顯示具有 Cisco 標籤的文章。 顯示所有文章
顯示具有 Cisco 標籤的文章。 顯示所有文章

2011年5月14日 星期六

HSRP Config

RA#
interface Ethernet0
ip address 171.16.6.5 255.255.255.0
standby 1 ip 171.16.6.100
standby 1 priority 105  (Priority 值大,Active)
standby 1 preempt (int 0 down-> up,搶回 Active)
standby 1 track Serial0  (int down => Priority -10 => standby)

RB#
interface Ethernet0
ip address 171.16.6.6 255.255.255.0
standby 1 ip 171.16.6.100 (可不設,自動學習)
standby 1 preempt
standby 1 track Serial1

2011年3月23日 星期三

POE 802.3at 802.3af 標準,AP1131AG AP1142N Power 需求

802.3at (PoE+) (up to 30W per port)

802.3af (up to 15.4W per port)

http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps6406/product_data_sheet0900aecd80322c0c.html

=============
WS-C2960-24PC-L

AP1131#sh power inline f0/1
Interface Admin  Oper       Power       Device                    Class Max
                                        (Watts)                           
--------- ------ ---------- ------- ------------------- ----- ----
Fa0/1     auto   on               12.2    AIR-LAP1131AG-T-K9  3     15.4
Interface  AdminPowerMax   AdminConsumption   
                      (Watts)                    (Watts)          
---------- --------------- -------------------- 
Fa0/1                 15.4                      15.4

=============
WS-C3560G-24PS-S

AP1142N#sh power inline g0/1
Interface Admin  Oper       Power        Device                Class Max
                                        (Watts)
--------- ------ ---------- ------- ------------------- ----- ----
Gi0/1     auto   on               15.4    AIR-LAP1142N-T-K9   3     15.4
Interface  AdminPowerMax   AdminConsumption
                      (Watts)                     (Watts)
---------- --------------- --------------------
Gi0/1                 15.4                 15.4

=============

2011年3月14日 星期一

ASA 8.3 SSLVPN / IPSEC VPN Config

一、 vpnclient access inside ,no nat (nat 0)

object-group network NETWORK_OBJ_10.1.10.0_26  (vpnclient_net)
 network-object 10.1.10.0 255.255.255.0

object-group network DM_INLINE_NETWORK    (inside_net)
 network-object object 192.168.0.0 255.255.0.0
 network-object object 10.0.0.0 255.0.0.0

nat (inside,outside) source static DM_INLINE_NETWORK DM_INLINE_NETWORK destination static NETWORK_OBJ_10.1.10.0_26 NETWORK_OBJ_10.1.10.0_26

VPN-SSL# sh nat
Manual NAT Policies (Section 1)
1 (inside) to (outside) source static DM_INLINE_NETWORK DM_INLINE_NETWORK destination static NETWORK_OBJ_10.1.10.0_26 NETWORK_OBJ_10.1.10.0_26
    translate_hits = 3, untranslate_hits = 15

VPN-SSL# sh xl
1 in use, 155 most used
Flags: D - DNS, i - dynamic, r - portmap, s - static, I - identity, T - twice
NAT from inside:192.168.0.0/16, 10.0.0.0/8 to outside:192.168.0.0/16,
    10.0.0.0/8
    flags sI idle 0:00:08 timeout 0:00:00



二、SplitTunnel

splitTunnel, ipsec vpn 建立連線後,依然可以上 internet

建立  ACL
access-list lab_splitTunnelAcl standard permit 10.0.0.0 255.0.0.0
access-list lab_splitTunnelAcl standard permit 192.168.0.0 255.255.0.0

套用在 group-policy 上

group-policy lab attributes
 dns-server value 10.1.1.1
 vpn-tunnel-protocol IPSec
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value lab_splitTunnelAcl