Manuel d'utilisation / d'entretien du produit 520 series du fabricant Cisco Systems
Aller à la page of 162
Americas Headquarters Cisco Systems, In c. 170 West Tasman Drive San Jose, CA 951 34-1706 USA http://www.ci sco.com Tel: 408 526-4000 800 553-NETS (638 7) Fax: 408 527-0883 Cisco S ecure Router 520 S .
THE SPECIFICATION S AND INFORMATION RE GARDING THE PR ODUCTS IN THIS MA NUAL ARE SUBJECT T O CHANGE WITHOUT NOTICE. ALL STATEMENTS , INFORMATION, AND RECOMMENDATI ONS IN THI S MANUAL ARE BE LIEVED TO BE A CCURATE BUT ARE PRESENTED WI THOUT WARRANTY OF ANY KIND, EX PRESS OR IMPLIED.
iii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 CONTENTS Preface ix Objective ix Audience ix Organization x Conventi ons xi Related Documentation xvi Obtaining Documentatio.
Contents iv Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 PART 2 Configuring Your Router for Ethernet and DSL Access CHAPTER 2 Sample Network Deployments 2-1 CHAPTER 3 Config.
Contents v Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Apply the Crypto Map to the Physic al Interface 6-8 Create an Easy VPN Remote Configuratio n 6-9 Verifying Your Easy .
Contents vi Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Guidelines for Creating Access Groups 11-3 Configuring a CBAC Firewall 11-3 Configuring Cisco IOS Firewall IDS 11-4 .
Contents vii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Saving Configuration Changes A-6 Summary A-7 Where to Go Next A-7 APPENDIX B Concepts B-1 ADSL B-1 Network Protocol.
Contents viii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Optional Variables C-4 Using the TFTP Download Command C-5 Configuration Register C-5 Changing th e Configurat ion.
ix Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface This preface describes the objectiv es, audience, org a nization, and co n ventions of this gui de, and describes related docu ments that ha ve additio nal information.
x Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface Organization This guide is or ganized into the follo wing chapters and appendi x. Part 1: Getting Started Chapter 1 , “Basic Router Conf iguration” Describes how to conf igure basic router features and interfaces.
xi Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface Conventions This section descri bes the con vention s used in this guide. Note Means reader take note . Notes contain helpful suggestio ns or references to additio nal information and material.
xii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface Attention IMPORT ANTES INFORMA TIONS DE SÉCURITÉ Ce symbole d'avertissement indique un danger . V ous vous trouvez dans une situation pouvant entraîner des blessures ou des do mmages corporels.
xiii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface ¡Advertencia! INSTRUCCIONES IMPORT ANTES DE SEGURIDAD Este símbolo de aviso indica peligro.
xiv Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface Avi so INSTRUÇÕES IMPORT ANTES DE SEGURANÇA Este símbolo de aviso significa perigo.
xv Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface.
xvi Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface Related Documentation The Cisco Secure Router 520 Series pr oduct is shipped wi th a minimal set of printed do cumentation. Additional prod uct documentation is a vailable on Cisco.
xvii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface Obtaining Documentation and Submitting a Service Request For info rmation on obtaining documentation, sub mitting a.
xviii Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Preface.
P ART 1 Get ting Star ted.
.
CH A P T E R 1-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 1 Basic Router Configuration The Cisco Secure Router 520 Series r outers are designed for small b usinesses with up to 50 users and telew orkers who want secure connect i vity to corporate LANs and to th e Internet.
1-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Con figuration Viewing the De fault Configuration Viewing the Default Configuration When the router first boots up, some basic confi gurat ion has already been performed.
1-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Configuration Interface Port Labels – Order the appropriate li ne from your public tele phone service pro vider . Ensure that the ADSL signaling type is DMT (also called AN SI T1.
1-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Con figuration Configuring Basic Parameters Configure Global Parameters Perform these steps to configure select ed gl obal parameters for your rout er: For complete in formation on the global paramet er commands, see the Cisco IOS Release 12.
1-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Configuration Configuring Basic Parameters Based on the rou ter you hav e, configure th e W AN interf.
1-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Con figuration Configuring Basic Parameters Perform these steps to conf igure the A TM interface, beg.
