<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Ограничение доступа по VLAN + NAT</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/23290.html</link>
    <description>Сеть поеделена на vlan, каждая сеть натится через свой пул внешних ip. Необходимо запретить трафик между vlan, и разрешить выходить в интернет. Вот конфиг&lt;br&gt;&lt;br&gt;interface FastEthernet0/0&lt;br&gt;description INTERNET&lt;br&gt;ip address 193.*.*.17 255.255.255.224&lt;br&gt;ip nat outside&lt;br&gt;ip virtual-reassembly in&lt;br&gt;duplex auto&lt;br&gt;speed auto&lt;br&gt;!&lt;br&gt;interface FastEthernet0/1&lt;br&gt;description LAN&lt;br&gt;ip virtual-reassembly in&lt;br&gt;duplex auto&lt;br&gt;speed auto&lt;br&gt;!&lt;br&gt;interface FastEthernet0/1.2&lt;br&gt;encapsulation dot1Q 2&lt;br&gt;ip address 172.16.0.1 255.255.254.0&lt;br&gt;ip nat inside&lt;br&gt;ip virtual-reassembly in&lt;br&gt;!&lt;br&gt;interface FastEthernet0/1.3&lt;br&gt;encapsulation dot1Q 3&lt;br&gt;ip address 172.16.2.1 255.255.254.0&lt;br&gt;ip nat inside&lt;br&gt;ip virtual-reassembly in&lt;br&gt;!&lt;br&gt;&lt;br&gt;!&lt;br&gt;ip nat pool first_ip 193.*.*.7 193.*.*.7 netmask 255.255.255.224&lt;br&gt;ip nat pool second_ip 193.*.*.21 193.*.*.21 netmask 255.255.255.224&lt;br&gt;ip nat inside source list 20 pool first_ip overload&lt;br&gt;ip nat inside source list 30 pool second_ip overload&lt;br&gt;ip route 0.0.0.0 0.0.0.0 193.*.*.1&lt;br&gt;!&lt;br&gt;logging esm config&lt;br&gt;access-list 20 permit 172.16.0.0 0.0.1</description>

<item>
    <title>Ограничение доступа по VLAN + NAT (wizmo)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/23290.html#2</link>
    <pubDate>Thu, 17 Nov 2011 17:48:23 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;  ip address 172.16.0.1 255.255.254.0 &lt;br&gt;&amp;gt;  ip nat inside &lt;br&gt;&amp;gt;  ip virtual-reassembly in &lt;br&gt;&amp;gt;  ip access-group first_network in &lt;br&gt;&amp;gt; interface FastEthernet0/1.3 &lt;br&gt;&amp;gt;  encapsulation dot1Q 3 &lt;br&gt;&amp;gt;  ip address 172.16.2.1 255.255.254.0 &lt;br&gt;&amp;gt;  ip nat inside &lt;br&gt;&amp;gt;  ip virtual-reassembly in &lt;br&gt;&amp;gt;  ip access-group first_network in &lt;br&gt;&lt;br&gt;Решение конечно, но не очень удобно если у меня 20 vlan&lt;br&gt;&lt;br&gt;</description>
</item>

<item>
    <title>Ограничение доступа по VLAN + NAT (Николай_kv)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/23290.html#1</link>
    <pubDate>Thu, 17 Nov 2011 12:49:07 GMT</pubDate>
    <description>&lt;br&gt;ip access-list extended first_network &lt;br&gt; deny ip 172.16.0.0 0.0.1.255 172.16.2.0 0.0.1.255&lt;br&gt; deny ip 172.16.2.0 0.0.1.255 172.16.0.0 0.0.1.255&lt;br&gt; permit ip any any&lt;br&gt;&lt;br&gt;потом вешаем на внутренний интерфейс допустим&lt;br&gt;&lt;br&gt;interface FastEthernet0/1.2 &lt;br&gt; encapsulation dot1Q 2 &lt;br&gt; ip address 172.16.0.1 255.255.254.0 &lt;br&gt; ip nat inside &lt;br&gt; ip virtual-reassembly in &lt;br&gt; ip access-group first_network in &lt;br&gt;&lt;br&gt;&lt;br&gt;interface FastEthernet0/1.3&lt;br&gt; encapsulation dot1Q 3&lt;br&gt; ip address 172.16.2.1 255.255.254.0&lt;br&gt; ip nat inside&lt;br&gt; ip virtual-reassembly in&lt;br&gt; ip access-group first_network in &lt;br&gt;</description>
</item>

</channel>
</rss>
