Hi nochmal,
hab die regel allow-VNC erstellt, kann sie aber erst morgen abend testen.
sollte wenn es geht auch über die vpn laufen, währe genial wenn das geht!
über die vpn möchte ich das ip-phone und in 2 freigaben in der firma was up- und downloaden.
ich hab da eine detewe openoffice x 320 die ip-telefonie isdn, router mit vpn, und sip telefonie macht, da muss ich auch mal drüber....
die router anpingen geht über vpn und internet.
das ergabniss von dem readscript wie folgt:
(passwörter und keys sind +++++)
____________________________________________________________
#
| LANCOM 1821+ Wireless ADSL (Ann.B)
| Ver. 7.26.0049 / 22.11.2007 / 6.26/e74.02.41.2
| SN. 076781800031
| Copyright (c) LANCOM Systems
Connection No.: 002 (LAN)
Password:
root@:/
> cd setup
root@:/Setup
> readscript
# Script (7.26.0049 / 22.11.2007) (0x0020411d;0x0c000063)
lang English
flash No
cd /Setup/WAN/Dialup-Peers
del *
tab Peer Dialup-remote B1-DT B2-DT WAN-layer
Callback
add "DEFAULT" "" 20 20 ""
No
add "FIRMA" "" 90 90 "FIRMA"
No
cd /
cd /Setup/WAN/Layer
del *
tab WAN-layer Encaps. Lay-3 Lay-2 L2-Opt. Lay-1
add "DEFAULT" TRANS PPP TRANS bnd+cmpr HDLC64K
add "T-ISDN" TRANS PPP TRANS none HDLC64K
add "MLPPP" TRANS PPP TRANS bnd+cmpr HDLC64K
add "PPPHDLC" TRANS PPP TRANS none HDLC64K
add "RAWHDLC" TRANS TRANS TRANS none HDLC64K
add "T-ADSL" LLC-MUX PPP PPPoE none AAL-5
add "PPPOEOA" LLC-MUX PPP PPPoE none AAL-5
add "PPPOA" LLC-MUX PPP TRANS none AAL-5
add "IPOEOA" LLC-ETH TRANS TRANS none AAL-5
add "IPOA" LLC-MUX TRANS TRANS none AAL-5
add "DHCPOEOA" LLC-ETH DHCP TRANS none AAL-5
add "DHCPOA" LLC-MUX DHCP TRANS none AAL-5
add "T-DSL" TRANS PPP PPPoE none ETH
add "PPPOE" TRANS PPP PPPoE none ETH
add "IPOE" ETHER TRANS TRANS none ETH
add "DHCPOE" ETHER DHCP TRANS none ETH
add "V.24_DEF" TRANS APPP TRANS none SERIAL
add "INTERNET" LLC-MUX PPP PPPoE none AAL-5
cd /
cd /Setup/WAN/PPP
del *
tab Peer Authent. Key Time Try Conf Fail Term Usernam
e Rights
add "DEFAULT" PAP "" 0 5 10 5 2 ""
none
add "INTERNET" none "20070807002" 5 5 10 5 2 "X
000+++++@mdsl.mnet-online.de" IP
add "FIRMA" CHAP "3+++++++" 3 5 10 5 2 "P
rivat" IP
cd /
cd /Setup/WAN/DSL-Broadband-Peers
del *
tab Peer SH-Time AC-name
Servicename WAN-layer ATM-VPI ATM-VCI
MAC-Type user-def.-MAC DSL-ifc(s) VLAN-ID
add "INTERNET" 9999 ""
"" "INTERNET" 1 32
local 000000000000 "" 0
cd /
cd /Setup/WAN/MTU-List
del *
tab Peer MTU
add "INTERNET" 1492
add "FIRMA" 1492
cd /
cd /Setup/WAN/Action-Table
del *
tab Index Active Host-Name
Peer Lock-Time Condition Action
Check-For
Owner
add 1 Yes "+++++++++++.DYNDNS.ORG"
"INTERNET" 2160000 Establish "http://++++:++++++++
+@members.dyndns.org/nic/update?system=dyndns&hostname=%h&myip=%a&wildcard=NOCHG
&mx=++++++++.dyndns.org&backmx=NO"
"contains=good %a?
