[more]
sw3560#sh run
Building configuration...
Current configuration : 7950 bytes
!
! Last configuration change at 05:32:12 UA Tue Jul 19 2016 by crysmas
! NVRAM config last updated at 07:32:43 UA Thu Jul 14 2016 by crysmas
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname sw3560
!
boot-start-marker
boot-end-marker
!
enable secret 5 *******
!
username **** privilege 15 password 7 ******
!
!
aaa new-model
!
!
aaa authentication login default local
aaa authentication enable default enable
!
!
!
aaa session-id common
clock timezone UA 1
system mtu routing 1500
ip routing
!
!
ip domain-name ****
ip name-server ****
ip name-server ****
ip name-server 8.8.8.8
vtp mode transparent
!
!
crypto pki trustpoint TP-self-signed-2188878592
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2188878592
revocation-check none
rsakeypair TP-self-signed-218878592
!
!
crypto pki certificate chain TP-self-signed-2188878592
certificate self-signed 01
spanning-tree mode pvst
spanning-tree extend system-id
!
!
!
!
vlan internal allocation policy ascending
!
vlan 10
name NEW
!
vlan 11
name PC
!
vlan 17
name IP-Tel
!
vlan 192
name ST
!
vlan 240
!
vlan 1570
!
ip ssh version 2
!
!
interface FastEthernet0
no ip address
no ip route-cache cef
no ip route-cache
no ip mroute-cache
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
description trunk to 2921
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 10,16,17,20,30,40,50,60,70,80-82,90,100,110,192
switchport trunk allowed vlan add 1570
switchport mode trunk
!
interface GigabitEthernet0/3
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/4
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/5
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/6
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/7
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/8
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/9
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/10
!
interface GigabitEthernet0/11
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/12
!
interface GigabitEthernet0/13
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/14
!
interface GigabitEthernet0/15
description Asterisk
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/16
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/17
!
interface GigabitEthernet0/18
switchport access vlan 17
switchport mode access
!
interface GigabitEthernet0/19
switchport access vlan 17
switchport mode access
!
interface GigabitEthernet0/20
!
interface GigabitEthernet0/21
!
interface GigabitEthernet0/22
!
interface GigabitEthernet0/23
switchport access vlan 192
switchport mode access
!
interface GigabitEthernet0/24
!
interface GigabitEthernet0/25
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/26
!
interface GigabitEthernet0/27
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/28
switchport access vlan 17
switchport mode access
!
interface GigabitEthernet0/29
!
interface GigabitEthernet0/30
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/31
!
interface GigabitEthernet0/32
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/33
!
interface GigabitEthernet0/34
!
interface GigabitEthernet0/35
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/36
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/37
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/38
!
interface GigabitEthernet0/39
switchport access vlan 10
!
interface GigabitEthernet0/40
!
interface GigabitEthernet0/41
!
interface GigabitEthernet0/42
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/43
!
interface GigabitEthernet0/44
switchport access vlan 16
switchport mode access
!
interface GigabitEthernet0/45
!
interface GigabitEthernet0/46
no switchport
no ip address
!
interface GigabitEthernet0/47
no switchport
no ip address
!
interface GigabitEthernet0/48
switchport access vlan 192
switchport mode access
!
interface GigabitEthernet1/1
!
interface GigabitEthernet1/2
!
interface GigabitEthernet1/3
!
interface GigabitEthernet1/4
!
interface TenGigabitEthernet1/1
!
interface TenGigabitEthernet1/2
!
interface Vlan1
no ip address
!
interface Vlan10
ip address 10.2.10.1 255.255.255.0
!
interface Vlan11
description LAN_
ip address 10.2.12.1 255.255.252.0
ip helper-address 10.2.10.3
ip helper-address 10.2.10.4
!
interface Vlan17
description IP-tel
ip address 10.2.17.1 255.255.252.0
ip helper-address 10.2.10.3
ip helper-address 10.2.10.4
!
interface Vlan192
description LAN_ST
ip address 192.168.1.27 255.255.248.0
!
interface Vlan1570
ip address 10.2.11.10 255.255.255.0
!
