SLIDE 21 21
Aufbau eines VPNs mit IPsec 41 Andreas Aurand
User-Einträge auf dem Radius-Server
andreas Auth-Type := Local,Password := "c", Service-Type==Framed-User,Framed-Protocol==PPP CHAP-Password = c, Service-Type = Framed-User, Framed-Protocol = PPP, Framed-IP-Address = 192.168.99.1, Framed-Routing = None, Cisco-AVPair = "lcp:interface-config#1 = ip address 192.168.99.2 255.255.255.252", Cisco-AVPair = "lcp:interface-config#2 = ppp timeout idle 120", Cisco-AVPair = "lcp:interface-config#3 = ppp ipcp dns 16.41.91.242", Cisco-AVPair = "lcp:interface-config#4 = ppp ipcp wins 16.41.91.242", Cisco-AVPair = "ip:route#1=50.104.7.0 255.255.255.0 192.168.99.1", Cisco-AVPair = "ip:inacl#1=permit ip host 192.168.99.1 host 192.168.176.1", Cisco-AVPair = "ip:inacl#2=permit ip host 192.168.99.1 host 192.168.176.2", Cisco-AVPair = "ip:inacl#3=permit ip 20.1.1.0 0.0.0.255 192.168.176.0 0.0.0.255" Marketing Auth-Type := Local,Password == c,Service-Type==Framed-User,Framed-Protocol==PPP CHAP-Password = c, Service-Type = Framed-User, Framed-Protocol = PPP, Cisco-AVPair = "lcp:interface-config#1 = ip unnumbered loopback0", Cisco-AVPair = "lcp:interface-config#2 = ppp ipcp dns 16.41.91.242", Cisco-AVPair = "lcp:interface-config#3 = ppp ipcp wins 16.41.91.242", Cisco-AVPair = "ip:addr-pool=W2K-Marketing",
- C. = "ip:inacl#1=permit tcp
192.168.100.0 0.0.0.255 host 192.168.56.7 range 3000 3030 time-range allow-sap",
- C. = "ip:inacl#2=permit tcp 192.168.100.0 0.0.0.255 any eq 8086 time-range allow-http"
Aufbau eines VPNs mit IPsec 42 Andreas Aurand
User-Einträge auf dem Radius-Server
Engineering Auth-Type := Local,Password := "c",Service-Type==Framed-User,Framed-Protocol==PPP Chap-Password = c, Service-Type = Framed-User, Framed-Protocol = PPP, Cisco-AVPair = "lcp:interface-config#1 = description -- L2TP Client Engineering --", Cisco-AVPair = "lcp:interface-config#2 = ip unnumbered loopback1", Cisco-AVPair = "ip:addr-pool=W2K-Engineering", Cisco-AVPair = "ip:inacl#1=permit ip 192.168.101.0 0.0.0.255 any", Cisco-AVPair = "ip:inacl#2=deny ip any any" Field Auth-Type := Local, Password := "c", Service-Type == Framed-User, Framed-Protocol == PPP Chap-Password = c, Service-Type = Framed-User, Framed-Protocol = PPP, Cisco-AVPair = "lcp:interface-config#1 = description -- L2TP Client Field --", Cisco-AVPair = "lcp:interface-config#2 = ip unnumbered loopback2", Cisco-AVPair = "ip:addr-pool=W2K-Field", Cisco-AVPair = "ip:inacl#1=permit tcp 192.168.102.0 0.0.0.255 host 192.168.56.7 eq telnet", Cisco-AVPair = "ip:inacl#2=deny ip any any" c3640-w2kpool Auth-Type := Local, Password := "df9434dvj", NAS-IP-Address == 16.37.176.79 Service-Type = Outbound-User, Cisco-AVPair = "ip:pool-timeout=3600", Cisco-AVPair = "ip:pool-def#1=W2K-Marketing 192.168.100.2 192.168.100.254", Cisco-AVPair = "ip:pool-def#2=W2K-Engineering 192.168.101.2 192.168.101.254", Cisco-AVPair = "ip:pool-def#3=W2K-Field 192.168.102.2 192.168.102.254"