skipiftrue=2" "root"
add 2 Yes "+++.DYNDNS.ORG"
"INTERNET" 0 Establish "dnscheck:+++.dyndns.org"
"isequal=%a?skipif
true=1" "root"
add 3 Yes "+++.DYNDNS.ORG"
"INTERNET" 900 Establish "http://+++:+++++++
+@members.dyndns.org/nic/update?system=dyndns&hostname=%h&myip=%a&wildcard=NOCHG
&mx=++++.dyndns.org&backmx=NO"
"contains=good %a"
"root"
add 4 Yes "+++.DYNDNS.ORG"
"INTERNET" 0 Establish "repeat:300"
""
"root"
cd /
cd /Setup/WAN/Router-Interface
tab Ifc MSN/EAZ YC. CLIP Accept-calls
set S0-1 "" Yes Yes none
set EXT "" Yes Yes all
cd /
set /Setup/Charges/Budget-Units 0
set /Setup/Charges/Dialup-Minutes-Budget 0
set /Setup/Charges/DSL-Broadband-Minutes-Budget 0
cd /Setup/LAN/IEEE802.1x/Supplicant-Ifc-Setup
tab Ifc Method Credentials
set LAN-1 none ""
set LAN-2 none ""
set LAN-3 none ""
set LAN-4 none ""
cd /
cd /Setup/TCP-IP/Network-list
del *
tab Network-name IP-Address IP-Netmask VLAN-ID Interface Sr
c-check Type Rtg-tag Comment
add "INTRANET" 192.168.102.254 255.255.255.0 0 any lo
ose Intranet 0 "local intranet"
add "DMZ" 0.0.0.0 255.255.255.0 0 any lo
ose DMZ 0 "demilitarized zone"
cd /
cd /Setup/IP-Router/IP-Routing-Table
del *
tab IP-Address IP-Netmask Rtg-tag Peer-or-IP Distance Masq
uerade Active Comment
add 192.168.101.0 255.255.255.0 0 "FIRMA" 0 No
Yes ""
add 192.168.0.0 255.255.0.0 0 "0.0.0.0" 0 No
Yes "block private networks: 192.168.x.y"
add 172.16.0.0 255.240.0.0 0 "0.0.0.0" 0 No
Yes "block private networks: 172.16-31.x.y"
add 10.0.0.0 255.0.0.0 0 "0.0.0.0" 0 No
Yes "block private network: 10.x.y.z"
add 224.0.0.0 224.0.0.0 0 "0.0.0.0" 0 No
Yes "block multicasts: 224-255.x.y.z"
add 255.255.255.255 0.0.0.0 0 "INTERNET" 0 on
Yes ""
cd /
cd /Setup/IP-Router/1-N-NAT/Service-Table
del *
tab D-port-from D-port-to Protocol Peer WAN-Address Int
ranet-Addres Map-Port Active Comment
add 5500 5500 TCP+UDP "DEFAULT" 0.0.0.0 192
.168.102.10 5500 Yes "VNC1"
add 5800 5800 TCP+UDP "DEFAULT" 0.0.0.0 192
.168.102.10 5800 Yes "VNC1"
add 5900 5900 TCP+UDP "DEFAULT" 0.0.0.0 192
.168.102.10 5900 Yes "VNC1"
cd /
cd /Setup/IP-Router/Firewall/Actions
del *
tab Name Description
add "ACCEPT" "%A"
add "DROP" "%D"
add "REJECT" "%R"
add "NO-CONNECT" "@C%R"
add "NO-INTERNET" "@I%R"
cd /
cd /Setup/IP-Router/Firewall/Objects
del *
tab Name Description
add "ANY" ""
add "ANYHOST" "%A0.0.0.0 %M0.0.0.0"
add "LOCALNET" "%L"
add "ICMP" "%P1"
add "TCP" "%P6"
add "FTP" "%P6 %S21"
add "MAIL" "%P6 %S25,110,143"
add "HTTP" "%P6 %S80,443"
add "NEWS" "%P6 %S119"
add "UDP" "%P17"
add "TFTP" "%P17 %S69"
add "IPSEC" "%P17 %S500"
add "ESP" "%P50"
add "AH" "%P51"
add "IPCOMP" "%P108"
add "DNS" "%S53"
add "NETBIOS" "%S137-139"
add "PPTP" "%P6 %S1723"
add "FTP-ANYHOST" "%S20,21 ANYHOST"
add "HTTP-HTTPS" "%S80,443,8008,8080 ANYHOST"
cd /
cd /Setup/IP-Router/Firewall/Rules
