I think I made the mail server mail only go to Hong Kong because there are restrictions on taking. But so ineffective strategy. Please look at the old door what it is. Thank you!
ZHF3750#show ver
Cisco IOS Software, C3750 Software (C3750-ADVIPSERVICESK9-M), Version 12.2 (25) SE
E1, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2006 by Cisco Systems, Inc.
Compiled by yenanh Mon 08:52 22-May-06
Image text-base : 0x00003000, data-0x01255B58 :
ROM : Bootstrap program is C3750 boot loader
BOOTLDR : C3750 Boot Loader (C3750-HBOOT-M) Version 12.1 (14r) EA1a, RELEASE SOFTWA
RE (fc1)
ZHF3750 uptime is 17 hours, 29 minutes
System returned to ROM by power-on
System image file is "flash:c3750-advipservicesk9-mz.122-25.SEE1/c3750-advipserv
Icesk9-mz.122-25.SEE1.bin "
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
Use. Delivery of Cisco cryptographic products does not imply
Third-authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
Compliance with U.S. and local country laws. By using this product you
Agree to comply with applicable laws and regulations. If you are unable
To comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at :
Http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
Export@cisco.com.
Creating WS-C3750G-24T (PowerPC405) processor (revision G0) with 118784K/12280K byt
Es of memory.
Processor board ID CAT0913K2JT
Last reset from power-on
12 Virtual Ethernet interfaces
24 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.
Flash-simulated non-volatile configuration 512K bytes of memory.
Base ethernet MAC Address : 00:13:C3:82:9E:80
Motherboard assembly number : 73-8046-08
Power supply part number : 341-0048-01
Motherboard serial number : CAT09140NAW
Power supply serial number : DTH090921F1
Model revision number : G0
Motherboard revision number : A0
Model number : WS-C3750G-24T-S
System serial number : CAT0913K2JT
Hardware Board Revision Number : 0x05
SW SW Version Switch Ports Model Image
------ ----- ----- ---------- ----------
WS-C3750G-24T * 1 24 12.2 (25) SEE1 C3750-ADVIPSERVICESK
3750#show run
Configuration register is 0xF
Switch one provision ws-c3750g-24t
Vtp domain ZHFENG
Vtp transparent mode
Ip subnet-zero
Ip routing
Ip host 192.168.100.34 ZHF
No file verify auto
Spanning-tree mode pvst
No spanning-tree optimize bpdu transmission
Spanning-tree extend system-id
!
Vlan internal allocation policy ascending
!
Vlan 2
Name server
!
Vlan 3
Name GENERAL
!
Vlan 4
Name HR&ADMIN
!
Vlan 5
Name FINANCE
!
Vlan 6
Name Prod&Eng
!
Vlan 7
R & D name
!
Vlan 8
Name SALES
!
Vlan 9
CCTV name
!
Vlan 10
TELEPHONE name
!
Vlan 15
Name telephone
!
Vlan 88
Name upvlan88
!
Vlan 89
Name HK-MPLS
!
!
Interface GigabitEthernet1/0/1
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/2
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/3
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/4
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/5
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/6
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/7
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/8
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/9
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/10
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/11
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/12
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/13
Switchport trunk encapsulation dot1q
Switchport mode trunk
!
Interface GigabitEthernet1/0/14
Description s-14
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,2
Switchport mode trunk
!
Interface GigabitEthernet1/0/15
Description s-15
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,2
Switchport mode trunk
!
Interface GigabitEthernet1/0/16
Switchport access vlan 2
Switchport mode access
Spanning-tree portfast
!
Interface GigabitEthernet1/0/17
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,3
Switchport mode trunk
!
Interface GigabitEthernet1/0/18
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,3
Switchport mode trunk
!
Interface GigabitEthernet1/0/19
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,3
Switchport mode trunk
!
Interface GigabitEthernet1/0/20
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,3
Switchport mode trunk
!
Interface GigabitEthernet1/0/21
Switchport trunk encapsulation dot1q
Switchport trunk allowed vlan 1,2
Switchport mode trunk
!
Interface GigabitEthernet1/0/22
!
Interface GigabitEthernet1/0/23
Switchport access vlan 89
Switchport mode access
Spanning-tree portfast
!
Interface GigabitEthernet1/0/24
Description UPLINKROUTER
Switchport access vlan 88
Switchport mode access
Speed 100
Full duplex
Flowcontrol receive on
!
Interface Vlan1
Ip address 192.168.100.35 255.255.255.224
!
Interface Vlan2
Ip address 192.168.101.1 255.255.255.0
No ip unreachables
No ip route-cache cef
Ip route-map mail policy
!
Interface Vlan3
Ip address 192.168.102.1 255.255.255.0
Ip 123 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan4
Ip address 192.168.103.1 255.255.255.0
Ip 124 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan5
Ip address 192.168.104.1 255.255.255.0
Ip 125 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan6
Ip address 192.168.105.1 255.255.255.0
Ip 126 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan7
Ip address 192.168.106.1 255.255.255.0
Ip 127 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan8
Ip address 192.168.107.1 255.255.255.0
Ip 128 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan9
Ip address 192.168.108.1 255.255.255.0
Ip 129 in access-group
Ip helper-address 192.168.100.35
!
Interface Vlan10
Ip address 192.168.252.1 255.255.255.0
!
Interface Vlan88
Ip address 192.168.100.2 255.255.255.252
!
Interface Vlan89
Ip address 192.168.100.254 255.255.255.252
Ip helper-address 192.168.100.34
!
