Cisco IOS Cookbook 中文精简版第十二章隧道和VP…

2008-02-23 04:55:03来源:互联网 阅读 ()

新老客户大回馈,云服务器低至5折

Router1(config-if)#exit

Router1(config)#ip route 0.0.0.0 0.0.0.0 172.16.1.2

Router1(config)#ip route 192.168.15.0 255.255.255.0 192.168.1.2

Router1(config)#end

Router1#

Router2#configure terminal

Enter configuration commands, one per line. End with CNTL/Z.

Router2(config)#crypto isakmp policy 10

Router2(config-isakmp)#encr aes 256

Router2(config-isakmp)#authentication pre-share

Router2(config-isakmp)#group 2

Router2(config-isakmp)#exit

Router2(config)#crypto isakmp key TUNNELKEY01 address 172.16.1.1

Router2(config)#crypto ipsec transform-set TUNNEL-TRANSFORM ah-sha-hmac esp-aes 256

Router2(cfg-crypto-trans)#mode transport

Router2(cfg-crypto-trans)#exit

Router2(config)#crypto map TUNNELMAP 10 ipsec-isakmp

% NOTE: This new crypto map will remain disabled until a peer

and a valid access list have been configured.

Router2(config-crypto-map)#set peer 172.16.1.1

Router2(config-crypto-map)#set transform-set TUNNEL-TRANSFORM

Router2(config-crypto-map)#match address 102

Router2(config-crypto-map)#exit

Router2(config)#access-list 102 permit gre host 172.16.2.1 host 172.16.1.1

Router2(config)#interface Tunnel1

Router2(config-if)#ip address 192.168.1.2 255.255.255.252

Router2(config-if)#tunnel source 172.16.2.1

Router2(config-if)#tunnel destination 172.16.1.1

Router2(config-if)#exit

Router2(config)#interface FastEthernet0/0

Router2(config-if)#ip address 172.16.2.1 255.255.255.0

Router2(config-if)#ip access-group 101 in

Router2(config-if)#crypto map TUNNELMAP

Router2(config-if)#exit

Router2(config)#access-list 101 permit gre host 172.16.1.1 host 172.16.2.1

Router2(config)#access-list 101 permit esp host 172.16.1.1 host 172.16.2.1

Router2(config)#access-list 101 permit udp host 172.16.1.1 host 172.16.2.1 eq isakmp

Router2(config)#access-list 101 permit ahp host 172.16.1.1 host 172.16.2.1

Router2(config)#access-list 101 deny ip any any log

Router2(config)#interface Loopback0

Router2(config-if)#ip address 192.168.15.1 255.255.255.0

Router2(config-if)#exit

标签:

版权申明:本站文章部分自网络,如有侵权,请联系:west999com@outlook.com
特别注意:本站所有转载文章言论不代表本站观点,本站所提供的摄影照片,插画,设计作品,如需使用,请与原作者联系,版权归原作者所有

上一篇:Cisco IOS Cookbook 中文精简版第十三章拨号备份

下一篇:Cisco IOS Cookbook 中文精简版第十一章队列和拥塞