R1 --------- R2 -------- R3
|
R1 的fa 0/0 IP为 172.16.1.1
真实计算机连在了R1的fa0/0上 IP为172.16.1.2
R1上有一个lo 0 回环接口 地址为 192.168.1.1
在R1上做了个NAT将lo 0的地址转换成R1去往R2的出口的那个网段的IP 如下
!
ip nat inside source list 100 interface Serial1/1 overload
!
access-list 100 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 permit ip any any
!
R3上面也有一个回环接口lo0 IP为192.168.2.0
同样也做了NAT 将lo0转换成去往R2的那个接口的IP(至于那个阻止回环接口到回环接口是用作VPN用的)
ip nat inside source list 100 interface Serial1/0 overload
!
logging alarm informational
access-list 100 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 100 permit ip any any
!
在R1 R2 R3上面都配置的静态路由 并且R3也配置了ip http server和密码本地验证
真实计算机可以ping通R3但是使用SDM 确连接不上R3
如果将真实计算机直接连接到R3上面 可以用SDM来管理
我发现问题好像出在R3的那个NAT上面,我取消R3的NAT
no ip nat inside source list 100 interface Serial1/0 overload
之后就可以从真实计算机上SDM到R3了
R1配置如下:
----------------------------
!
interface Loopback0
ip address 192.168.1.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
interface FastEthernet0/0
ip address 172.16.1.1 255.255.255.0
duplex auto
speed auto
!
interface Serial1/1
ip address 12.1.1.1 255.255.255.0
ip nat outside
ip virtual-reassembly
serial restart-delay 0
!
ip http server
no ip http secure-server
!
!
ip nat inside source list 100 interface Serial1/1 overload
!
access-list 100 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 permit ip any any
!
-----------------------------------
R2配置如下:
------------------
!
!
username test privilege 15 secret 5 $2$Nph2$JQFvgkst31RiYWegOdY6u.
!
!
!
interface Loopback0
ip address 192.168.2.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
interface Serial1/0
ip address 12.1.1.2 255.255.255.0
ip nat outside
ip virtual-reassembly
serial restart-delay 0
!
ip route 172.16.1.0 255.255.255.0 12.1.1.1
ip http server
ip http authentication local
no ip http secure-server
!
!
ip nat inside source list 100 interface Serial1/0 overload
!
logging alarm informational
access-list 100 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 100 permit ip any any
!
!
PC配置:
C:\Documents and Settings\Administrator>ping 12.1.1.2