Hallo,
Zitat von Wordo
Du solltest deine access-lists mal posten
Fuer IPSec brauchst du Port 500/UDP und Protokoll 50.
|
folgende ACL habe ich:
============================================
access-list 100 permit icmp any host 82.139.196.198
access-list 100 permit icmp any host 82.139.201.73
access-list 100 permit icmp any host 82.139.201.74
access-list 100 permit icmp any host 212.60.137.241
access-list 100 permit icmp any host 212.60.137.242
access-list 100 permit icmp any host 212.60.137.243
access-list 100 permit icmp any host 212.60.137.244
access-list 100 permit icmp any host 212.60.137.245
access-list 100 permit icmp any host 212.60.137.246
access-list 100 permit icmp any host 212.60.137.247
access-list 100 permit icmp any host 212.60.137.248
access-list 100 permit icmp any host 212.60.137.249
access-list 100 permit icmp any host 212.60.137.250
access-list 100 permit icmp any host 212.60.137.251
access-list 100 permit icmp any host 212.60.137.252
access-list 100 permit icmp any host 212.60.137.253
access-list 100 permit icmp any host 212.60.137.254
access-list 100 permit udp any host 212.60.137.254
access-list 100 permit ahp any host 212.60.137.254
access-list 100 permit esp any host 212.60.137.254
access-list 100 permit gre any host 212.60.137.254
access-list 100 permit tcp any host 82.139.201.74
access-list 100 permit tcp any host 212.60.137.241
access-list 100 permit tcp any host 212.60.137.242
access-list 100 permit tcp any host 212.60.137.243
access-list 100 permit tcp any host 212.60.137.244
access-list 100 permit tcp any host 212.60.137.245
access-list 100 permit tcp any host 212.60.137.246
access-list 100 permit tcp any host 212.60.137.247
access-list 100 permit tcp any host 212.60.137.248
access-list 100 permit tcp any host 212.60.137.249
access-list 100 permit tcp any host 212.60.137.250
access-list 100 permit tcp any host 212.60.137.251
access-list 100 permit tcp any host 212.60.137.252
access-list 100 permit tcp any host 212.60.137.253
access-list 100 permit tcp any host 212.60.137.254
access-list 100 deny ip any any log
access-list 199 deny ip any any log
dialer-list 1 protocol ip permit
============================================
Die Pakete kommen scheinbar nicht durch den Cisco-Router durch, denn bei dem ASG kommt nichts an...
Michael