del *
tab Name Prot. Source
Destination Action
Linked Prio Firewall- VPN-Rule Stateful Rtg-tag Comment
add "ALLOW-VPN-ROUTING" "ANY" "ANYHOST"
"ANYHOST" "%Lcds0 @v %A"
No 1 Yes No Yes 0 ""
add "WINS" "TCP,UDP" "%S137-139 ANYHOST"
"ANYHOST" "%Lcds0 %R %N"
No 0 Yes
set "P2P-1-6" Yes
set "WLAN-1-2" Yes
set "WLAN-1-3" Yes
set "WLAN-1-4" Yes
set "WLAN-1-5" Yes
set "WLAN-1-6" Yes
set "WLAN-1-7" Yes
set "WLAN-1-8" Yes
set "LAN-2" Yes
set "LAN-3" Yes
set "LAN-4" Yes
cd /
cd /Setup/Config/Access-Table
tab Ifc. Telnet TFTP HTTP SNMP HTTPS Telnet-SSL SSH
set LAN Yes Yes Yes Yes Yes Yes Yes
set WAN Yes Yes Yes Yes Yes Yes Yes
set WLAN No No No No No No No
cd /
set /Setup/WLAN/Country Germany
set /Setup/WLAN/Inter-Station-Traffic globally-off
cd /Setup/WLAN/Radar-Pattern-Thresholds
tab Pattern-pps Threshold
set 700 8
set 1800 6
set 330 15
cd /
set /Setup/Time/Fetch-Method NTP
set /Setup/VPN/Operating yes
cd /Setup/VPN/VPN-Peers
del *
tab Peer SH-Time Extranet-Address Remote-Gw
Rtg-tag Layer dynamic I
KE-Exchange Rule-creation DPD-Inact-Timeout IKE-CFG
add "FIRMA" 9999 0.0.0.0 "copytec1.dyndns.org"
0 "FIRMA" No M
ain-Mode auto 60 Off
cd /
cd /Setup/VPN/Layer
del *
tab Name PFS-Grp IKE-Grp IKE-Prop-List IPSEC-Prop-List
IKE-Key
add "FIRMA" 5 5 "WIZ-IKE-PRESH-KEY" "IPS-FIRMA"
"FIRMA"
cd /
cd /Setup/VPN/Proposals/IKE
del *
tab Name IKE-Crypt-Alg IKE-Crypt-Keylen IKE-Auth-Alg IK
E-Auth-Mode Lifetime-Sec Lifetime-KB
add "PSK-AES-MD5" AES-CBC 128 MD5 Pr
eshared-Key 8000 0
add "PSK-AES-SHA" AES-CBC 128 SHA1 Pr
eshared-Key 8000 0
add "PSK-BLOW-MD5" BLOWFISH-CBC 128 MD5 Pr
eshared-Key 8000 0
add "PSK-BLOW-SHA" BLOWFISH-CBC 128 SHA1 Pr
eshared-Key 8000 0
add "PSK-CAST-MD5" CAST128-CBC 128 MD5 Pr
eshared-Key 8000 0
add "PSK-CAST-SHA" CAST128-CBC 128 SHA1 Pr
eshared-Key 8000 0
add "PSK-3DES-MD5" 3DES-CBC 168 MD5 Pr
eshared-Key 8000 0
add "PSK-3DES-SHA" 3DES-CBC 168 SHA1 Pr
eshared-Key 8000 0
add "PSK-DES-MD5" DES-CBC 56 MD5 Pr
eshared-Key 8000 0
add "PSK-DES-SHA" DES-CBC 56 SHA1 Pr
eshared-Key 8000 0
add "RSA-AES-MD5" AES-CBC 128 MD5 RS
A-Signature 8000 0
add "RSA-AES-SHA" AES-CBC 128 SHA1 RS
A-Signature 8000 0
add "RSA-BLOW-MD5" BLOWFISH-CBC 128 MD5 RS
A-Signature 8000 0
add "RSA-BLOW-SHA" BLOWFISH-CBC 128 SHA1 RS
A-Signature 8000 0
add "RSA-CAST-MD5" CAST128-CBC 128 MD5 RS
A-Signature 8000 0
add "RSA-CAST-SHA" CAST128-CBC 128 SHA1 RS
A-Signature 8000 0
add "RSA-3DES-MD5" 3DES-CBC 168 MD5 RS
A-Signature 8000 0
add "RSA-3DES-SHA" 3DES-CBC 168 SHA1 RS
A-Signature 8000 0
add "RSA-DES-MD5" DES-CBC 56 MD5 RS
A-Signature 8000 0
add "RSA-DES-SHA" DES-CBC 56 SHA1 RS
A-Signature 8000 0
add "WIZ-PSK-AES-MD5" AES-CBC 128 MD5 Pr
eshared-Key 108000 0
add "WIZ-PSK-AES-SHA" AES-CBC 128 SHA1 Pr
eshared-Key 108000 0
add "WIZ-PSK-BLOW-MD5" BLOWFISH-CBC 128 MD5 P
reshared-Key 108000 0