1-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Configuration Configuring Basic Parameters Perform these steps to conf igure a loopback interface, be.
1-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Con figuration Configuring Basic Parameters Last clearing of "show interface" counters neve.
1-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Configuration Configuring Basic Parameters For complete in formation about the co mmand line commands, see the Cisco IOS Rel ease 12.3 documentation set .
1-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Con figuration Configuring Static Routes Configuring Static Routes Static routes pro vide fix ed routing paths through the network. Th ey are manually conf igured on the router .
1-11 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Configuration Configuring Dyn amic Routes ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is not set 10.
1-12 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 1 Basic Router Con figuration Configuring Dynamic Routes For complete in formation on the dynamic routi ng commands, see the Cisco IOS Release 12 .3 documentatio n set.
P ART 2 Conf iguring Y our Router f o r Ethernet and DSL A ccess.
.
CH A P T E R 2-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 2 Sample Network Deployments This part of the softw are config uration guide presents a v ariety of possible Ethernet and Digital Subscriber Line (DSL)—based networ k conf igurations using the Cisco Secure Router 520 Ser ies router .
2-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 2 Sample Network De ployments • Chapter 7, “Configuring VPNs Using an IPsec T u nnel and G eneric Ro uting Encap.
CH A P T E R 3-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 3 Configuring PPP over Ethernet with NAT The Cisco Secure Router 520 Ethernet-to-Ethernet r outers su pport Point-to-Po int Protocol o ver Ethern et (PPPoE) clients and network address translat ion (N A T).
3-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuring PPP over Ethernet with NAT Configure the Vir tual Private Dialup Network Group Number PPPoE The PPPoE Client feature on the router pro vides PPPoE client support on Ethernet interf aces.
3-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuri ng PPP over Ethern et with NAT Configure the Fast Ethern et WAN Interfaces Configure the Fast Ethernet W.
3-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuring PPP over Ethernet with NAT Configure the Dialer Interface Configure the Dialer Interface The dialer in.
3-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuri ng PPP over Ethern et with NAT Configure Network Address Translation Configure Network Address Translati.
3-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuring PPP over Ethernet with NAT Configure Netw ork Address Tran slation Perform these steps to configu re t.
3-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuri ng PPP over Ethern et with NAT Configure Network Address Translation Note If you want to use N A T with a virtual-template interf ace, you must conf igure a loopback interf ace.
3-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuring PPP over Ethernet with NAT Configuratio n Example Configuration Example The follo wing conf iguration example sho ws a portion of the configurat ion file for the PPPoE scenario described in th is chapter .
3-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuri ng PPP over Ethern et with NAT Configuration E xample Dynamic mappings: -- Inside Source [Id: 1] access-.
3-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 3 Configuring PPP over Ethernet with NAT Configuratio n Example.
CH A P T E R 4-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 4 Configuring PPP over ATM with NAT The Cisco Secure Router 520 ADSL-ov er-PO TS and Cisco Secure Router 520 ADSL-ov er-ISDN routers support Point-to-Point Protocol o ver Asynchronous T r ansfer Mode (PPPoA) clie nts and network address translation (N A T).
4-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configu ring PPP over ATM with N AT Configure the Dialer Interface In this scenario, the smal l business or remote.
4-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configuring PPP over ATM with NAT Configure th e Dialer Interface Perform these steps to configure a dialer interf.
4-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configu ring PPP over ATM with N AT Configure the Dialer Interface Repeat these steps for any ad ditional dialer interfac es or dialer pools needed. Step 8 exit Example: Router(config-if)# exit Router(config)# Exits the dialer 0 interface configuration.
4-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configuring PPP over ATM with NAT Configure the ATM WAN Interface Configure the ATM WAN Interface Perform these st.
4-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configu ring PPP over ATM with N AT Configure DSL Signa ling Protocol Configure DSL Signaling Protocol DSL signaling must be conf igured on the A TM interf ace for connection to your ISP .
4-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configuring PPP over ATM with NAT Configure Network Address Translation Verify the Configuration Y ou can verify t hat the confi guration is set the way yo u want b y using the sho w dsl interface atm command from pri vileged EXEC mode.
