我有一台 CISCO 1941,有 2 个外部 IP 地址分配给一个接口
interface GigabitEthernet0/1
description $ETH-WAN$
ip address X.X.X.X2 255.255.255.240 secondary
ip address X.X.X.X1 255.255.255.240
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
我在主 IP 上有各种端口转换。辅助 IP 静态转换为 IP 为 192.168.19.17 的服务器。这可以正常工作几个小时,然后停止工作。发出以下解决问题:
router(config)#no ip nat inside source static 192.168.129.17 X.X.X.X2
router(config)#ip nat inside source static 192.168.129.17 X.X.X.X2
任何的想法?当它停止工作时,发出 traceroute XXXX2 在 XXXX1 停止
我的配置有问题吗(见下文)?
我该如何调试它?
router#sh run
(...)
!
interface GigabitEthernet0/0
description $ETH-LAN$
ip address 192.168.129.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
interface GigabitEthernet0/1
description $ETH-WAN$
ip address X.X.X.X2 255.255.255.240 secondary
ip address X.X.X.X1 255.255.255.240
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
!
interface Virtual-Template1 type tunnel
ip unnumbered GigabitEthernet0/1
ip mtu 1300
tunnel mode ipsec ipv4
tunnel protection ipsec profile CiscoCP_Profile1
!
ip local pool SDM_POOL_1 192.168.129.200 192.168.129.254
ip forward-protocol nd
!
ip http server
no ip http secure-server
!
ip dns server
ip nat inside source list 1 interface GigabitEthernet0/1 overload
ip nat inside source route-map SDM_RMAP_1 interface GigabitEthernet0/1 overload
ip nat inside source static tcp 192.168.129.13 500 X.X.X.X1 500 extendable
ip nat inside source static udp 192.168.129.13 500 X.X.X.X1 500 extendable
ip nat inside source static tcp 192.168.129.13 548 X.X.X.X1 548 extendable
ip nat inside source static udp 192.168.129.13 548 X.X.X.X1 548 extendable
ip nat inside source static tcp 192.168.129.13 1701 X.X.X.X1 1701 extendable
ip nat inside source static udp 192.168.129.13 1701 X.X.X.X1 1701 extendable
ip nat inside source static tcp 192.168.129.13 1723 X.X.X.X1 1723 extendable
ip nat inside source static udp 192.168.129.13 1723 X.X.X.X1 1723 extendable
ip nat inside source static tcp 192.168.129.13 3283 X.X.X.X1 3283 extendable
ip nat inside source static udp 192.168.129.13 3283 X.X.X.X1 3283 extendable
ip nat inside source static tcp 192.168.129.22 3389 X.X.X.X1 3389 extendable
ip nat inside source static tcp 192.168.129.13 4500 X.X.X.X1 4500 extendable
ip nat inside source static udp 192.168.129.13 4500 X.X.X.X1 4500 extendable
ip nat inside source static tcp 192.168.129.13 5900 X.X.X.X1 5900 extendable
ip nat inside source static udp 192.168.129.13 5900 X.X.X.X1 5900 extendable
ip nat inside source static 192.168.129.17 X.X.X.X2
ip route 0.0.0.0 0.0.0.0 X.X.X.gateway 254
ip route 172.17.0.0 255.255.0.0 192.168.129.9
!
access-list 1 permit 192.168.129.0 0.0.0.255
access-list 1 permit 46.182.204.0 0.0.0.255
access-list 100 permit ip 192.168.128.0 0.0.15.255 any
access-list 100 permit ip 172.17.0.0 0.0.0.255 any
access-list 101 remark CCP_ACL Category=4
access-list 101 remark IPSec Rule
access-list 101 permit ip 192.168.129.0 0.0.0.255 192.168.130.0 0.0.0.255
access-list 102 remark CCP_ACL Category=2
access-list 102 permit ip 192.168.129.0 0.0.0.255 any
!
!
!
!
route-map SDM_RMAP_1 permit 1
match ip address 102
!
(...)