| 
 
| crypto isakmp policy 106 P9 R' g2 }, M! n0 _  w encr 3des6 B$ N5 L4 F2 Z% r. k* r' M
 authentication pre-share
 : J* \6 }3 a) S  D, q7 g2 x$ O. {5 vgroup 2
 7 d' R, w( @& B, S( D2 ^crypto isakmp key cisco address 10.1.12.2 255.255.255.0
 , D# s( z' o9 m; {, r1 M!& G" l4 M$ ]% C" g# B1 |+ L
 !' U) ?) v6 @5 k9 K" o
 crypto ipsec transform-set vpn esp-3des esp-sha-hmac
 - o: m5 ]( p; p8 w" Xmode transport0 s7 K# Z, H& l- g
 !8 G9 h7 |1 T  x9 M
 crypto map vpntest 1 ipsec-isakmp
 " t6 R1 Y: C1 W/ aset peer 10.1.12.2  V+ r* b" q2 f6 _  S
 set transform-set vpn
 3 I+ m/ E8 h" g) _match address 100
 / W/ \9 X+ V' [2 r$ a( i  c/ z9 n!
 ( J7 U" r3 h0 R( N!) r8 b1 `+ T, D- b
 !
 6 L- f9 T& q  x( K: T) k!+ D2 M3 C% d; u3 s" K, j) N
 interface Loopback0
 6 R5 Q0 l8 X) c* h! Hip address 1.1.1.1 255.255.255.0
 3 r% E) _8 A( s, L& N) U% B& g5 ^!
 # |0 K( r% b# J8 e# ainterface Ethernet0/0% ?& N) ^3 ?0 D# c- H( l
 ip address 10.1.12.1 255.255.255.0" F3 _* r) Z! B( o$ b5 P
 half-duplex8 }5 u$ o; J1 x) G( X* d7 f
 crypto map vpntest4 q) F0 z3 U5 O! s# @
 
 ; }: w7 H( I4 F3 N4 ~access-list 100 permit ip host 1.1.1.1 host 2.2.2.2
 7 E8 o8 D  M& F$ Z0 m
 % f/ q( o+ g1 S( }) vR2的配置大部分相同,以下几条不同:
 $ i$ i$ S: x- Naccess-list 100 permit ip host 2.2.2.2 host 1.1.1.16 O; B% B1 ?& w2 p6 V+ y
 
 7 l7 ]) k2 A- K" w& x; s4 _4 {crypto isakmp key cisco address 10.1.12.1 255.255.255.0
 $ c# C0 f% {# _/ s1 H9 u( c) V9 J
 $ D/ P& v$ Y# W- Ucrypto map vpntest 1 ipsec-isakmp
 - G; C8 r9 U# bset peer 10.1.12.1
 8 ]& H3 d3 U) a5 ^# Z) I4 dset transform-set vpn
 ! y' {% @, u) G  E( v3 h, y) gmatch address 100
 ; W  m$ @2 X( v8 _" ^% k
 , i% S8 \- d8 Y$ |" a# ?这么做不能通信,请问是什么原因导致.
 : A' b/ n/ E* P3 @# }) ^4 Xsh cry isa sa ' z) J* s0 ^* x& C/ e) N# o$ [
 发现什么都建立不起来
 | 
 |