4-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configu ring PPP over ATM with N AT Configure Netw ork Address Tran slation Step 4 ip nat { inside | outside } Example: Router(config-if)# ip nat inside Router(config-if)# Applies NA T to the Fast Ethernet LAN interface as the inside interf ace.
4-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configuring PPP over ATM with NAT Configuration E xample Note If you want to use N A T with a virtual-template interf ace, you must conf igure a loopback interf ace.
4-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 4 Configu ring PPP over ATM with N AT Configuratio n Example ip mtu 1492 encapsulation ppp dialer pool 1 dialer-group 1 ppp authentication chap ! ip classless ( default ) ! ip nat pool pool1 192.
CH A P T E R 5-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 5 Configuring a LAN with DHCP and VLANs The Cisco Secure Router 520 Ser ies routers supp ort clients on both phy sical LANs and virtual LANs (VLANs).
5-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configu ring a LAN with DHCP and VLANs Configure DHCP Note Whenev er you change server p roperties, you must relo ad the serv er with the configur ation data from the Network Re gistrar database.
5-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configuring a LAN with DHCP and VLANs Configure DHCP Step 4 ip dhcp pool name Example: Router(config)# ip dhcp pool dpool1 Router(dhcp-config)# Creates a DHCP address pool on the router and enters DHCP pool conf iguration mode.
5-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configu ring a LAN with DHCP and VLANs Configure DHCP Configuration Example The follo wing conf iguration example sho ws a portion of the confi guration fi le for the DCHP confi guration described in this chapter .
5-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configuring a LAN with DHCP and VLANs Configure VLANs Message Sent BOOTREPLY 0 DHCPOFFER 0 DHCPACK 0 DHCPNAK 0 Rou.
5-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configu ring a LAN with DHCP and VLANs Configure VLANs Assign a Switch Port to a VLAN Perform these steps to assig.
5-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configuring a LAN with DHCP and VLANs Configure VLANs VLAN ISL Id: 3 Name: red-vlan Media Type: Ethernet VLAN 802.10 Id: 100003 State: Operational MTU: 1500 VLAN ISL Id: 1002 Name: fddi-default Media Type: FDDI VLAN 802.
5-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 5 Configu ring a LAN with DHCP and VLANs Configure VLANs VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Tran.
CH A P T E R 6-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel The Cisco Secure Router 520 Ser ies routers support the creation of V irtual Priv ate Networks (VPNs).
6-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Cisco Easy VPN The Cisco Easy VPN client feature elimin ates much of the tedious conf iguration work b y implementing the Cisco Un ity Client prot ocol.
6-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Configure the I KE Policy Note The procedures in this chap ter assume that you h av e already conf igur ed basic router feat ures as well as PPPoE or PPPoA with N A T , DCHP and VLANs.
6-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Configure Gro up Policy Information Configure Group Policy In.
6-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Apply Mode Con figur ation to the Crypto Map Apply Mode Confi.
6-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Enable Policy Lookup Enable Policy Lookup Perform these steps.
6-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Configure the IPsec Cryp to Method and Paramete rs Perform th.
6-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Apply the Crypto Ma p to the Phys ical Interface Apply the Crypto Map to the Physical Interface The crypto maps must be applied to each interface through which IP Security (IPsec) traff ic flows.
6-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Create an Easy VPN Remote Configuration Create an Easy VPN Remote Configuration The router acting as the IPsec remote router must create an Easy VPN remote configuration and assign it to the outgoing interf ace.
6-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Verifying Your Easy VPN Configuration Verifying Your Easy VP.
6-11 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Configuration E xample username Cisco password 0 Cisco ! cry.
6-12 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel Configuratio n Example.
CH A P T E R 7-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 7 Configuring VPNs Using an IPsec Tunnel and Generic Routing Encapsulation The Cisco Secure Router 520 Ser ies routers support the creation of virtual pr iv ate networks (VPNs).
7-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configur ing VPNs Using an IP sec Tun nel and Generic Routing E ncapsulation Configure a VPN GRE Tunnels GRE tunne.
7-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configuring VPNs Using an IPsec Tunnel and Generic Routing Encap sulation Configure a VPN Configure the IKE Policy.
7-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configur ing VPNs Using an IP sec Tun nel and Generic Routing E ncapsulation Configure a VPN Configure Group Polic.
