Router10(Tunnel100) Router(config)#interface Tunnel100 Router(config-if)# %LINK-5-CHANGED: Interface Tunnel100, changed state to up Router(config-if)#ip address 100.100.100.1 255.255.255.0 Router(config-if)#tunnel source gi0/2 Router(config-if)#tunnel destination 11.11.11.21 Router(config)#int gi0/2 Router(config-if)#ip nat outside Router(config-if)#ex Router(config)#int gi0/0 Router(config-if)#ip nat inside Router(config-if)#ex Router(config)#int gi 0/1 Router(config-if)#ip nat inside Router(config-if)#ex Router(config)#ip nat inside source list FOR-NAT interface gi0/2 overload Router(config)#ip route 0.0.0.0 0.0.0.0 11.11.11.18 Router(config)#ip route 172.16.0.0 255.255.128.0 100.100.100.2 Router(config)#ip route 172.16.128.0 255.255.128.0 100.100.100.2 Router(config)#ip route 10.0.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.32.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.64.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.96.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.128.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.160.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.192.0.0 255.224.0.0 100.100.100.2 Router(config)#ip route 10.224.0.0 255.224.0.0 100.100.100.2 Router(config)#ip access-list extended FOR-NAT Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 172.16.0.0 0.0.127.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 172.16.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 172.16.0.0 0.0.127.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 172.16.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.0.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.32.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.64.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.96.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.128.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.160.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.192.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.0.0 0.0.3.255 10.224.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.0.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.32.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.64.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.96.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.128.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.160.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.192.0.0 0.31.255.255 Router(config-ext-nacl)#deny ip 192.168.128.0 0.0.127.255 10.224.0.0 0.31.255.255 Router(config-ext-nacl)#permit ip 192.168.0.0 0.0.3.255 any Router(config-ext-nacl)#permit ip 192.168.128.0 0.0.127.255 any Router(config-ext-nacl)# Router9(Tunnel100) Router(config)#interface Tunnel100 Router(config-if)# %LINK-5-CHANGED: Interface Tunnel100, changed state to up Router(config-if)#ip address 100.100.100.2 255.255.255.0 Router(config-if)#tunnel source gi0/2 Router(config-if)#tunnel destination 11.11.11.17 Router(config)#int gi0/2 Router(config-if)#ip nat outside Router(config-if)#ex Router(config)#int gi0/1 Router(config-if)#ip nat inside Router(config-if)#ex Router(config)#int gi0/0 Router(config-if)#ip nat inside Router(config-if)#ex Router(config)#ip nat inside source list FOR-NAT interface gi0/2 overload Router(config)#ip nat inside source static tcp 199.24.12.2 80 11.11.11.21 80 Router(config)#ip route 0.0.0.0 0.0.0.0 11.11.11.22 Router(config)#ip route 192.168.128.0 255.255.128.0 100.100.100.1 Router(config)#ip route 192.168.0.0 255.255.252.0 100.100.100.1 Router(config)#ip access-list extended FOR-NAT Router(config-ext-nacl)#deny ip 10.0.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.32.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.64.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.96.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.128.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.160.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.192.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.224.0.0 0.31.255.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 172.16.0.0 0.0.127.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 172.16.128.0 0.0.127.255 192.168.128.0 0.0.127.255 Router(config-ext-nacl)#deny ip 10.0.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.32.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.64.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.96.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.128.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.160.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.192.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 10.224.0.0 0.31.255.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 172.16.0.0 0.0.127.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#deny ip 172.16.128.0 0.0.127.255 192.168.0.0 0.0.3.255 Router(config-ext-nacl)#permit ip 10.0.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.32.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.64.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.96.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.128.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.160.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.192.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 10.224.0.0 0.31.255.255 any Router(config-ext-nacl)#permit ip 172.16.0.0 0.0.127.255 any Router(config-ext-nacl)#permit ip 172.16.128.0 0.0.127.255 any