re:我是一个初级用户,碰到一个VPN的小问题...
我是一个初级用户,碰到一个VPN的小问题,就是用户的权限太大不知道如何设置。
具体问题如下:
通过WINDOWS2000自带的PPP VPN虚拟隧道连接。路由上设置了用户和密码,可是现在我发现居然在用户名和密码上空的也能连接。所以我想控制这个漏洞,不知道如何进行具体的设置。
楼上的也发一份VPN的文档给我行吗?
现在具体的设置如下:
XXXX>en
Password:
XXXX#show run
Building configuration...
Current configuration : 2539 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname XXX
!
boot-start-marker
boot-end-marker
!
enable secret level 7 5 $1$uja1$50zoee.tAYUDgzjUPGt8n/
enable password 7 094F471A1A0A
!
username cisco password 7 110A1016141D
aaa new-model
!
!
aaa authentication login userauth local
aaa authorization network groupauth local
aaa session-id common
ip subnet-zero
!
!
XXXX#en
XXXX#show run
Building configuration...
Current configuration : 2539 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname XXXX
!
boot-start-marker
boot-end-marker
!
enable secret level 7 5 $1$uja1$50zoee.tAYUDgzjUPGt8n/
enable password 7 094F471A1A0A
!
username cisco password 7 110A1016141D
aaa new-model
!
!
aaa authentication login userauth local
aaa authorization network groupauth local
aaa session-id common
ip subnet-zero
!
!
no ip domain lookup
ip domain name nnbus.com
!
ip audit notify log
ip audit po max-events 100
vpdn enable
!
vpdn-group PPTP_Windows
! Default PPTP VPDN group
accept-dialin
protocol pptp
virtual-template 1
!
no ftp-server write-enable
!
!
!
crypto isakmp policy 3
hash md5
authentication pre-share
group 2
crypto isakmp client configuration address-pool local ippool
!
crypto isakmp client configuration group haman
key haman
pool ippool
!
crypto isakmp client configuration group hamanclient
key hamancisco123
pool ippool
acl 133
!
!
crypto ipsec transform-set myset esp-des esp-md5-hmac
!
crypto dynamic-map dynmap 10
set transform-set myset
!
!
crypto map clientmap client authentication list userauth
crypto map clientmap isakmp authorization list groupauth
crypto map clientmap client configuration address respond
crypto map clientmap 10 ipsec-isakmp dynamic dynmap
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 192.168.5.1 255.255.255.0
ip nat inside
duplex auto
speed auto
!
interface Serial0/0
ip address 10.101.206.22 255.255.255.240 secondary
ip address 10.101.206.21 255.255.255.240 secondary
ip address 10.254.101.122 255.255.255.240
ip accounting output-packets
ip nat outside
crypto map clientmap
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Virtual-Template1
ip unnumbered Serial0/0
peer default ip address pool ippool
no keepalive
ppp encrypt mppe auto
!
ip local pool ippool 172.145.0.8 172.145.0.8
ip nat inside source list 1 interface Serial0/0 overload
ip nat inside source static 172.145.0.8 10.101.206.22
no ip http server
no ip http secure-server
ip classless
ip route 0.0.0.0 0.0.0.0 202.103.228.29
!
!
access-list 1 permit 10.101.206.22 0.0.0.255
access-list 133 permit ip 110.101.206.22 0.0.0.255 any
access-list 133 permit ip 10.101.206.22 0.0.0.255 any
!
snmp-server community public RO
snmp-server community private RW
snmp-server enable traps tty
!
!
!
!
dial-peer cor custom
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
password 7 05080F1C2243
!
!
!
end
XXXX#
为了安全具体的主机名称和IP我都改过了。请谅解。