7-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configuring VPNs Using an IPsec Tunnel and Generic Routing Encap sulation Configure a VPN Enable Policy Lookup Per.
7-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configur ing VPNs Using an IP sec Tun nel and Generic Routing E ncapsulation Configure a VPN Perform these steps t.
7-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configuring VPNs Using an IPsec Tunnel and Generic Routing Encap sulation Configure a VPN Apply the Crypto Map to the Physical Interface The crypto maps must be applied to each interface through which IP sec traf fic flo w s.
7-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configur ing VPNs Using an IP sec Tun nel and Generic Routing E ncapsulation Configure a GRE Tunnel Configure a GR.
7-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configuring VPNs Using an IPsec Tunnel and Generic Routing Encap sulation Configuration E xample Configuration Exa.
7-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configur ing VPNs Using an IP sec Tun nel and Generic Routing E ncapsulation Configuratio n Example tunnel source fastethernet 0 tunnel destination interface 192.168.
7-11 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configuring VPNs Using an IPsec Tunnel and Generic Routing Encap sulation Configuration E xample ! ! Utilize NAT overload in order to make best use of the ! single address provided by the ISP.
7-12 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 7 Configur ing VPNs Using an IP sec Tun nel and Generic Routing E ncapsulation Configuratio n Example.
CH A P T E R 8-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 8 Configuring a Simple Firewall The Cisco Secure Router 520 Series routers support network traf fic filtering b y means of access lists.
8-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 8 Config uring a Simple Firewall Figure 8-1 sho ws a network deplo yment using PPPoE or PPPoA with N A T and a fire wall.
8-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 8 Configuring a Simple Firewall Configure Acce ss Lists Note The procedures in this chap ter assume that you h av e already conf igur ed basic router feat ures as well as PPPoE or PPPoA with N A T .
8-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 8 Config uring a Simple Firewall Configure Inspection Rules Configure Inspection Rules Perform these steps to confi .
8-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 8 Configuring a Simple Firewall Configuration E xample Configuration Example A telecommuter is granted s ecure access to a corporat e network, using IPsec tunnel ing. Security to the home network is acco mplished through f irewal l inspec tion.
8-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 8 Config uring a Simple Firewall Configuratio n Example ip nat outside no cdp enable ! ! acl 103 defines traffic allowed from the peer for the IPsec tunnel. access-list 103 permit udp host 200.
CH A P T E R 9-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 9 Configuring a Wireless LAN Connection The Cisco Secure Router 520 Series routers support a secur e, af fordab.
9-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configu ring a Wireless LAN Connectio n Configure the Root Radio Statio n Configuration Tasks Perform the follo wi.
9-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configuring a Wireless LAN Connection Configure the Ro ot Radio Station Step 3 encryption method algorithm ke y Ex.
9-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configu ring a Wireless LAN Connectio n Configure Bridging on VLA Ns Configure Bridging on VLANs Perform these ste.
9-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configuring a Wireless LAN Connection Configure Radio Station Su binterfaces Repeat Step 2 through Step 6 abov e for each VLAN that requires a wireless inte rface.
9-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configu ring a Wireless LAN Connectio n Configuratio n Example Repeat these steps to configure more subinterfaces, as needed.
9-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configuring a Wireless LAN Connection Configuration E xample ! encryption vlan 1 mode ciphers tkip ! ssid cisco vl.
9-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 9 Configu ring a Wireless LAN Connectio n Configuratio n Example no ip address bridge-group 3 bridge-group 3 spanning-disabled ! interface BVI1 ip address 10.0.1.1 255.
P ART 3 Conf iguring A dditional F eatures and T r oubleshooting.
.
CH A P T E R 10-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 10 Additional Configuration Options This part of the softw are conf iguration guid e describes addi tional conf iguration options and troubleshooting t ips for the Cisco Secure Router 520 Series routers.
10-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 10 Additional Configuration Options.
CH A P T E R 11-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 11 Configuring Security Features This chapter gi ves an ov erview of authentication, au thorization, and accou.
11-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 11 Configur ing Security Features Configuring AutoSecure For info rmation about confi guring AAA services and suppo.
11-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 11 Configuring Security Featur es Configuring a CBAC Firewall Access Groups A sequence of access list def initions bound together with a common name or number is called an access group.
