|
站点到站点IPSec VPN实验 基础配置学习笔记
1、底层IP Internet: interface FastEthernet0/0 ip address 202.100.1.2 255.255.255.0 duplex auto speed auto ! interface FastEthernet0/1 ip address 202.100.2.2 255.255.255.0 duplex auto speed auto R1: interface FastEthernet0/0 ip address 202.100.1.1 255.255.255.0 duplex auto speed auto ! interface FastEthernet0/1 ip address 192.168.1.254 255.255.255.0 duplex auto speed auto ! 2、配置默认路由 ip route 0.0.0.0 0.0.0.0 202.100.1.2 3、配置IPSec VPN第一阶段策略 crypto isakmp policy 10 //进入配置IPSec的isakmp策略 encr 3des //加密算法(3des) hash md5 //完整性校验算法(md5) authentication pre-share //认证算法(域共享) group 2 (组,决定了加密长度) ! crypto isakmp key cisco address 202.100.2.1 //域共享口令,进行建立隧道时做认证 ! ip access-list extended vpn //VPN加密的感兴趣流 permit ip 192.168.1.0 0.0.0.255 172.16.1.0 0.0.0.255 ! crypto ipsec transform-set cisco esp-3des esp-md5-hmac //转换集:告诉路由器,怎么处理这个加密流量,采用什么加密算法,完整性算法、源认证 ! crypto map cisco 10 ipsec-isakmp //做一个map整合策略 ,10:代表跟一个站点建立IPSec VPN,如果建立多个站点,则通过序号来区分 set peer 202.100.2.1 //跟谁建立IPSec VPN match address vpn //感兴趣流是什么(加密流量) set transform-set cisco //怎么去处理这个加密流量(转换集) ! interface FastEthernet0/0 ip address 202.100.1.1 255.255.255.0 crypto map cisco //调用在接口下 R2: interface FastEthernet0/0 ip address 202.100.2.1 255.255.255.0 duplex auto speed auto crypto map cisco ! interface FastEthernet0/1 ip address 172.16.1.254 255.255.255.0 duplex auto speed auto ip route 0.0.0.0 0.0.0.0 202.100.2.2 crypto isakmp policy 10 //进入配置IPSec的isakmp策略 encr 3des //加密算法(3des) hash md5 //完整性校验算法(md5) authentication pre-share //认证算法(域共享) group 2 (组,决定了加密长度) ! crypto isakmp key cisco address 202.100.1.1 //域共享口令,进行建立隧道时做认证 ! ip access-list extended vpn//VPN加密的感兴趣流 permit ip 172.16.1.0 0.0.0.255 192.168.1.0 0.0.0.255 ! crypto ipsec transform-set cisco esp-3des esp-md5-hmac//转换集:告诉路由器,怎么处理这个加密流量,采用什么加密算法,完整性算法、源认证 ! crypto map cisco 10 ipsec-isakmp //做一个map整合策略 ,10:代表跟一个站点建立IPSec VPN,如果建立多个站点,则通过序号来区分 set peer 202.100.1.1 //跟谁建立IPSec VPN set transform-set cisco //感兴趣流是什么(加密流量) match address vpn //怎么去处理这个加密流量(转换集) ! interface FastEthernet0/0 ip address 202.100.2.1 255.255.255.0 crypto map cisco //调用在接口下
|