
ipsec vpn不能ping成功# I; A- F" D# x. D
R1的主要配置
$ _+ o6 \' ^# }/ p! u/ mios为3640
7 Q' j" i" m+ r+ h! Z% kcrypto isakmp policy 16 [' h8 H6 x: h
hash md56 ^8 r* S1 Y& [2 r( f. M; W* X" E% A
authentication pre-share0 O; ^( B. w8 W. J& a0 I" ^
crypto isakmp key cisco address 12.1.1.2! z( e2 a7 M/ c3 n
!
3 O: ~, M' Y* `2 ]" d!
" w/ M, d4 o0 x6 F. s$ j0 q7 }crypto ipsec transform-set CCNP esp-des esp-md5-hmac
- c" K( B/ ~6 W( Z0 D9 M) C!
; p6 t# V' P' v. Tcrypto map CCIE 1 ipsec-isakmp ( i4 ^; z( h0 @: E0 {
set peer 12.1.1.2
/ B2 K9 \3 |! p# |6 x. n4 [ set transform-set ccnp
) _3 d( }+ s8 t" ]$ k match address 1014 x- G$ D1 E# c! }# E* q
!
7 c# b- I/ g4 e!
1 m, V3 A: g r5 M/ e!# ]% b Z! x1 e/ C) |: E: R7 u
!
/ y4 w+ Q3 | n- b& l4 L9 |, |interface Loopback09 W9 ^: U* |5 b4 B9 Z8 {) s
ip address 192.168.1.1 255.255.255.0/ q5 i( G. s! t
!1 Y# I; e2 w u2 | c
interface FastEthernet0/0+ o: N" z" u7 L3 X: d
ip address 12.1.1.1 255.255.255.0
) z4 S _7 L: E5 N. P8 { duplex auto; x8 Z" m; g/ {8 b+ d, b& \$ H4 e+ J$ n
speed auto( K+ U$ T0 f6 J a( ?
crypto map ccie1 F/ I( ^+ X9 W
!! x0 X* [- }! j& u' q+ e
no ip http server: t' @ V1 M6 e6 S/ v% @6 \# O8 f
no ip http secure-server
) t. ?1 [* f. b. f" g7 |% M!
) q1 C1 Z. D( s) [& Z" h!8 m8 I7 }; |6 p( [/ j) p; b3 d
!: S* o; ?1 J/ l$ H( u6 n- J% \
access-list 101 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
& `4 y$ [; x" c6 ]6 W: ]; I
% c1 `1 A# E$ V. J# I9 ?, {; v1 i* S8 g W
R2的主要配置:- Q9 f* z' t& |: f4 \
crypto isakmp policy 1
- ]/ P2 X$ l3 |. V, l hash md5/ x+ R) \2 `; d* |$ p( r. c
authentication pre-share
# Y- J: H$ J: wcrypto isakmp key cisco address 12.1.1.1
" l" m3 x7 }" r# K( o0 ]4 s) O!
8 W8 x5 z8 T# M6 Q; i% q!
1 `) M4 U. J6 L' Jcrypto ipsec transform-set ccnp esp-des esp-md5-hmac - Q( ]' d) v# A4 D
!- Z8 l$ D ]- l' M
crypto map ccie 1 ipsec-isakmp / \0 i( b9 u0 H' P
set peer 12.1.1.14 l- a0 k1 D( k
set transform-set ccnp 6 f+ w8 u% ?+ O/ ^% s0 N# U! l
match address 101) G0 {3 Q, G4 E q9 n
!
6 i4 `1 Y |2 F!
* q! a+ |6 ~1 T& A!
1 h; ~ K( ~9 \9 u" L" \: D!
. {1 [. O0 `9 }1 {- }9 H4 M- B L# q Einterface Loopback0& ^$ @$ J4 O; f% P3 f
ip address 192.168.2.1 255.255.255.03 }8 h& J0 \2 ]
!
( ~! P: [4 q' f2 M6 ointerface FastEthernet0/0$ `& V! v+ h2 S- l3 `* v% j
ip address 12.1.1.2 255.255.255.0
4 x$ y+ Z3 K3 [ duplex auto
6 U2 ?/ H% `" n6 l% J speed auto
" ^" S: h% r! g& K: f8 y, m$ p crypto map ccie
: G+ ^* o% ^3 D: L! \- |) t6 b!
. B9 V( z- f# W& X8 ?/ Ano ip http server
: U. |7 j" W7 Fno ip http secure-server
. r: |$ L v4 e$ S1 Y!
! `" u6 k( @5 n: C9 C: O3 X!6 T. I; x+ @* J w3 M! m
!5 V3 d+ d' F# A2 [
access-list 101 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255 |
|