11-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 11 Configur ing Security Features Configuring Cisco IOS Firewall IDS Configuring Cisco IOS Firewall IDS Cisco IOS F.
CH A P T E R 12-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 12 Troubleshooting Use the information in this chapter to help isolate problems you might encounter or to rule out the router as the source of a problem.
12-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troublesho oting ADSL Troublesho oting ADSL Troubleshooting If you e xperience trouble with the ADSL connection, v erify the follo wing: • The ADSL line is connected and i s using pins 3 and 4.
12-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troub leshooting ATM Troubleshoo ting Commands This command sends end-to-end O AM F5 packets, which are echoed back by the aggregator .
12-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troublesho oting ATM Troubleshooting Co mmands Ta b l e 12-1 describes possible command ou tput for the sho w interface command.
12-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troub leshooting ATM Troubleshoo ting Commands show atm interface Command T o display A TM-specifi c information about an A TM interface, use the show atm interface atm 0 command from pri vileged EXEC mode, as sh ow n in Example 12-3 .
12-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troublesho oting ATM Troubleshooting Co mmands • T o disable debu gging, enter the undeb ug all command. • To u s e deb ug commands during a T elnet session on your r outer , enter the terminal monitor command.
12-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troub leshooting ATM Troubleshoo ting Commands 00:03:00: DSL: 1: Modem state = 0x8 00:03:02: DSL: 2: Modem state.
12-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troublesho oting Software Upgrad e Methods Example 12-7 sho w s sample output for the deb ug atm packet co mmand.
12-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troub leshooting Recovering a Lost Password Recovering a Lost Password T o recov er a lost enable or lost enable-secret passw ord: 1. Change the Configuration Re gister 2.
12-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troublesho oting Recovering a Lost Pa ssword Cisco SR520W-ADSL (MPC8272) processor (revision 0x100) with 118784K/12288K bytes of memory.
12-11 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troub leshooting Recovering a Lost Password Step 7 Enter the enable command to enter enable mode.
12-12 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Chapter 12 Troublesho oting Recovering a Lost Pa ssword Step 3 Enter exit to e xit configuratio n mode: Router(config)# ex.
P ART 4 Reference Inf ormation.
.
A-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 APPENDIX A Cisco IOS Software Basic Skills Understanding ho w to use Cisco IOS software can sa ve you time when you are conf iguring your router . If you need a refresher , take a fe w minutes to read this appendix.
A-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisco IOS Software Basic Skills Understandi ng Command Mode s Y ou can use the terminal emulation software to change settings for the type of de vice that is connected to the PC, in this case a rout er .
A-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisc o IOS Software Basic Skills Understanding Command Mode s Ta b l e A -2 Command Modes Summary Mode Access Method Prompt Exit and Entrance Method About This Mode User EXEC Begin a session with your router .
A-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisco IOS Software Basic Skills Getting Help Getting Help Y ou can use the qu estion mark (?) a nd ar ro w ke ys to help you enter commands.
A-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisc o IOS Software Basic Skills Entering Glob al Configuration Mode Y ou can use two commands to do this: • en.
A-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisco IOS Software Basic Skills Saving Configu ration Changes Abbreviating Commands Y ou only ha ve to enter enough ch aracters for the router to reco gnize the command as unique.
A-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisc o IOS Software Basic Skills Summary Press Return to accept the default destination filename startup- conf ig , or enter your desired destination filename and p ress Return .
A-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix A Cisco IOS Software Basic Skills Where to Go Next.
B-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 APPENDIX B Concepts This appendix contains conceptual information that may be useful to In ternet service providers or network admin istrators when the y configure Cisco ro uters.
B-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts Network Pro tocols Network Protocols Network protoco ls enable the network to pass data fro m its source to a specif ic destination ov er LAN or W AN links.
B-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts PPP Authentication Protocols PPP Authentication Protocols The Point-to-Point Pr otocol (PPP) encapsulates netwo rk layer protocol informat ion ov er point-to-point li nks.
B-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts TACACS+ Note W e recommend us ing CHAP because it is th e more secure of the two protocols. TACACS+ Cisco Secure Router 520 Ser ies routers supp ort the T erminal Access Controller Access Control System Plus (T ACA CS+) protocol through T elnet.
