Добрый день!
Имеем cisco 2801 вот вырезка из конфига:ip inspect name FW tcp router-traffic
ip inspect name FW udp router-traffic
interface FastEthernet0/0
ip address 172.16.1.8 255.255.255.0
ip access-group WAN-IN in
ip inspect FW out
ip access-list extended WAN-IN
permit tcp any any established
permit icmp any any
permit tcp any any eq 22
permit tcp any any eq telnet
При этом нет возможности слить рабочий конфиг с маршрутизатора на удаленный tftp сервер.
copy running-config tftp://172.16.1.160
Address or name of remote host [172.16.1.160]?
Destination filename [s10-r1-confg]?
.....
%Error opening tftp://172.16.1.160/s10-r1-confg (Timed out)
В логах появляется следующее:
000097: Apr 12 15:33:32 UZB: %SEC-6-IPACCESSLOGP: list WAN-IN denied udp 172.16.1.160(59691) -> 172.16.1.8(64445), 1 packet
т.е. инспекция не работает :(
sh ip inspect all
Session audit trail is disabled
Session alert is enabled
one-minute (sampling period) thresholds are [unlimited : unlimited] connections
max-incomplete sessions thresholds are [unlimited : unlimited]
max-incomplete tcp connections per host is unlimited. Block-time 0 minute.
tcp synwait-time is 30 sec -- tcp finwait-time is 5 sec
tcp idle-time is 3600 sec -- udp idle-time is 30 sec
dns-timeout is 5 sec
Inspection Rule Configuration
Inspection name FW
udp alert is on audit-trail is off timeout 30
inspection of router local traffic is enabled
tcp alert is on audit-trail is off timeout 3600
inspection of router local traffic is enabled
tftp alert is on audit-trail is off timeout 30
Interface Configuration
Interface FastEthernet0/0
Inbound inspection rule is not set
Outgoing inspection rule is FW
udp alert is on audit-trail is off timeout 30
inspection of router local traffic is enabled
tcp alert is on audit-trail is off timeout 3600
Inbound access list is WAN-IN
Outgoing access list is not set
Half-open Sessions
Session 63334B78 (172.16.1.8:50593)=>(172.16.1.160:69) udp SIS_OPENING