Vous êtes sur la page 1sur 5

;jamesiswizard_1

client fe80:0:0:0:0:0:10.66.16.0 255.255.248.0


# /sbin/ip -6 route add 2000::/3 via 2001:0db8:0:f101::1
# /sbin/route -A inet6 add 2000::/3 gw 2001:0db8:0:f101::1
# /sbin/ip -6 route add 2000::/3 dev eth0 metric 1
# /sbin/route -A inet6 add 2000::/3 dev eth0
dev tun-vpn-tls
ifconfig 10.31.113.194 255.255.248.0
tun-mtu 1500
tun-mtu-extra 32
float
setenv FORWARD_COMPATIBLE 1
client
remote 68.68.108.221 666
proto udp
mssfix 1450
sndbuf 100000
rcvbuf 100000
dhcp-option DISABLE-NBT
resolv-retry infinite
verb 1
bind
setenv PUSH_PEER_INFO
inactive 50000000 50000
hand-window 120
dev tun
route-method exe
route-delay 5
remote-random
pull
persist-key
persist-tun
persist-local-ip
persist-remote-ip
auth-retry nointeract
mute 20
auth-user-pass
auth-nocache
reneg-sec 0
hand-window 120
mute replay warnings
interface Tunnel10
ip vrf forwarding Staff
ip address 10.254.254.23 255.255.255.0
no ip redirects
ip mtu 1416
ip nhrp authentication MFS
ip nhrp map multicast 172.16.1.1
ip nhrp map 10.254.254.1 172.16.1.1
ip nhrp map 10.254.254.3 172.16.1.3
ip nhrp map multicast 172.16.1.3
ip nhrp network-id 10
ip nhrp holdtime 600
ip nhrp nhs 10.254.254.1
ip nhrp nhs 10.254.254.3
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 10
!

interface Tunnel20
ip vrf forwarding Clients
ip address 10.254.253.23 255.255.255.0
no ip redirects
ip mtu 1416
ip nhrp authentication MFSC
ip nhrp map 10.254.253.1 172.16.1.1
ip nhrp map multicast 172.16.1.1
ip nhrp map multicast 172.16.1.3
ip nhrp map 10.254.253.3 172.16.1.3
ip nhrp network-id 20
ip nhrp holdtime 600
ip nhrp nhs 10.254.253.1
ip nhrp nhs 10.254.253.3
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 20
!
interface Tunnel10
ip vrf forwarding Staff
ip address 10.254.254.1 255.255.255.0
no ip redirects
ip mtu 1416
ip nhrp authentication MFS
ip nhrp map multicast dynamic
ip nhrp network-id 10
ip nhrp holdtime 360
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 10
!
interface Tunnel20
ip vrf forwarding Clients
ip address 10.254.253.1 255.255.255.0
no ip redirects
ip mtu 1416
ip nhrp authentication MFSC
ip nhrp map multicast dynamic
ip nhrp network-id 20
ip nhrp holdtime 360
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 20
!
interface Tunnel10
ip vrf forwarding Staff
ip address 10.254.254.3 255.255.255.0
no ip redirects
ip mtu 1416
ip nhrp authentication MFS
ip nhrp map multicast dynamic
ip nhrp network-id 10
ip nhrp holdtime 360
ip nhrp server-only
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint

tunnel key 10
remote 68.68.108.51 80,10,443,1274
!
interface Tunnel20
ip vrf forwarding Clients
ip address 10.254.253.3 255.255.255.0
no ip redirects
ip mtu 1416
ip nhrp authentication MFSC
ip nhrp map multicast dynamic
ip nhrp network-id 20
ip nhrp holdtime 360
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0 tunnel mode gre multipoint
tunnel key 20
!
interface Tunnel1
description BRANCH GRE TUNNEL
ip address 10.10.10.10 255.255.255.0
no ip redirects
ip mtu 1400
ip nhrp authentication dmvpn
ip nhrp map multicast dynamic
ip nhrp map 10.10.10.1 74.95.xxx.xxx
ip nhrp map multicast 74.95.xxx.xxx
ip nhrp network-id 99
ip nhrp holdtime 360
ip nhrp nhs 10.10.10.1
ip nhrp server-only
ip tcp adjust-mss 1360
no ip mroute-cache
delay 1000
qos pre-classify
tunnel source FastEthernet4
tunnel mode gre multipoint
tunnel key 100099
tunnel protection ipsec profile dmvpnprof
interface FastEthernet0
switchport access vlan 192
!
interface FastEthernet1
switchport access vlan 192
!
interface FastEthernet2
switchport access vlan 192
!
interface FastEthernet3
switchport access vlan 192
!
interface FastEthernet4
desc WAN
ip dhcp client lease 365 0 0
ip address dhcp
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
interface Vlan192
ip address 192.168.100.254 255.255.255.0
ip nat inside

