Vlan på Cisco 3560
HejJeg sidder på et netværk med en masse vlans. Jeg skal have
en windows 2003 server på vlan2, alle vlans skal have adgang til serveren men jeg kan ikke melde dem ind i domænet.
Jeg er sikker på et er en policies som ikke er rigtig. Kan nogen hjælpe mig ?
!
interface Vlan2
ip address 192.168.2.10 255.255.255.0
!
interface Vlan10
ip address 192.168.10.10 255.255.255.0
ip access-group 120 in
!
interface Vlan11
ip address 192.168.11.10 255.255.255.0
ip access-group 120 in
!
interface Vlan12
ip address 192.168.12.10 255.255.255.0
ip access-group 130 in
!
interface Vlan13
ip address 192.168.13.10 255.255.255.0
ip access-group 120 in
!
interface Vlan14
ip address 192.168.14.10 255.255.255.0
ip access-group 120 in
!
interface Vlan15
ip address 192.168.15.10 255.255.255.0
ip access-group 120 in
!
interface Vlan16
ip address 192.168.16.10 255.255.255.0
ip access-group 120 in
!
interface Vlan17
ip address 192.168.17.10 255.255.255.0
ip access-group 120 in
!
interface Vlan18
ip address 192.168.18.10 255.255.255.0
ip access-group 120 in
!
interface Vlan19
ip address 192.168.19.10 255.255.255.0
ip access-group 120 in
!
interface Vlan20
ip address 192.168.20.10 255.255.255.0
ip access-group 120 in
!
interface Vlan21
ip address 192.168.21.10 255.255.255.0
ip access-group 120 in
!
interface Vlan22
ip address 192.168.22.10 255.255.255.0
ip access-group 120 in
!
interface Vlan23
ip address 192.168.23.10 255.255.255.0
ip access-group 120 in
!
interface Vlan24
ip address 192.168.24.10 255.255.255.0
ip access-group 120 in
!
interface Vlan25
ip address 192.168.25.10 255.255.255.0
ip access-group 120 in
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.2.1
ip http server
!
access-list 120 permit udp any any eq bootpc
access-list 120 permit udp any any eq bootps
access-list 120 permit udp any any eq domain
access-list 120 permit udp any eq domain any
access-list 120 permit ip any 192.168.2.0 0.0.0.255
access-list 120 permit icmp any any
access-list 120 deny ip any 192.168.0.0 0.0.255.255
access-list 120 permit ip any any
access-list 130 permit udp any any eq bootpc
access-list 130 permit udp any any eq bootps
access-list 130 permit udp any any eq domain
access-list 130 permit udp any eq domain any
access-list 130 permit ip any 192.168.2.0 0.0.0.255
access-list 130 permit ip 192.168.12.0 0.0.0.255 host 192.168.200.30
access-list 130 permit icmp any any
access-list 130 deny ip any 192.168.0.0 0.0.255.255
access-list 130 permit ip any any