM_LOW tcp&#012;ip inspect name SDM_LOW udp&#012;ip inspect name SDM_LOW vdolive&#012;ip auth-proxy max-nodata-conns 3&#012;ip admission max-nodata-conns 3&#012;!&#012;multilink bundle-name authenticated&#012;!&#012;!&#012;username drek privilege 15 password 7 xxxxxxxxxxxxxxxxx&#012;! &#012;!&#012;crypto isakmp policy 3&#012; encr aes 256&#012; authentication pre-share&#012; group 2&#012;!&#012;crypto isakmp client configuration group vpnclient&#012; key xxxxxxxxxxxxxxxxxxxxx&#012; pool ippool&#012;!&#012;!&#012;crypto ipsec transform-set myset esp-aes esp-sha-hmac &#012;!&#012;crypto dynamic-map dynmap 10&#012; set transform-set myset &#012; reverse-route&#012;!&#012;!&#012;crypto map clientmap client authentication list userauthen&#012;crypto map clientmap isakmp authorization list groupauthor&#012;crypto map clientmap client configuration address respond&#012;crypto map clientmap 10 ipsec-isakmp dynamic dynmap &#012;!&#012;crypto ctcp port 443 10000 &#012;archive&#012; log config&#012;  hidekeys&#012;!&#012;!&#012;!&#012;bridge irb&#012;!&#012;!&#012;interface FastEthernet0&#012; load-interval 30&#012; shutdown&#012;!&#012;interface FastEthernet1&#012; description Cisco Lab Interface&#012; load-interval 30&#012; duplex full&#012; speed 10&#012;!&#012;interface FastEthernet2&#012; description Blu Ray Player&#012; load-interval 30&#012;!&#012;interface FastEthernet3&#012; description Linux Box&#012; load-interval 30&#012; duplex full&#012;!&#012;interface FastEthernet4&#012; description WAN Interface&#012; ip address dhcp&#012; ip access-group inbound_wan in&#012; ip nat outside&#012; ip inspect SDM_LOW out&#012; ip virtual-reassembly&#012; load-interval 30&#012; duplex auto&#012; speed auto&#012; no cdp enable&#012; crypto map clientmap&#012;!&#012;interface Dot11Radio0&#012; no ip address&#012; no dot11 extension aironet&#012; !&#012; encryption vlan 1 mode ciphers tkip &#012; !&#012; ssid xxxxxxxxxxxxxx&#012; !&#012; speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0&#012; station-role root&#012; no cdp enable&#012;!&#012;interface Dot11Radio0.1&#012; encapsulation dot1Q 1 native&#012; bridge-group 1&#012; bridge-group 1 subscriber-loop-control&#012; bridge-group 1 spanning-disabled&#012; bridge-group 1 block-unknown-source&#012; no bridge-group 1 source-learning&#012; no bridge-group 1 unicast-flooding&#012;!&#012;interface Vlan1&#012; description Internal network&#012; no ip address&#012; ip nat inside&#012; ip virtual-reassembly&#012; bridge-group 1&#012; bridge-group 1 spanning-disabled&#012;!&#012;interface BVI1&#012; description Layer-3 LAN interface to bridge FA1-3 ports$FW_INSIDE$&#012; ip address 192.168.1.1 255.255.255.0&#012; ip access-group cisco_lab out&#012; ip nat inside&#012; ip virtual-reassembly&#012;!&#012;ip local pool ippool 172.29.100.1 172.29.100.5&#012;no ip forward-protocol nd&#012;!&#012;!&#012;no ip http server&#012;no ip http secure-server&#012;ip nat inside source route-map outbound_route_map interface FastEthernet4 overload&#012;!&#012;ip access-list extended cisco_lab&#012; permit ip 172.29.100.0 0.0.0.255 host 192.168.1.2&#012; permit ip any any&#012;ip access-list extended inbound_wan&#012; remark Inbound WAN ACL&#012; permit tcp any any eq 22&#012; permit ahp any any&#012; permit esp any any&#012; permit udp any any eq isakmp&#012; permit udp any any eq non500-isakmp&#012; permit udp any eq bootps any eq bootpc&#012; permit icmp any any echo-reply&#012; permit icmp any any time-exceeded&#012; permit icmp any any unreachable&#012; deny   ip 10.0.0.0 0.255.255.255 any&#012; deny   ip 172.16.0.0 0.15.255.255 any&#012; deny   ip 192.168.0.0 0.0.255.255 any&#012; deny   ip 127.0.0.0 0.255.255.255 any&#012; deny   ip host 255.255.255.255 any&#012; deny   ip any any log&#012;ip access-list extended outbound_route_map&#012; deny   ip 192.168.1.0 0.0.0.255 host 172.29.100.1&#012; deny   ip 192.168.1.0 0.0.0.255 host 172.29.100.2&#012; deny   ip 192.168.1.0 0.0.0.255 host 172.29.100.3&#012; deny   ip 192.168.1.0 0.0.0.255 host 172.29.100.4&#012; deny   ip 192.168.1.0 0.0.0.255 host 172.29.100.5&#012; deny   ip host 192.168.1.1 host 172.29.100.1&#012; deny   ip host 192.168.1.1 host 172.29.100.2&#012; deny   ip host 192.168.1.1 host 172.29.100.3&#012; deny   ip host 192.168.1.1 host 172.29.100.4&#012; deny   ip host 192.168.1.1 host 172.29.100.5&#012; permit ip 192.168.1.0 0.0.0.255 any&#012; permit ip 172.29.100.0 0.0.0.255 any&#012;!&#012;!&#012;!&#012;!&#012;route-map outbound_route_map permit 1&#012; match ip address outbound_route_map&#012;!&#012;!&#012;control-plane&#012;!&#012;bridge 1 protocol ieee&#012;bridge 1 route ip&#012;!&#012;line con 0&#012; exec-timeout 5 0&#012; logging synchronous&#012; no modem enable&#012; transport output all&#012;line aux 0&#012; transport output all&#012;line vty 0 3&#012; exec-timeout 5 0&#012; logging synchronous&#012; transport input telnet&#012; transport output all&#012;line vty 4&#012; exec-timeout 5 0&#012; logging synchronous&#012; transport input ssh&#012; transport output all&#012;!&#012;scheduler max-task-time 5000&#012;ntp logging&#012;ntp clock-period 17175082&#012;ntp server 71.40.128.157 prefer&#012;end&#012;</textarea><!--end code block--><br><small>--<br>"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy</small><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22618246</guid>
<pubDate>Fri, 26 Jun 2009 21:12:49 EDT</pubDate>
</item>

</channel>
</rss>