add "WIZ-PSK-BLOW-SHA" BLOWFISH-CBC 128 SHA1 P
reshared-Key 108000 0
add "WIZ-PSK-3DES-MD5" 3DES-CBC 168 MD5 P
reshared-Key 108000 0
add "WIZ-PSK-3DES-SHA" 3DES-CBC 168 SHA1 P
reshared-Key 108000 0
add "WIZ-PSK-CAST-MD5" CAST128-CBC 128 MD5 P
reshared-Key 108000 0
add "WIZ-PSK-CAST-SHA" CAST128-CBC 128 SHA1 P
reshared-Key 108000 0
cd /
cd /Setup/VPN/Proposals/IPSEC
del *
tab Name Encaps-Mode ESP-Crypt-Alg ESP-Crypt-Keylen ES
P-Auth-Alg AH-Auth-Alg IPCOMP-Alg Lifetime-Sec Lifetime-K
B
add "TN-AES-MD5-96" Tunnel AES-CBC 128 HM
AC-MD5 none none 2000 200000
add "TN-AES-SHA-96" Tunnel AES-CBC 128 HM
AC-SHA1 none none 2000 200000
add "TN-BLOW-MD5-96" Tunnel BLOWFISH-CBC 128 HM
AC-MD5 none none 2000 200000
add "TN-BLOW-SHA-96" Tunnel BLOWFISH-CBC 128 HM
AC-SHA1 none none 2000 200000
add "TN-CAST-MD5-96" Tunnel CAST128-CBC 128 HM
AC-MD5 none none 2000 200000
add "TN-CAST-SHA-96" Tunnel CAST128-CBC 128 HM
AC-SHA1 none none 2000 200000
add "TN-3DES-MD5-96" Tunnel 3DES-CBC 168 HM
AC-MD5 none none 2000 200000
add "TN-3DES-SHA-96" Tunnel 3DES-CBC 168 HM
AC-SHA1 none none 2000 200000
add "TN-DES-MD5-96" Tunnel DES-CBC 56 HM
AC-MD5 none none 2000 200000
add "TN-DES-SHA-96" Tunnel DES-CBC 56 HM
AC-SHA1 none none 2000 200000
add "WIZ-TN-AES-MD5-96" Tunnel AES-CBC 128
HMAC-MD5 none none 2000 200000
add "WIZ-TN-BLW-SHA-96" Tunnel BLOWFISH-CBC 128
HMAC-SHA1 none none 2000 200000
add "WIZ-TN-3DS-MD5-96" Tunnel 3DES-CBC 168
HMAC-MD5 none none 2000 200000
add "WIZ-TN-3DS-SHA-96" Tunnel 3DES-CBC 168
HMAC-SHA1 none none 2000 200000
add "WIZ-TN-BLWSHA-SHA" Tunnel BLOWFISH-CBC 128
HMAC-SHA1 HMAC-SHA1 none 2000 200000
cd /
cd /Setup/VPN/Proposals/IKE-Proposal-Lists
del *
tab IKE-Proposal-List IKE-Proposal-1 IKE-Proposal-2 IKE-Proposal-3
IKE-Proposal-4 IKE-Proposal-5 IKE-Proposal-6 IKE-Proposal-7 IKE
-Proposal-8
add "IKE_PRESH_KEY" "PSK-AES-MD5" "PSK-AES-SHA" "PSK-BLOW-MD5"
"PSK-BLOW-SHA" "PSK-CAST-MD5" "PSK-CAST-SHA" "PSK-3DES-MD5" "PS
K-3DES-SHA"
add "IKE_RSA_SIG" "RSA-AES-MD5" "RSA-AES-SHA" "RSA-BLOW-MD5"
"RSA-BLOW-SHA" "RSA-CAST-MD5" "RSA-CAST-SHA" "RSA-3DES-MD5" "RS
A-3DES-SHA"
add "WIZ-IKE-PRESH-KEY" "WIZ-PSK-AES-MD5" "WIZ-PSK-AES-SHA" "WIZ-PSK-BLOW-MD
5" "WIZ-PSK-BLOW-SHA" "WIZ-PSK-3DES-MD5" "WIZ-PSK-3DES-SHA" "WIZ-PSK-CAST-MD
5" "WIZ-PSK-CAST-SHA"
cd /
cd /Setup/VPN/Proposals/IPSEC-Proposal-Lists
del *
tab IPSEC-Proposal-List IPSEC-Proposal-1 IPSEC-Proposal-2 IPSEC-Proposal-3
IPSEC-Proposal-4 IPSEC-Proposal-5 IPSEC-Proposal-6 IPSEC-Proposal-7 I
PSEC-Proposal-8
add "ESP_TN" "TN-AES-MD5-96" "TN-AES-SHA-96" "TN-BLOW-MD5-96"
"TN-BLOW-SHA-96" "TN-CAST-MD5-96" "TN-CAST-SHA-96" "TN-3DES-MD5-96" "
TN-3DES-SHA-96"
add "IPS-FIRMA" "WIZ-TN-AES-MD5-96" "WIZ-TN-BLW-SHA-96" "WIZ-TN-BLWS
HA-SHA" "WIZ-TN-3DS-MD5-96" "WIZ-TN-3DS-SHA-96" "" ""
""
cd /