ip virtual-reassembly
ip nat pool JT 98.201.157.44 98.201.157.44 netmask 255.255.255.248
ip nat inside source route-map nonat interface FastEthernet4 overload
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 172.168.0.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.50.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.60.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.70.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.80.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.90.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.100.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.110.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.120.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 192.168.130.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 10.1.0.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 10.2.0.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 10.3.0.0 0.0.0.255
access-list 114 deny ip 192.168.100.0 0.0.0.255 10.4.0.0 0.0.0.255
access-list 114 permit ip 192.168.100.0 0.0.0.255 any
remote 68.68.108.51 80,443,1723
lport 53,3124,3127,3128,9201,8755,8080,9201,80,8091,8081
push dhcp-option DNS 2002:0:0:0:0:0:208.67.222.222
push dhcp-option DNS 2002:0:0:0:0:0:208.67.220.220
push dhcp-option DNS 2002:0:0:0:0:0:808:808
push dhcp-option DNS 2002:0:0:0:0:0:808:404
route fe80::a1f:0 2002::ffff:0 vpn_gateway
route fe80:0:0:0:0:0:a73:0 2002:0:0:0:0:0:ffff:0 vpn_gateway
route fe80:0:0:0:0:0:a28:0 2002:0:0:0:0:0:ffff:0 vpn_gateway
route fe80:0:0:0:0:0:a50:0 2002:0:0:0:0:0:ffff:0 vpn_gateway
route fe80::a29:0 2002:0:0:0:0:0:255.255.0.0 vpn_gateway
route add -inet6 default fe80:0:0:0:0:0:192.168.167.2
!
lport 666
route-map nonat permit 10
match ip address 114
router eigrp 10
network 10.10.10.0 0.0.0.255
network 192.168.100.0
no auto-summary
!
<ca>
-----BEGIN CERTIFICATE----MIIDbzCCAtigAwIBAgIJANGtJdZolHNaMA0GCSqGSIb3DQEBBA UAMIGCMQswCQYD
VQQGEwJVUzELMAkGA1UECBMCSUwxETAPBgNVBAcTCFZpcmdpbm lhMRMwEQYDVQQK
EwpOZWJvIEdyb3VwMRYwFAYDVQQDEw1OZWJvIEdyb3VwIENBMS YwJAYJKoZIhvcN
AQkBFhdpbmZvQG1ldHJvZnJlZWZpdnBuLmNvbTAeFw0wNjAyMj IyMDI1MzhaFw0x
NjAyMjAyMDI1MzhaMIGCMQswCQYDVQQGEwJVUzELMAkGA1UECB MCSUwxETAPBgNV
BAcTCFZpcmdpbmlhMRMwEQYDVQQKEwpOZWJvIEdyb3VwMRYwFA YDVQQDEw1OZWJv
IEdyb3VwIENBMSYwJAYJKoZIhvcNAQkBFhdpbmZvQG1ldHJvZn JlZWZpdnBuLmNv
bTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAvEDRxUrh+X R+KyATvCpjE1MY
dYr/718wrJivyCIccVN1ILPjL0kXnuzF7v/hpglsE1ZhxwUgNLg3W0OIqHH/yDtO
qDowqMaxpWGF0Ws9g+qLDnX8NiGB4UOietzmE1xkH1riyrOR2/gYZa5RNGiifMNw
kdWDQrWajdqqE1z0vIsCAwEAAaOB6jCB5zAdBgNVHQ4EFgQUdd GJ7gvOx2UcrTNp
jOp1DugqnnEwgbcGA1UdIwSBrzCBrIAUddGJ7gvOx2UcrTNpjO p1DugqnnGhgYik
gYUwgYIxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJJTDERMA8GA1 UEBxMIVmlyZ2lu
aWExEzARBgNVBAoTCk5lYm8gR3JvdXAxFjAUBgNVBAMTDU5lYm 8gR3JvdXAgQ0Ex
JjAkBgkqhkiG9w0BCQEWF2luZm9AbWV0cm9mcmVlZml2cG4uY2 9tggkA0a0l1miU

c1owDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQASnHV5ii2huXzyg6mb
zVspSvKB0lA0GOOngpXtdhdxOCy0O7rXWZCIq9UnXk5ycEOIAD wSzcZtueMgAfuq
GunYCNo9ibzXsITi2btXLNpKj7t+xex8TllpxVgmVTLBw6CWDk z3TjpXe2pQ/E+w
dSWrBl+3U0ARcDGmiu1gLwgFTA==
-----END CERTIFICATE----</ca>

Vous aimerez peut-être aussi