seiyar Mada mada dane! | J'ai un cisco c827 avec le dernier IOS c820-oy6-mz.123-8.T.bin , ios 12.3(8)T
voici mon sh run
Code :
- !
- version 12.3
- no service pad
- service timestamps debug datetime msec
- service timestamps log datetime msec
- no service password-encryption
- !
- hostname Kamui
- !
- boot-start-marker
- boot-end-marker
- !
- no logging buffered
- enable secret xxxxxxxxxxxxxxxxxxxxxx
- !
- username Kamui password 0 xxxxxxxxx
- no aaa new-model
- ip subnet-zero
- no ip source-route
- ip dhcp excluded-address 10.0.0.138
- !
- ip dhcp pool CLIENT
- import all
- network 10.0.0.0 255.0.0.0
- default-router 10.0.0.138
- lease 0 2
- !
- !
- ip name-server 80.118.196.36
- ip name-server 80.118.192.100
- ip inspect name myfw cuseeme timeout 3600
- ip inspect name myfw ftp timeout 3600
- ip inspect name myfw rcmd timeout 3600
- ip inspect name myfw realaudio timeout 3600
- ip inspect name myfw smtp timeout 3600
- ip inspect name myfw tftp timeout 30
- ip inspect name myfw udp timeout 15
- ip inspect name myfw tcp timeout 3600
- ip inspect name myfw h323 timeout 3600
- !
- !
- !
- interface Ethernet0
- ip address 10.0.0.138 255.0.0.0
- no ip proxy-arp
- ip nat inside
- ip virtual-reassembly
- no ip route-cache
- hold-queue 100 out
- !
- interface ATM0
- no ip address
- atm vc-per-vp 64
- no atm ilmi-keepalive
- dsl operating-mode auto
- pvc 8/35
- encapsulation aal5mux ppp dialer
- dialer pool-member 1
- !
- !
- interface Dialer1
- ip address negotiated
- ip access-group 111 in
- ip nat outside
- ip inspect myfw out
- ip virtual-reassembly
- encapsulation ppp
- dialer pool 1
- dialer-group 1
- ppp authentication chap pap callin
- ppp chap hostname xxxxxxxxx
- ppp chap password 0 xxxxxxxx
- ppp pap sent-username xxxxxxxx password 0 xxxxx
- ppp ipcp wins request
- hold-queue 224 in
- !
- ip classless
- ip route 0.0.0.0 0.0.0.0 Dialer1
- ip http server
- ip nat translation timeout 3600
- ip nat translation tcp-timeout 3600
- ip nat translation udp-timeout 1200
- ip nat translation finrst-timeout 300
- ip nat translation syn-timeout 120
- ip nat translation dns-timeout 300
- ip nat translation icmp-timeout 120
- ip nat translation max-entries 2147483647
- ip nat inside source list 1 interface Dialer1 overload
- ip nat inside source list 102 interface Dialer1 overload
- ip nat inside source static tcp 10.0.0.1 9999 interface Dialer1 9999
- ip nat inside source static udp 10.0.0.1 10000 interface Dialer1 10000
- ip nat inside source static tcp 10.0.0.1 10002 interface Dialer1 10002
- ip nat inside source static tcp 10.0.0.1 10003 interface Dialer1 10003
- ip nat inside source static tcp 10.0.0.1 25000 interface Dialer1 25000
- ip nat inside source static tcp 10.0.0.1 25001 interface Dialer1 25001
- ip nat inside source static tcp 10.0.0.1 25002 interface Dialer1 25002
- ip nat inside source static tcp 10.0.0.1 25003 interface Dialer1 25003
- !
- access-list 102 remark Flux sortant
- access-list 102 permit ip 10.0.0.0 0.255.255.255 any
- access-list 102 deny udp any any eq netbios-ns
- access-list 102 deny udp any any eq netbios-dgm
- access-list 102 deny udp any any eq netbios-ss
- access-list 102 deny tcp any any eq 135
- access-list 102 deny udp any any eq 135
- access-list 102 deny tcp any any eq 139
- access-list 111 deny ip 10.0.0.0 0.255.255.255 any
- access-list 111 deny ip 172.0.0.0 0.240.255.255 any
- access-list 111 deny ip 192.168.0.0 0.0.255.255 any
- access-list 111 deny ip 127.0.0.0 0.255.255.255 any
- access-list 111 deny ip 255.0.0.0 0.255.255.255 any
- access-list 111 deny ip 224.0.0.0 7.255.255.255 any
- access-list 111 permit tcp any any eq 25000
- access-list 111 permit tcp any any eq 25001
- access-list 111 permit tcp any any eq 25002
- access-list 111 permit tcp any any eq 25003
- access-list 111 permit tcp any any eq 10003
- access-list 111 permit tcp any any eq 10002
- access-list 111 permit udp any any eq 10000
- access-list 111 permit tcp any any eq 9999
- dialer-list 1 protocol ip permit
- !