!
router eigrp 30
network 10.2.0.0 0.0.255.255
network 10.2.10.0 0.0.0.255
network 10.2.12.0 0.0.0.255
network 10.2.16.0 0.0.3.255
network 10.2.20.0 0.0.0.255
network 10.2.30.0 0.0.0.255
network 10.2.40.0 0.0.0.255
network 10.2.50.0 0.0.0.255
network 10.2.60.0 0.0.0.255
network 10.2.70.0 0.0.0.255
network 10.2.80.0 0.0.0.255
network 10.2.81.0 0.0.0.255
network 10.2.90.0 0.0.0.255
network 10.2.100.0 0.0.0.255
network 10.2.120.0 0.0.0.255
network 10.10.1.0 0.0.0.255
network ****.0 0.0.0.3
network 192.168.0.0 0.0.7.255
network 192.170.1.0 0.0.0.3
eigrp stub connected summary
!
ip default-gateway 10.2.10.15
ip classless
ip route 0.0.0.0 0.0.0.0 10.2.10.15
ip route 192.168.25.0 255.255.255.0 192.168.1.254
no ip http server
no ip http secure-server
!
access-list 10 permit 192.168.1.14
access-list 10 permit 192.168.1.0 log
access-list 10 permit 192.168.5.130
no cdp run
snmp-server community RW RO 5
snmp-server community RO RO
snmp-server community private RW
snmp-server community *** RO
snmp-server location ****
snmp-server host 192.168.5.130 RO
snmp-server host 192.168.5.130 RW
snmp-server host 192.168.5.130 ****
!
!
line con 0
password 7 ***************
line vty 5 14
line vty 15
password 7 **********
!
ntp clock-period 36027919
ntp server 10.2.10.2 (циска 2921)
end
[/more]
конфиг 3560, маршрутизатор, у меня связка идет так: 2921 - 3560 по канулу бегает только трафик сетевой без ната, с 2921 - ТМЖ - 3560 - НАТ бегает но на ТМЖ добавил правило разрешить все всем.
sw3560#sh run
Building configuration...
Current configuration : 7950 bytes
!
! Last configuration change at 05:32:12 UA Tue Jul 19 2016 by crysmas
! NVRAM config last updated at 07:32:43 UA Thu Jul 14 2016 by crysmas
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname sw3560
!
boot-start-marker
boot-end-marker
!
enable secret 5 *******
!
username **** privilege 15 password 7 ******
!
!
aaa new-model
!
!
aaa authentication login default local
aaa authentication enable default enable
!
!
!
aaa session-id common
clock timezone UA 1
system mtu routing 1500
ip routing
!
!
ip domain-name ****
ip name-server ****
ip name-server ****
ip name-server 8.8.8.8
vtp mode transparent
!
!
crypto pki trustpoint TP-self-signed-2188878592
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2188878592
revocation-check none
rsakeypair TP-self-signed-218878592
!
!
crypto pki certificate chain TP-self-signed-2188878592
certificate self-signed 01
spanning-tree mode pvst
spanning-tree extend system-id
!
!
!
!
vlan internal allocation policy ascending
!
vlan 10
name NEW
!
vlan 11
name PC
!
vlan 17
name IP-Tel
!
vlan 192
name ST
!
vlan 240
!
vlan 1570
!
ip ssh version 2
!
!
interface FastEthernet0
no ip address
no ip route-cache cef
no ip route-cache
no ip mroute-cache
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
description trunk to 2921
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 10,16,17,20,30,40,50,60,70,80-82,90,100,110,192
switchport trunk allowed vlan add 1570
switchport mode trunk
!
interface GigabitEthernet0/3
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/4
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/5
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/6
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/7
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/8
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/9
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/10
!
interface GigabitEthernet0/11
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/12
!
interface GigabitEthernet0/13
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/14
!
interface GigabitEthernet0/15
description Asterisk
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/16
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/17
!
interface GigabitEthernet0/18
switchport access vlan 17
switchport mode access
!
interface GigabitEthernet0/19
switchport access vlan 17
switchport mode access
!
