Имеется аггрегат C1760. Не проходят через роутер вызовы одного из sip провайдеров на астериск.
Дома на dlink роутере сделал проброс udp 5060 для этой же железки и все заработало.
Сам я кошек готовить не умею, после прочтения док пришли кое какие мысли, но ставить эксперименты на боевом рутере и в силу своей зелености не хочется.
Может подскажет кто, как пробросить, udp 5060 на конкретный локальный IP?
Вот, конфиг:
Код: Выделить всё
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname cisco-1760
!
boot-start-marker
boot system flash c1700-advipservicesk9-mz.124-8.bin
boot-end-marker
!
logging buffered 4096 warnings
enable password XXXXXXXXXXXXX
!
aaa new-model
!
!
!
aaa session-id common
!
resource policy
!
clock timezone MSK 4
ip cef
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.0.254
ip dhcp excluded-address 192.168.0.211
!
ip dhcp pool home
import all
network 192.168.0.0 255.255.255.0
dns-server 91.207.136.55 192.168.0.211
default-router 192.168.0.211
!
!
ip domain name XXXXXXXX
ip name-server A.B.C.D
ip name-server A.B.C.E
ip ssh version 2
l2tp-class l2tp
!
!
pseudowire-class l2tp
encapsulation l2tpv2
protocol l2tpv2 l2tp
ip local interface FastEthernet0/0.102
!
!
interface FastEthernet0/0
description XXXXXXXXXXXXX
no ip address
load-interval 30
speed auto
no cdp enable
!
interface FastEthernet0/0.1
encapsulation dot1Q 1 native
ip address 192.168.10.1 255.255.255.248
no cdp enable
!
interface FastEthernet0/0.102
encapsulation dot1Q 102
ip address 10.21.176.9 255.255.255.0
no ip proxy-arp
ip nat outside
ip virtual-reassembly
no cdp enable
!
interface FastEthernet0/0.1211
description Home
encapsulation dot1Q 1211
ip address 192.168.0.211 255.255.255.0
ip nat inside
ip virtual-reassembly
no cdp enable
!
interface Virtual-PPP1
description VPN
ip address negotiated
ip mtu 1400
ip nat outside
ip virtual-reassembly
ip tcp adjust-mss 1400
load-interval 30
no peer neighbor-route
no cdp enable
ppp chap hostname XXXXX
ppp chap password XXXXXXXXXXXXX
pseudowire A.B.C.G 1 pw-class l2tp
!
ip route 0.0.0.0 0.0.0.0 Virtual-PPP1 name first_route_over_vpn
ip route 10.0.0.0 255.0.0.0 10.21.176.1
ip route 10.20.245.110 255.255.255.255 10.21.176.1
ip route A.B.C.G 255.255.255.255 10.21.176.1
ip route A.B.C.F 255.255.255.224 10.21.176.1
!
ip dns server
!
no ip http server
no ip http secure-server
ip nat translation tcp-timeout 60
ip nat translation udp-timeout 600
ip nat translation max-entries 1152000
no ip nat service sip udp port 5060
ip nat inside source list 1 interface Virtual-PPP1 overload
ip nat inside source list 100 interface Virtual-PPP1 overload
ip nat inside source list 101 interface FastEthernet0/0.102 overload
ip nat inside source static tcp 192.168.0.7 22 interface Virtual-PPP1 10023
ip nat inside source static tcp 192.168.0.16 22 interface Virtual-PPP1 10022
ip nat inside source static tcp 192.168.0.228 80 interface Virtual-PPP1 1081
ip nat inside source static tcp 192.168.0.127 80 interface Virtual-PPP1 1080
!
access-list 1 permit 192.168.101.0 0.0.0.255
access-list 100 deny ip any A.B.C.E.0 0.0.1.255
access-list 100 deny ip any X.X.X.0 0.0.31.255
access-list 100 deny ip any X.X.X.0 0.0.7.255
access-list 100 deny ip any X.X.X.0 0.0.15.255
access-list 100 deny ip any X.X.X.0 0.0.7.255
access-list 100 deny ip A.B.C.0 0.0.1.255 any
access-list 100 deny ip X.X.X.0 0.0.31.255 any
access-list 100 deny ip X.X.X.0 0.0.7.255 any
access-list 100 deny ip X.X.X.0 0.0.15.255 any
access-list 100 deny ip X.X.X.0 0.0.7.255 any
access-list 100 deny ip any 10.0.0.0 0.255.255.255
access-list 100 permit ip 192.168.0.0 0.0.0.255 any
access-list 100 deny ip any any
access-list 101 permit ip 192.168.0.0 0.0.0.255 A.B.C.E.0 0.0.1.255
access-list 101 permit ip 192.168.0.0 0.0.0.255 X.X.X.0 0.0.31.255
access-list 101 permit ip 192.168.0.0 0.0.0.255 X.X.X.0 0.0.7.255
access-list 101 permit ip 192.168.0.0 0.0.0.255 X.X.X.0 0.0.15.255
access-list 101 permit ip 192.168.0.0 0.0.0.255 X.X.X.0 0.0.7.255
access-list 101 permit ip 192.168.0.0 0.0.0.255 10.0.0.0 0.255.255.255
access-list 101 deny ip any any
no cdp run
!
!
control-plane
!
!
alias exec ps show proc cpu sort | excl 0.00%__0.00%__0.00%
!
line con 0
line aux 0
line vty 0 4
transport input telnet ssh
transport output all
!
ntp clock-period 17208047
ntp server 194.87.0.28
end
A.B.C.D и A.B.C.E - name-server провайдера.
Заранее благодарю, если подскажите, что именно тупо вписать