- control-plane
- !
- banner motd
- ===Welcome On Kamui Cisco Router!!!====
- $, $, ,
- "ss.$ss. .s'
- , .ss$$$$$$$$$$s,
- $. s$$$$$$$$$$$$$$`$$Ss
- "$$$$$$$$$$$$$$$$$$o$$$ ,
- s$$$$$$$$$$$$$$$$$$$$$$$$s, ,s
- s$$$$$$$$$"$$$$$$""""$$$$$$"$$$$$,
- s$$$$$$$$$$s""$$$$ssssss"$$$$$$$$"
- s$$$$$$$$$$' `"""ss"$"$s""
- s$$$$$$$$$$, `"""""$ .s$$s
- s$$$$$$$$$$$$s,... `s$$' `
- `ssss$$$$$$$$$$$$$$$$$$$$####s. .$$"$. , s-
- `""""$$$$$$$$$$$$$$$$$$$$#####$$$$$$" $.$'
- "$$$$$$$$$$$$$$$$$$$$$####s"" .$$$|
- "$$$$$$$$$$$$$$$$$$$$$$$$##s .$$" $
- $$""$$$$$$$$$$$$$$$$$$$$$$$$$$$$$" `
- $$" "$"$$$$$$$$$$$$$$$$$$$$S""""'
- , ," ' $$$$$$$$$$$$$$$$####s
- $. .s$$$$$$$$$$$$$$$$$####"
- , "$s. ..ssS$$$$$$$$$$$$$$$$$$$####"
- $ .$$$S$$$$$$$$$$$$$$$$$$$$$$$$#####"
- Ss ..sS$$$$$$$$$$$$$$$$$$$$$$$$$$$######""
- "$$sS$$$$$$$$$$$$$$$$$$$$$$$$$$$########"
- , s$$$$$$$$$$$$$$$$$$$$$$$$#########""'
- $ s$$$$$$$$$$$$$$$$$$$$$#######""' s' ,
- $$..$$$$$$$$$$$$$$$$$$######"' ....,$$.... ,$
- "$$$$$$$$$$$$$$$######"' , .sS$$$$$$$$$$$$$$$$s$$
- $$$$$$$$$$$$#####" $, .s$$$$$$$$$$$$$$$$$$$$$$$$s.
- ) $$$$$$$$$$$#####' `$$$$$$$$$###########$$$$$$$$$$$.
- (( $$$$$$$$$$$##### $$$$$$$$###" "####$$$$$$$$$$
- ) \ $$$$$$$$$$$$####. $$$$$$###" "###$$$$$$$$$ s'
- ( ) $$$$$$$$$$$$$####. $$$$$###" ####$$$$$$$$s$$'
- ) ( ( $$"$$$$$$$$$$$#####.$$$$$###' .###$$$$$$$$$$"
- ( ) ) _,$" $$$$$$$$$$$$######.$$##' .###$$$$$$$$$$
- ) ( ( \. "$$$$$$$$$$$$$#######,,,. ..####$$$$$$$$$$$"
- ( )$ ) ) ,$$$$$$$$$$$$$$$$$$####################$$$$$$$$$$$"
- ( ($$ ( \ _sS" `"$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$S$$,
- ) )$$$s ) ) . . `$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$"' `$$
- ( $$$Ss/ .$, .$,,s$$$$$$##S$$$$$$$$$$$$$$$$$$$$$$$$S"" '
- \)_$$$$$$$$$$$$$$$$$$$$$$$##" $$ `$$. `$$.
- `"S$$$$$$$$$$$$$$$$$#" $ `$ `$
- `"""""""""""""' ' ' '
- ===Welcome On Kamui Cisco Router====
- !
- line con 0
- transport preferred all
- transport output all
- line vty 0 4
- exec-timeout 120 0
- password xxxxxxxxx
- login local
- length 0
- transport preferred all
- transport input all
- transport output all
- !
- scheduler max-task-time 5000
- end
|
si quelqu'un pouvais améliorer mes ACL sa serait sympas , de tels sorte que je puisse pinger vers le WAN , et interdire le WAN de pinguer mon routeur , je passe tous les tests de sécurité , grc,pc flank mise à part celui ci , sygate udp scan , si vous pouviez me régler çà sa serais sympas http://scan.sygatetech.com/preudpscan.html
merci @+++ Message édité par seiyar le 06-06-2004 à 19:13:24
|