We have a Cisco 881 setup with outside world connection via Fa4. On the same unit we have a 3G connection configured.
Does anybody know if there is a way to set the router up to simultaneously allow use of the 3G and the wired WAN? Not looking for a fail-over type of set-up. I want the traffic from the LAN to external destinations to pass via Fa4 but I would like to be able to SSH into the router from the internet via the 3G for maintenance purposes. We currently have our default gateway (gateway of last resort) set as the upstream router connected to Fa4.
I would say that if you want only to access the roouter via 3G by SSH and nothing else, then much simpler is to configure local PBR for source address match 3G card's ip-address and use "set interface C0/0/0".
route-map LOCAL_TRAFFIC permit 10
match ip address 3G_ACCESS
set interface C0/0/0 Null0
(Null0 is required to drop traffic in case C0/0/0 is down)
ip policy route-map LOCAL_TRAFFIC
there are several options for 3G_ACCESS ACL to be configured:
1. ip access-l sta 3G_ACCESS
permit host <3G interface IP-address>
2. ip access-l ext 3G_ACCESS
permit tcp host <3G interface IP-address> eq 22 any
3. ip access-l ext 3G_ACCESS
deny ip any
deny ip host
permit tcp any eq 22 any
4. and etc.
Surely the best practice is to use access-class command under line vty if you always use static public address to connect with if not, then I would recommend to use login delay and telnet quiet-mode.
Ps: the best practice is to use dialer interface instead of direct configuration under C0/0/0; in this case set interface should be dialerX.
We have 3 identical switches configured by someone else and would like to claim some of the Gigabit ports(G1/G2/G3/G4) for use on servers. When we try to change the wiring and configuration, we run in to connectivity issues. Attached is a des...
This is actually a pretty cool feature, i didn't even know it existed until I was looking for a solution to advertise a subnet (prefix in BGP talk), only if a certain condition existed. This is exactly what conditional advertisements does
j ai une question j ai achete un routeur cisco 887VA-k9 , je le configuré avec la configuration ci- dessous
si je le lier avec mon pc portable sur l un de ses ports directement ça marche toute est bien ( la connexion internet + m...