B-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts NAT PVC A PVC is a connection between remote hosts and ro uters.
B-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts Easy IP (Phase 1) T r anslations can be static or dynamic. A static address translation establishes a one-to-one mapping between t he inside network an d the outsid e domain.
B-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts QoS QoS This section descri bes Quality of Service (QoS) parameter s, including the follo wing: • IP P.
B-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts QoS In general, multilink PPP wi th interlea ving is used in conjunc tion with CBWFQ and RSVP or IP Precedence to ensure voice packet deli very .
B-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts Access Lists Access Lists W ith basic standard and static e xtended access lists, you can approximate session f iltering by using the established ke yword with the permit command.
B-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix B Concepts Access Lists.
C-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 APPENDIX C ROM Monitor The R OM monitor firmware runs when the rout er is po we red up or reset. The f irmware helps to initialize the processor hardware an d boot the operating sy stem sof tware.
C-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor ROM Monitor Commands T imesaver Break (system interrupt) is alw ays enabled for 60 second s after the rout er reboots, re gardless of whether it is set to on or of f in the configurat ion register .
C-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Command Descriptions Commands are case sensitiv e. Y ou can halt any comma nd by pressing the Break key on a terminal.
C-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Disaster Recover y with TFTP Down load TFTP Download Command Variables This section describes the syst em v ariables that can be set in R OM monitor mode and that are used during the TFTP download process.
C-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Configuration Register Using the TFTP Download Command Perform these steps in R OM monitor mode to do.
C-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Configuratio n Register Changing the Configuration Register Manually T o change the virtual conf igur.
C-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Console Download Console Download Y ou can use cons ole do wnload, a R OM monitor functio n, to do w nload either a software image or a confi guration file o ver the router console por t.
C-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Debug Command s Error Reporting Because the R OM monitor console download uses the co nsole to perfor.
C-9 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Exiting the ROM Monitor FP: 0x80005f9c, PC: 0x80008118 FP: 0x80005fac, PC: 0x80008064 FP: 0x80005fc4,.
C-10 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix C ROM Monitor Exiting the ROM Monitor.
D-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 APPENDIX D Common Port Assignments Ta b l e D-1 lists currently assign ed T ransmission Cont rol Protocol (TCP) port number s. T o the extent possible, the User Datagram Protocol (UDP) uses the same numbers.
D-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Appendix D Common Po rt Assignments 75 — Any pri vate dial-out service 77 — Any pri vate RJE service 79 FINGER Finger 95.
IN-1 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 INDEX Symbols -? command C-3 ? command A-4, C-3 A AAL B-5 AAL3/4 B-5 AAL5 B-5 abbreviating commands A-6 access groups 11-3 .
Index IN-2 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 configuration example 1-9 configuring 1-8 command modes A-2 to A-4 commands -? C-3 ? A-4 abbreviating A-6 access list.
Index IN-3 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 Fast Ethernet LAN interfaces 1-4 Fast Ethernet WA N interface 1-5 firewall 8-1 to 8-6 global parameters 1-4 GRE tunne.
Index IN-4 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 extended access list, overview B-9 F Fast Ethernet LAN interfaces, configuring 1-4 Fast Ethernet WAN interface, confi.
Index IN-5 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 loopback interface, config uring 1-6 to 1-8 low laten cy queuing See LFQ M meminfo command C -9 metrics RIP B-2 mode .
Index IN-6 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 protocols ATM B-4 Ethernet B-4 network B-2 network interface B-4 to B-5 PPP authentication B-3 routing overview B-2 t.
Index IN-7 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01 troubleshooting co mmands, ATM 12-2 to 12-8 U UDP port numbers D-1 to D-2 undoing commands A-6 upgrading software, me.
Index IN-8 Cisco Secure Router 520 Series Software Configuration Guide OL-14210-01.
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté Cisco Systems 520 series c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du Cisco Systems 520 series - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation Cisco Systems 520 series, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le Cisco Systems 520 series va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le Cisco Systems 520 series, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du Cisco Systems 520 series.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le Cisco Systems 520 series. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei Cisco Systems 520 series ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.