PPTP клиент не видит локальную сеть.Впервые пришлось конфигурировать Cisco 2911 так что сильно не ругайте)
Подключаюсь c Win7 к PPTP серверу, получаю ip, dns и тд...
Но ни одного пакета на адреса локальной сети отправить не могу, соответственно кроме как на адрес самой кошки.
Что только не перепробовал, нужна помощь знатаков, уверен что проблема на поверхности, но в силу отсутствия опыта я не могу ее увидеть и исправить.
Врубил все логи ACL, пусто, инет пробрасыватся такое чувство что трабл в AAA.
Как по вашему вообще конфиг для новичка есть ли вопиющие ошибки и косяки? Что делать с PPTP? Заранее благодарен!
Вот конфиг кошки:
version 15.1
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service compress-config
service sequence-numbers
!
hostname Cisco
!
boot-start-marker
boot-end-marker
!
!
security authentication failure rate 3 log
security passwords min-length 6
logging buffered 51200
logging console critical
enable secret 5 //////////////////////////
enable password 7 ////////////////////////
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization console
aaa authorization exec default local
aaa authorization network default local
!
!
!
aaa session-id common
!
clock timezone Moscow 4 0
clock calendar-valid
!
no ipv6 cef
no ip source-route
ip cef
!
no ip bootp server
ip domain name abm
ip name-server 192.168.10.2
ip name-server 87.245.145.96
ip inspect log drop-pkt
ip inspect name FW dns
ip inspect name FW https
ip inspect name FW icmp
ip inspect name FW http
ip inspect name FW pop3
ip inspect name FW smtp
ip inspect name FW ssh
ip inspect name FW ftp
ip inspect name FW pop3s
ip inspect name FW tcp
ip inspect name FW udp
!
multilink bundle-name authenticated
!
parameter-map type inspect global
log dropped-packets enable
vpdn enable
vpdn logging
vpdn logging local
vpdn logging user
!
!
vpdn-group 1
! Default PPTP VPDN group
accept-dialin
protocol pptp
virtual-template 1
l2tp tunnel timeout no-session 15
!
!
crypto pki token default removal timeout 0
!
crypto pki trustpoint TP-self-signed-2227124110
!
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2227124110
revocation-check none
!
!
!
archive
log config
logging enable
hidekeys
username vpnuser privilege 0 password 7 12345
username Administrator privilege 15 view root secret 5 ////////////////
!
redundancy
!
!
ip tcp synwait-time 10
no ip ftp passive
ip ssh time-out 60
ip ssh authentication-retries 2
!
!
!
!
interface Null0
no ip unreachables
!
interface GigabitEthernet0/0
description LAN
ip address 192.168.10.7 255.255.255.0
ip access-group LAN in
no ip redirects
no ip unreachables
no ip proxy-arp
ip verify unicast reverse-path
ip flow ingress
ip nat inside
ip inspect FW in
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
interface GigabitEthernet0/1
description WAN
ip address 213.170.46.242 255.255.255.248
ip access-group WAN in
no ip redirects
!
no ip unreachables
no ip proxy-arp
ip verify unicast reverse-path
ip flow ingress
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
interface GigabitEthernet0/2
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
shutdown
duplex auto
speed auto
no mop enabled
!
interface Virtual-Template1
mtu 1480
ip unnumbered GigabitEthernet0/0
ip nat inside
ip inspect FW in
ip virtual-reassembly in
peer default ip address pool vpn
no keepalive
ppp authentication ms-chap-v2
ppp ipcp dns 192.168.10.2
!
!
ip local pool vpn 192.168.10.140 192.168.10.149
ip forward-protocol nd
!
ip http server
ip http access-class 2
ip http authentication local
ip http secure-server
!
ip dns server
ip nat inside source list NAT interface GigabitEthernet0/1 overload
ip route 0.0.0.0 0.0.0.0 213.170.46.249
!
ip access-list standard NAT
remark NAT
permit 192.168.10.0 0.0.0.255
!
ip access-list extended LAN
remark Lan to Wan
deny ip 213.170.46.248 0.0.0.7 any log
deny ip host 255.255.255.255 any log
deny ip 127.0.0.0 0.255.255.255 any log
permit udp host 192.168.10.2 eq domain any
permit tcp host 192.168.10.2 any eq smtp
permit udp host 192.168.10.2 host 192.168.10.7 eq ntp
deny tcp any any eq smtp log
permit ip 192.168.10.0 0.0.0.255 any
deny ip any any log
!
ip access-list extended WAN
remark Wan to Lan
permit tcp any any eq 1723
permit gre any host 213.170.46.242
permit tcp any host 213.170.46.242 eq 3000
permit icmp any host 213.170.46.242 log unreachable
deny ip 10.0.0.0 0.255.255.255 any log
deny ip 172.16.0.0 0.15.255.255 any log
deny ip 192.168.0.0 0.0.255.255 any log
deny ip 127.0.0.0 0.255.255.255 any log
deny ip host 255.255.255.255 any log
deny ip host 0.0.0.0 any log
deny ip any any log
!
logging esm config
logging trap debugging
logging 192.168.10.24
logging 192.168.10.14
access-list 2 remark HTTP Access-class list (using in ip http server)
access-list 2 remark CCP_ACL Category=1
access-list 2 permit 192.168.10.0 0.0.0.255 log
access-list 2 deny any log
!
no cdp run
!
!
control-plane
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 0 0
transport output telnet
line aux 0
transport output telnet
line vty 0 4
exec-timeout 60 0
privilege level 15
password 7 0010475451505256ghghghA
logging synchronous
transport input all
transport output none
!
scheduler allocate 20000 1000
ntp update-calendar
ntp server 192.168.10.2 prefer source GigabitEthernet0/1