interface GigabitEthernet0/20
!
interface GigabitEthernet0/21
!
interface GigabitEthernet0/22
!
interface GigabitEthernet0/23
switchport access vlan 192
switchport mode access
!
interface GigabitEthernet0/24
!
interface GigabitEthernet0/25
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/26
!
interface GigabitEthernet0/27
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/28
switchport access vlan 17
switchport mode access
!
interface GigabitEthernet0/29
!
interface GigabitEthernet0/30
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/31
!
interface GigabitEthernet0/32
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/33
!
interface GigabitEthernet0/34
!
interface GigabitEthernet0/35
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/36
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/37
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/38
!
interface GigabitEthernet0/39
switchport access vlan 10
!
interface GigabitEthernet0/40
!
interface GigabitEthernet0/41
!
interface GigabitEthernet0/42
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/43
!
interface GigabitEthernet0/44
switchport access vlan 16
switchport mode access
!
interface GigabitEthernet0/45
!
interface GigabitEthernet0/46
no switchport
no ip address
!
interface GigabitEthernet0/47
no switchport
no ip address
!
interface GigabitEthernet0/48
switchport access vlan 192
switchport mode access
!
interface GigabitEthernet1/1
!
interface GigabitEthernet1/2
!
interface GigabitEthernet1/3
!
interface GigabitEthernet1/4
!
interface TenGigabitEthernet1/1
!
interface TenGigabitEthernet1/2
!
interface Vlan1
no ip address
!
interface Vlan10
ip address 10.2.10.1 255.255.255.0
!
interface Vlan11
description LAN_
ip address 10.2.12.1 255.255.252.0
ip helper-address 10.2.10.3
ip helper-address 10.2.10.4
!
interface Vlan17
description IP-tel
ip address 10.2.17.1 255.255.252.0
ip helper-address 10.2.10.3
ip helper-address 10.2.10.4
!
interface Vlan192
description LAN_ST
ip address 192.168.1.27 255.255.248.0
!
interface Vlan1570
ip address 10.2.11.10 255.255.255.0
!
!
router eigrp 30
network 10.2.0.0 0.0.255.255
network 10.2.10.0 0.0.0.255
network 10.2.12.0 0.0.0.255
network 10.2.16.0 0.0.3.255
network 10.2.20.0 0.0.0.255
network 10.2.30.0 0.0.0.255
network 10.2.40.0 0.0.0.255
network 10.2.50.0 0.0.0.255
network 10.2.60.0 0.0.0.255
network 10.2.70.0 0.0.0.255
network 10.2.80.0 0.0.0.255
network 10.2.81.0 0.0.0.255
network 10.2.90.0 0.0.0.255
network 10.2.100.0 0.0.0.255
network 10.2.120.0 0.0.0.255
network 10.10.1.0 0.0.0.255
network ****.0 0.0.0.3
network 192.168.0.0 0.0.7.255
network 192.170.1.0 0.0.0.3
eigrp stub connected summary
!
ip default-gateway 10.2.10.15
ip classless
ip route 0.0.0.0 0.0.0.0 10.2.10.15
ip route 192.168.25.0 255.255.255.0 192.168.1.254
no ip http server
no ip http secure-server
!
access-list 10 permit 192.168.1.14
access-list 10 permit 192.168.1.0 log
access-list 10 permit 192.168.5.130
no cdp run
snmp-server community RW RO 5
snmp-server community RO RO
snmp-server community private RW
snmp-server community *** RO
snmp-server location ****
snmp-server host 192.168.5.130 RO
snmp-server host 192.168.5.130 RW
snmp-server host 192.168.5.130 ****
!
!
line con 0
password 7 ***************
line vty 5 14
line vty 15
password 7 **********
!
ntp clock-period 36027919
ntp server 10.2.10.2 (циска 2921)
end
[/more]
конфиг 3560, маршрутизатор, у меня связка идет так: 2921 - 3560 по канулу бегает только трафик сетевой без ната, с 2921 - ТМЖ - 3560 - НАТ бегает но на ТМЖ добавил правило разрешить все всем.