Ip classless
192.168.100.1 ip route 0.0.0.0 0.0.0.0
Ip route 0.0.0.0 0.0.0.0 192.168.100.253 10
255.255.255.0 ip route 191.100.20.0 192.168.100.253
Ip route 203.194.130.139 255.255.255.255 192.168.100.253
Ip route 210.177.52.51 255.255.255.255 192.168.100.253
Ip http server
Ip http secure-server
!
!
Access-list 111 permit tcp any SMTP host 192.168.101.2 eq
Access-list 124 deny 0.0.0.255 192.168.104.0 192.168.103.0 ip 0.0.3.255
Access-list 124 deny 0.0.0.255 192.168.108.0 192.168.103.0 ip 0.0.0.255
Access-list 124 deny 0.0.0.255 192.168.102.0 192.168.103.0 ip 0.0.0.255
Access-list 124 deny 0.0.0.255 192.168.100.32 192.168.103.0 ip 0.0.0.31
124 permit ip any any access-list
Access-list 125 deny 0.0.0.255 192.168.105.0 192.168.104.0 ip 0.0.0.255
Access-list 125 deny 0.0.0.255 192.168.108.0 192.168.104.0 ip 0.0.0.255
Access-list 125 deny 0.0.0.255 192.168.107.0 192.168.104.0 ip 0.0.0.255
Access-list 125 deny 0.0.0.255 192.168.106.0 192.168.104.0 ip 0.0.0.255
Access-list 125 deny 0.0.0.255 192.168.100.32 192.168.104.0 ip 0.0.0.31
Access-list 125 deny 0.0.0.255 192.168.102.0 192.168.104.0 ip 0.0.0.255
Access-list 125 deny 0.0.0.255 192.168.103.0 192.168.104.0 ip 0.0.0.255
125 permit ip any any access-list
Access-list 126 deny 0.0.0.255 192.168.106.0 192.168.105.0 ip 0.0.0.255
Access-list 126 deny 0.0.0.255 192.168.108.0 192.168.105.0 ip 0.0.0.255
Access-list 126 deny 0.0.0.255 192.168.107.0 192.168.105.0 ip 0.0.0.255
Access-list 126 deny 0.0.0.255 192.168.104.0 192.168.105.0 ip 0.0.0.255
Access-list 126 deny 0.0.0.255 192.168.100.32 192.168.105.0 ip 0.0.0.31
Access-list 126 deny 0.0.0.255 192.168.102.0 192.168.105.0 ip 0.0.0.255
Access-list 126 deny 0.0.0.255 192.168.103.0 192.168.105.0 ip 0.0.0.255
126 permit ip any any access-list
Access-list 127 deny 0.0.0.255 192.168.105.0 192.168.106.0 ip 0.0.0.255
Access-list 127 deny 0.0.0.255 192.168.108.0 192.168.106.0 ip 0.0.0.255
Access-list 127 deny 0.0.0.255 192.168.107.0 192.168.106.0 ip 0.0.0.255
Access-list 127 deny 0.0.0.255 192.168.104.0 192.168.106.0 ip 0.0.0.255
Access-list 127 deny 0.0.0.255 192.168.100.32 192.168.106.0 ip 0.0.0.31
Access-list 127 deny 0.0.0.255 192.168.102.0 192.168.106.0 ip 0.0.0.255
Access-list 127 deny 0.0.0.255 192.168.103.0 192.168.106.0 ip 0.0.0.255
127 permit ip any any access-list
Access-list 128 deny 0.0.0.255 192.168.105.0 192.168.107.0 ip 0.0.0.255
Access-list 128 deny 0.0.0.255 192.168.108.0 192.168.107.0 ip 0.0.0.255
Access-list 128 deny 0.0.0.255 192.168.104.0 192.168.107.0 ip 0.0.0.255
Access-list 128 deny 0.0.0.255 192.168.106.0 192.168.107.0 ip 0.0.0.255
Access-list 128 deny 0.0.0.255 192.168.100.32 192.168.107.0 ip 0.0.0.31
Access-list 128 deny 0.0.0.255 192.168.102.0 192.168.107.0 ip 0.0.0.255
Access-list 128 deny 0.0.0.255 192.168.103.0 192.168.107.0 ip 0.0.0.255
128 permit ip any any access-list
Access-list 129 deny 0.0.0.255 192.168.105.0 192.168.108.0 ip 0.0.0.255
Access-list 129 deny 0.0.0.255 192.168.104.0 192.168.108.0 ip 0.0.0.255
Access-list 129 deny 0.0.0.255 192.168.107.0 192.168.108.0 ip 0.0.0.255
Access-list 129 deny 0.0.0.255 192.168.106.0 192.168.108.0 ip 0.0.0.255
Access-list 129 deny 0.0.0.255 192.168.100.32 192.168.108.0 ip 0.0.0.31
Access-list 129 deny 0.0.0.255 192.168.102.0 192.168.108.0 ip 0.0.0.255
Access-list 129 deny 0.0.0.255 192.168.103.0 192.168.108.0 ip 0.0.0.255
129 permit ip any any access-list
Route-map mail permit 10
Match ip address 111
Set ip next-hop 192.168.100.253
!
Route-map mail permit 20
!
!
Control-plane
!
!
Line con 0
Password 8250@szhq
Line vty 0 4
Password 8250@szhq
Login
Line vty 5 15
Password 8250@szhq
Login
!
End
Routing main distribution strategy
Ip local policy route-map mail
Access-list 111 permit tcp any eq SMTP host 192.168.101.2
Interface Vlan2
Ip address 192.168.101.1 255.255.255.0
No ip unreachables
No ip route-cache cef
Ip route-map mail policy
Route-map mail permit 10
Match ip address 111
Set ip next-hop 192.168.100.253
!
Route-map mail permit 20
Ip policy route-map mail and sometimes not write into the DCT VLAN 2. I do not know why, oh