i got my DHCP problem half way solved. now for some reason, when I place ACL's on the WAN port (e0/0), i can't get an address from the DHCP server. i need to take the ACL's off and then the router will get an address.
also, the performace of the router is HORRIBLE. it works intermittantly... and it's really slow. i know that CBAC's tax the processor, but this is a home setup that serves 2 computers. i'd figure a 2611 with 16F/64R would at least perform better than my 4-port linksys.
here's the comfig. maybe someone can tell me what's causing the slowdown.
-----------------------------------
version 12.3
no service pad
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
!
hostname pluto
!
boot-start-marker
boot-end-marker
!
enable secret 5 xxx
enable password 7 xxx
!
username austin password 7 xxx
clock timezone PST -8
clock summer-time PDT recurring
aaa new-model
!
!
aaa session-id common
ip subnet-zero
no ip source-route
!
!
ip domain name sol.home
ip name-server 24.52.223.218
ip name-server 24.52.223.219
!
no ip bootp server
ip audit notify log
ip audit po max-events 100
ip audit smtp spam 50
ip ssh time-out 30
ip ssh authentication-retries 2
ip ssh rsa keypair-name general-keypairs
ip ssh break-string
!
!
!
crypto isakmp policy 3
encr 3des
!
!
!
!
!
!
!
!
!
!
no voice hpi capture buffer
no voice hpi capture destination
!
!
!
!
!
!
interface Ethernet0/0
description *** ethernet 0 - WAN Interface ***
ip address dhcp
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
half-duplex
no cdp enable
hold-queue 100 out
!
interface Serial0/0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
shutdown
no fair-queue
no cdp enable
!
interface BRI0/0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
shutdown
no cdp enable
!
interface Ethernet0/1
description *** ethernet 0/1 - LAN Interface ***
ip address 10.10.100.1 255.255.255.248
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat inside
full-duplex
no cdp enable
hold-queue 100 out
!
ip nat pool homenatpool 10.10.100.1 10.10.100.1 netmask 255.255.255.248
ip nat inside source list 25 interface Ethernet0/0 overload
no ip http server
no ip http secure-server
ip classless
!
ip access-list extended INBOUND
permit tcp any any eq 67
permit udp any any eq 68
permit icmp host 67.21.13.132 any log
permit udp host 68.65.79.1 any log
evaluate INVITED-TRAFFIC
deny ip any any log
ip access-list extended OUTBOUND
permit ip any any reflect INVITED-TRAFFIC
ip access-list extended ICMP_DENY
deny icmp any any echo log
deny icmp any any redirect log
deny icmp any any mask-request log
ip access-list extended ICMP_PERMIT
permit icmp any any echo-reply
permit icmp any any time-exceeded
permit icmp any any packet-too-big
permit icmp any any traceroute
permit icmp any any unreachable
permit icmp any any parameter-problem
ip access-list extended SSH_ACCESS
permit tcp host 10.10.xxx host 10.10.100.1 eq 22 log
permit tcp host 10.10.xxx host 10.10.100.1 eq 22 log
deny tcp any any eq 22 log
logging trap debugging
access-list 24 permit any
access-list 25 permit 10.10.100.0 0.0.0.7
no cdp run
!
!
!
!
banner exec ^CC
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* This system is private property, and is intended for the specific *
* use of authorized users only. All activities of individuals using this *
* computing system without authority, or in excess of their authority, are *
* monitored and recorded by system personnel. If any such monitoring *
* reveals possible evidence of criminal activity, system personnel may *
* provide such evidence to law enforcement officials. *
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *^C
!
line con 0
password 7 xxx
stopbits 1
speed 115200
line aux 0
line vty 0
access-class SSH_ACCESS in
transport input ssh
line vty 1 4
transport input none
!
scheduler max-task-time 5000
ntp clock-period 17168756
ntp server 192.4.41.41
ntp server 192.5.41.40
!
!
end
----------------------
also, the performace of the router is HORRIBLE. it works intermittantly... and it's really slow. i know that CBAC's tax the processor, but this is a home setup that serves 2 computers. i'd figure a 2611 with 16F/64R would at least perform better than my 4-port linksys.
here's the comfig. maybe someone can tell me what's causing the slowdown.
-----------------------------------
version 12.3
no service pad
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
!
hostname pluto
!
boot-start-marker
boot-end-marker
!
enable secret 5 xxx
enable password 7 xxx
!
username austin password 7 xxx
clock timezone PST -8
clock summer-time PDT recurring
aaa new-model
!
!
aaa session-id common
ip subnet-zero
no ip source-route
!
!
ip domain name sol.home
ip name-server 24.52.223.218
ip name-server 24.52.223.219
!
no ip bootp server
ip audit notify log
ip audit po max-events 100
ip audit smtp spam 50
ip ssh time-out 30
ip ssh authentication-retries 2
ip ssh rsa keypair-name general-keypairs
ip ssh break-string
!
!
!
crypto isakmp policy 3
encr 3des
!
!
!
!
!
!
!
!
!
!
no voice hpi capture buffer
no voice hpi capture destination
!
!
!
!
!
!
interface Ethernet0/0
description *** ethernet 0 - WAN Interface ***
ip address dhcp
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
half-duplex
no cdp enable
hold-queue 100 out
!
interface Serial0/0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
shutdown
no fair-queue
no cdp enable
!
interface BRI0/0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
shutdown
no cdp enable
!
interface Ethernet0/1
description *** ethernet 0/1 - LAN Interface ***
ip address 10.10.100.1 255.255.255.248
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat inside
full-duplex
no cdp enable
hold-queue 100 out
!
ip nat pool homenatpool 10.10.100.1 10.10.100.1 netmask 255.255.255.248
ip nat inside source list 25 interface Ethernet0/0 overload
no ip http server
no ip http secure-server
ip classless
!
ip access-list extended INBOUND
permit tcp any any eq 67
permit udp any any eq 68
permit icmp host 67.21.13.132 any log
permit udp host 68.65.79.1 any log
evaluate INVITED-TRAFFIC
deny ip any any log
ip access-list extended OUTBOUND
permit ip any any reflect INVITED-TRAFFIC
ip access-list extended ICMP_DENY
deny icmp any any echo log
deny icmp any any redirect log
deny icmp any any mask-request log
ip access-list extended ICMP_PERMIT
permit icmp any any echo-reply
permit icmp any any time-exceeded
permit icmp any any packet-too-big
permit icmp any any traceroute
permit icmp any any unreachable
permit icmp any any parameter-problem
ip access-list extended SSH_ACCESS
permit tcp host 10.10.xxx host 10.10.100.1 eq 22 log
permit tcp host 10.10.xxx host 10.10.100.1 eq 22 log
deny tcp any any eq 22 log
logging trap debugging
access-list 24 permit any
access-list 25 permit 10.10.100.0 0.0.0.7
no cdp run
!
!
!
!
banner exec ^CC
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* This system is private property, and is intended for the specific *
* use of authorized users only. All activities of individuals using this *
* computing system without authority, or in excess of their authority, are *
* monitored and recorded by system personnel. If any such monitoring *
* reveals possible evidence of criminal activity, system personnel may *
* provide such evidence to law enforcement officials. *
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *^C
!
line con 0
password 7 xxx
stopbits 1
speed 115200
line aux 0
line vty 0
access-class SSH_ACCESS in
transport input ssh
line vty 1 4
transport input none
!
scheduler max-task-time 5000
ntp clock-period 17168756
ntp server 192.4.41.41
ntp server 192.5.41.40
!
!
end
----------------------