cd /Setup/VPN/Certificates-and-Keys/IKE-Keys
del *
tab Name Local-ID-Type Local-Identity
Remote-ID-Type R
emote-Identity
Shared-Sec
Shared-Sec-File
add "FIRMA" No-Identity ""
No-Identity "
"
"++++++++++++++++"
""
cd /
cd /Setup/Interfaces/WLAN/Operational
tab Ifc Operating Operation-Mode Link-LED-Function
set WLAN-1 No Access-Point Normal
cd /
cd /Setup/Interfaces/WLAN/Network
tab Ifc Operating Network-Name MAC-Filter RAD
IUS-Accounting Closed-Network Max-Stations Cl.-Brg.-Support
set WLAN-1 Yes "URSUS" Yes No
No 0 No
set WLAN-1-2 No "LANCOM" Yes No
No 0 No
set WLAN-1-3 No "LANCOM" Yes No
No 0 No
set WLAN-1-4 No "LANCOM" Yes No
No 0 No
set WLAN-1-5 No "LANCOM" Yes No
No 0 No
set WLAN-1-6 No "LANCOM" Yes No
No 0 No
set WLAN-1-7 No "LANCOM" Yes No
No 0 No
set WLAN-1-8 No "LANCOM" Yes No
No 0 No
cd /
cd /Setup/Interfaces/WLAN/Transmission
tab Ifc Packet-Size Min-Tx-Rate Max-Tx-Rate Basic-Rate Hard-
Retries Soft-Retries 11b-Preamble RTS-Threshold Min-Frag-Len
set WLAN-1 1600 Auto Auto 2M 10
0 Auto 2347 0
set WLAN-1-2 1600 Auto Auto 2M 10
0 Auto 2347 16
set WLAN-1-3 1600 Auto Auto 2M 10
0 Auto 2347 16
set WLAN-1-4 1600 Auto Auto 2M 10
0 Auto 2347 16
set WLAN-1-5 1600 Auto Auto 2M 10
0 Auto 2347 16
set WLAN-1-6 1600 Auto Auto 2M 10
0 Auto 2347 16
set WLAN-1-7 1600 Auto Auto 2M 10
0 Auto 2347 16
set WLAN-1-8 1600 Auto Auto 2M 10
0 Auto 2347 16
cd /
cd /Setup/Interfaces/WLAN/Performance
tab Ifc QoS Tx-Bursting Compression
set WLAN-1 No 4 No
cd /
cd /Setup/Interfaces/WLAN/Encryption
tab Ifc Encryption Default-Key Method Key
WPA-Version WPA-S
ession-Keytypes WPA-Rekeying-Cycle Client-EAP-Method Authentication
set WLAN-1 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 0 Open-System
set WLAN-1-2 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
set WLAN-1-3 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
set WLAN-1-4 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
set WLAN-1-5 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
set WLAN-1-6 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
set WLAN-1-7 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
set WLAN-1-8 Yes 1 WEP-104-Bits "L00A0
57129927" WPA1 TKIP/
AES 0 TLS Open-System
cd /
cd /Setup/Interfaces/WLAN/Group-Encryption-Keys
tab Ifc Keytype-2 Key-2
Keytype-3 Key-3
Keytype-4 Key-4
set WLAN-1 WEP-104-Bits "0x0000000000"
WEP-104-Bits "0x0000000000"
WEP-104-Bits "0x0000000000"
cd /
set /Setup/NTP/RQ-Interval 3600
cd /Setup/NTP/RQ-Address
del *
tab RQ-Address Loopback-Addr.
add "PTBTIME1.PTB.DE" ""
cd /
cd /Setup/VLAN/Networks
del *
tab Name VLAN-ID Ports
add "Default_VLAN" 1 "LAN-1,WLAN-1,P2P-1-1~P2P-1-6,WLAN-1-2~WLAN-1
-8,LAN-2~LAN-4"
cd /
flash Yes
# done
exit
root@:/Setup
>
________________________________________________________________________
Danke im voraus
Michael