Автор: bga83
Дата сообщения: 02.07.2014 10:56
ситуация следующая: есть две циски, надо поднять между ними туннель. В свзяи с тем, что одна из их за неподконтрольным мне провайдерским натом вариант в IPSEC GRE отпадает, из того что сразу приходит на ум PPTP.
На той циске что имеет реальный адрес настроен PPTP-сервер, все корректно работает, во всяком случае WIndows-клиент нормально соединяется, получает адрес, требуемые ресурсы доступны.
А вот с настройкой PPTP-клиента в циске возникли проблемы. Туннель не поднимается
[more=Конфиг..]
Current configuration : 4541 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
service internal
!
hostname c851
!
boot-start-marker
boot-end-marker
!
no logging buffered
!
no aaa new-model
!
resource policy
!
ip subnet-zero
no ip gratuitous-arps
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.3.51 192.168.3.254
ip dhcp excluded-address 192.168.0.1 192.168.3.9
ip dhcp excluded-address 192.168.3.1 192.168.3.8
ip dhcp excluded-address 192.168.3.1 192.168.3.9
!
ip dhcp pool DHCP_pool
network 192.168.1.0 255.255.255.0
dns-server 8.8.8.8
default-router 192.168.1.1
!
ip dhcp pool wifi
network 192.168.3.0 255.255.255.0
dns-server 8.8.8.8
default-router 192.168.3.1
!
!
ip cef
ip domain name home.int
ip name-server 192.168.245.14
ip name-server 192.168.248.21
ip multicast-routing
vpdn enable
!
vpdn-group 1
request-dialin
protocol pptp
rotary-group 0
initiate-to ip <реальный адрес циски, где поднят PPTP-сервер>
!
!
!
crypto pki trustpoint TP-self-signed-1409342422
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1409342422
revocation-check none
rsakeypair TP-self-signed-1409342422
!
!
crypto pki certificate chain TP-self-signed-1409342422
certificate self-signed 01
30820245 308201AE A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343039 33343234 3232301E 170D3036 30343130 31383232
32355A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34303933
34323432 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100A4B6 33ED5927 7EC4C317 7DE0E639 8456CC54 0BFDBB92 79410C1D 0B1C536A
C0EC1F91 0EF8F4D4 AA2ECE75 4F7EC339 F055FE7F FFCFB4EE 23F9E567 B65FC12F
29572D9B 8630EBEC F687625D C5CD687A 0C31EEE6 73A63D3E AA47D32F 20F2F060
0C52E9D3 787E6D35 819C636E 71761975 36169213 A65CC680 A04A1DD0 B4DDCD82
275D0203 010001A3 6D306B30 0F060355 1D130101 FF040530 030101FF 30180603
551D1104 11300F82 0D633835 312E686F 6D652E69 6E74301F 0603551D 23041830
168014DF 96008FE8 07F26511 67166488 3D32B8CE 209CC630 1D060355 1D0E0416
0414DF96 008FE807 F2651167 1664883D 32B8CE20 9CC6300D 06092A86 4886F70D
01010405 00038181 00776E03 3CADC2E6 C7A33A5D A2DF4354 00B0B845 E0217D3A
CF872568 4E8083E4 78CC3699 CC0D6AD2 8EE4CF04 0C12C8CF 35D8550F B435F165
BF0539DA 482F8A4E 28CBC413 AC708922 C67AAA25 AADBED23 79C5D923 76251B6C
A1B13310 6D3999A5 6F3BDF6C 00DAD8BC CEE9E630 52325374 FE338057 84B14925
DEA7E14B 159B17B4 EA
quit
username root privilege 15 secret 5 $1$5wEq$jv.2MCeALPgbFt04ljcQz/
!
!
!
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
description WAN
mac-address 101c.c01f.3621
ip address 10.204.247.102 255.255.252.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface Dot11Radio0
ip address 192.168.3.1 255.255.255.0
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1452
!
encryption vlan 1 mode ciphers tkip
!
encryption mode ciphers tkip
!
ssid Shakran
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 7 1521030D0F23072D2F216D74
!
speed basic-1.0 basic-2.0 basic-5.5 basic-6.0 basic-9.0 basic-11.0 basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0
station-role root
no dot11 extension aironet
no cdp enable
!
interface Vlan1
description LAN
ip address 192.168.1.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
interface Dialer0
mtu 1450
ip address 192.168.0.11 255.255.255.0
encapsulation ppp
dialer in-band
dialer idle-timeout 0
dialer string 123
dialer vpdn
dialer-group 1
no cdp enable
ppp pfc local request
ppp pfc remote apply
ppp encrypt mppe auto
ppp chap hostname root
ppp chap password 7 040B2A550B744116
!
ip classless
ip route 0.0.0.0 0.0.0.0 10.204.244.1
ip route 192.168.1.0 255.255.255.0 Vlan1
ip route 192.168.3.0 255.255.255.0 Dot11Radio0
!
ip http server
ip http authentication local
ip http secure-server
ip http secure-trustpoint CA-trust-local
ip nat inside source list NAT interface FastEthernet4 overload
!
ip access-list extended NAT
permit ip 192.168.0.0 0.0.3.255 any
!
dialer-list 1 protocol ip permit
!
control-plane
!
!
line con 0
no modem enable
line aux 0
line vty 0 4
privilege level 15
login local
transport input ssh
!
scheduler max-task-time 5000
end
[/more]
ну и еще что видно
[more]
c851#show ip interface brief
Interface IP-Address OK? Method Status Protocol
Dot11Radio0 192.168.3.1 YES NVRAM up up
FastEthernet0 unassigned YES unset up down
FastEthernet1 unassigned YES unset up up
FastEthernet2 unassigned YES unset up down
FastEthernet3 unassigned YES unset up down
FastEthernet4 10.204.247.102 YES NVRAM up up
Vlan1 192.168.1.1 YES NVRAM up up
NVI0 unassigned YES unset up up
Virtual-Dot11Radio0 192.168.3.1 YES TFTP down down
Dialer0 192.168.0.11 YES manual up up
Virtual-Access1 unassigned YES unset down down
c851#show ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route
Gateway of last resort is 10.204.244.1 to network 0.0.0.0
10.0.0.0/22 is subnetted, 1 subnets
C 10.204.244.0 is directly connected, FastEthernet4
C 192.168.0.0/24 is directly connected, Dialer0
C 192.168.1.0/24 is directly connected, Vlan1
C 192.168.3.0/24 is directly connected, Dot11Radio0
S* 0.0.0.0/0 [1/0] via 10.204.244.1
c851#ping 192.168.0.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.0.1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
[/more]
С цисками не особо много дела имел, так что подскажите в каком направлении копать