interface FastEthernet0/1
description $ES_LAN$$ETH-LAN$$FW_INSIDE$
ip address 192.168.1.8 255.255.255.0 secondary
ip address 192.168.2.8 255.255.255.0 secondary
ip address 10.20.20.1 255.255.255.0
ip access-group 100 in
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip route-cache flow
duplex auto
speed auto
no mop enabled
!
interface Serial0/0/0
description External - T1$FW_OUTSIDE$$ES_WAN$
ip address XXX.XX.XX.81 255.255.255.248 secondary
ip address XXX.XX.XX.82 255.255.255.248 secondary
ip address XXX.XX.XX.83 255.255.255.248 secondary
ip address XXX.XX.XX.84 255.255.255.248 secondary
ip address XXX.XX.XX.85 255.255.255.248 secondary
ip address XXX.XX.XX.78 255.255.255.248
ip access-group 101 in
ip nat outside
ip virtual-reassembly
encapsulation ppp
crypto map CMAP
!
ip local pool vpn1 192.168.3.1 192.168.3.254
ip classless
ip route 0.0.0.0 0.0.0.0 Serial0/0/0
!
!
no ip http server
no ip http secure-server
ip nat inside source list 106 interface Serial0/0/0 overload
ip nat inside source static 10.20.20.48 XXX.XX.XX.81
ip nat inside source static 10.20.20.49 XXX.XX.XX.82
ip nat inside source static 10.20.20.52 XXX.XX.XX.83
ip nat inside source static 10.20.20.50 XXX.XX.XX.84
!
(access-lists not shown except the nat acl)
access-list 106 remark ----==== Serial0/0/0 NAT ACL ====----
access-list 106 deny ip 10.20.20.0 0.0.0.255 192.168.3.0 0.0.0.255
access-list 106 permit ip 10.20.20.0 0.0.0.255 any
|