!
!
!
ip dhcp-server excluded-address 10.10.10.1 10.10.10.29
ip dhcp-server excluded-address 10.20.10.1 10.20.10.29
!
ip dhcp-server pool "DATA"
network 10.10.10.0 255.255.255.0
dns-server 10.10.1.12 10.10.1.14 10.10.1.16
default-router 10.10.10.1
!
ip dhcp-server pool "VOICE"
network 10.20.10.0 255.255.255.0
default-router 10.20.10.1
option 128 ip X.X.X.X
option 129 ip X.X.X.X
option 130 ascii XXXX
!
!
!
!
!
!
qos map ppp1QosWizard 20
match list aclppp1QosWizRTP20
priority 300
set dscp 26
qos map ppp1QosWizard 21
match list aclppp1QosWizSignal21
set dscp 26
!
!
!
!
vlan 1
name "Default"
!
vlan 2
name "DATA"
!
vlan 3
name "VOICE"
!
!
!
no ethernet cfm
!
!
!
!
interface switchport 0/1
no shutdown
!
interface switchport 0/2
no shutdown
!
interface switchport 0/3
no shutdown
!
interface switchport 0/4
no shutdown
!
interface switchport 0/5
no shutdown
!
interface switchport 0/6
spanning-tree edgeport
no shutdown
switchport voice vlan 3
!
interface switchport 0/7
no shutdown
!
interface switchport 0/8
no shutdown
!
!
!
interface vlan 1
description Data VLAN
ip address 10.10.10.1 255.255.255.0
no shutdown
!
interface vlan 3
description Voice VLAN
ip address 10.20.10.1 255.255.255.0
no shutdown
!
!
interface t1 1/1
description MPLS-T1
fdl none
tdm-group 1 timeslots 1-24 speed 64
no shutdown
!
interface ppp 1
ip address X.X.X.X 255.255.255.252
media-gateway ip primary
qos-policy out ppp1QosWizard
no shutdown
cross-connect 1 t1 1/1 1 ppp 1
!
!
!
!
!
!
!
ip access-list standard NATLIST
permit any
!
!
ip access-list extended aclppp1QosWizRTP20
permit ip 10.20.10.0 0.0.0.255 any
!
ip access-list extended aclppp1QosWizSignal21
permit udp any any eq 5060
permit tcp any any eq 5060
!
ip access-list extended NONAT
permit ip 10.10.10.0 0.0.0.255 10.0.0.0 0.255.255.255
!
ip access-list extended OUTSIDE_IN
permit icmp any any
permit tcp any any eq ssh
permit ip any any
!
ip access-list extended self
permit ip any any log
!
!
ip policy-class INSIDE
allow list NONAT stateless
allow list self self
nat source list NATLIST interface eth 0/1 overload
!
ip policy-class OUTSIDE
allow reverse list NONAT stateless
allow list OUTSIDE_IN
!
!
!
ip route 0.0.0.0 0.0.0.0 X.X.X.X
!
|