[配置案例] ASA5510与Router建立IPSEC Dynamic VPN.pdf |
思科防火墙对接VPN案例
ASA5510与Router建立IPSEC Dynamic VPN.pdf ![]() 路由器配置: 路由器上网配置不作解释,但是有一点需要注意,感兴趣流的配置需要在nat 中deny,后放行才行。 ip nat inside source list nat interface Dialer1 overload //PAT 配置 ip access-list extended nat deny ip 192.168.0.0 0.0.255.255 188.188.188.0 0.0.0.255 //先将感兴趣流 拒绝,不让它走NAT permit ip any any //放行上网流量 VPN 配置: crypto isakmp policy 1 encr 3des hash sha authentication pre-share group 2 crypto isakmp key cisco123 address 157.255.21.33(ASA 防火墙固定公网 地址) crypto ipsec transform-set ccie esp-3des esp-sha-hmac //配置转换集 crypto map l2l 1 ipsec-isakmp set peer 157.255.21.33 set transform set transformset transform set transform set transform -set set ccie match address match address match address match address match address match address match address match address 100100100 interface Dialer1interface Dialer1interface Dialer1interface Dialer1interface Dialer1interface Dialer1 interface Dialer1 interface Dialer1interface Dialer1 crypto map l2l crypto map l2l crypto map l2lcrypto map l2lcrypto map l2lcrypto map l2l crypto map l2lcrypto map l2l // 在接口上应用此映射 access access -list list list list 100 permit ip permit ip permit ip permit ip permit ip permit ip permit ip 192.168.0.0192.168.0.0192.168.0.0192.168.0.0192.168.0.0192.168.0.0192.168.0.0192.168.0.0192.168.0.0192.168.0.0 (本地 IP 段) 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 0.0.255.255 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 188.188.188.0 (远端 (远端 IP 段) 0.0.0.2550.0.0.255 0.0.0.255 0.0.0.255 0.0.0.2550.0.0.255 // 感兴趣流 ASA 配置 ASAASA 上网配置不作解释,在有 上网配置不作解释,在有 NATNATNAT的防火墙上,需要配置 的防火墙上,需要配置 NATNATNAT旁路。 NATNATNAT旁路配置 (不能让这部分流量走 (不能让这部分流量走 NATNATNAT) object network inside_offices_networkobject network inside_offices_object network inside_offices_networkobject network inside_offices_object network inside_offices_networkobject network inside_offices_networkobject network inside_offices_networkobject network inside_offices_object network inside_offices_networkobject network inside_offices_object network inside_offices_networkobject network inside_offices_networkobject network inside_offices_networkobject network inside_offices_object network inside_offices_networkobject network inside_offices_object network inside_offices_object network inside_offices_networkobject network inside_offices_object network inside_offices_networkobject network inside_offices_networkobject network inside_offices_object network inside_offices_subnet 188.188.188.0 255.255.255.0 subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0 subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0 subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0 subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0 subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0subnet 188.188.188.0 255.255.255.0 object network vpnobject network vpn object network vpnobject network vpn object network vpnobject network vpnobject network vpnobject network vpn object network vpnobject network vpn object network vpnobject network vpnobject network vpn subnet 192.168.0.0 255.255.0.0 subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0 subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0 subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0 subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0 subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0subnet 192.168.0.0 255.255.0.0 subnet 192.168.0.0 255.255.0.0 nat nat nat (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network (inside,outside) source static inside_offices_network inside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn inside_offices_network destination static vpn vpninside_offices_network destination static vpn vpninside_offices_network destination static vpn VPNVPN 配置: crypto ikev1 policy 1 crypto ikev1 policy 1 crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1 crypto ikev1 policy 1crypto ikev1 policy 1crypto ikev1 policy 1 crypto ikev1 policy 1 authentication pre authentication preauthentication pre authentication preauthentication preauthentication preauthentication preauthentication pre authentication pre-share share encryption 3desencryption 3desencryption 3des encryption 3des encryption 3desencryption 3desencryption 3desencryption 3desencryption 3des encryption 3des hash shahash sha hash shahash shahash sha group 2 group 2group 2group 2group 2group 2 lifetime 86400lifetime 86400lifetime 86400 lifetime 86400 lifetime 86400lifetime 86400lifetime 86400lifetime 86400lifetime 86400lifetime 86400lifetime 86400lifetime 86400 crypto ipsec ikev1 transform crypto ipsec ikev1 transform crypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transform crypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transform crypto ipsec ikev1 transformcrypto ipsec ikev1 transformcrypto ipsec ikev1 transform crypto ipsec ikev1 transform -set set ccie espesp -3des esp3des esp 3des esp 3des esp -sha -hmac hmac hmac hmac crypto dynamic crypto dynamic crypto dynamiccrypto dynamiccrypto dynamic crypto dynamic crypto dynamic-map dymap 1 set ikev1 transformmap dymap 1 set ikev1 transform map dymap 1 set ikev1 transformmap dymap 1 set ikev1 transform map dymap 1 set ikev1 transform map dymap 1 set ikev1 transformmap dymap 1 set ikev1 transform map dymap 1 set ikev1 transformmap dymap 1 set ikev1 transformmap dymap 1 set ikev1 transformmap dymap 1 set ikev1 transformmap dymap 1 set ikev1 transformmap dymap 1 set ikev1 transformmap dymap 1 set ikev1 transformmap dymap 1 set ikev1 transform map dymap 1 set ikev1 transform map dymap 1 set ikev1 transform -set set ccie crypto dynamic crypto dynamic crypto dynamiccrypto dynamiccrypto dynamic crypto dynamic crypto dynamic-map dymap 1 set reversemap dymap 1 set reverse map dymap 1 set reversemap dymap 1 set reverse map dymap 1 set reverse map dymap 1 set reversemap dymap 1 set reverse map dymap 1 set reversemap dymap 1 set reversemap dymap 1 set reversemap dymap 1 set reversemap dymap 1 set reversemap dymap 1 set reversemap dymap 1 set reverse -routerouterouterouteroute crypto map crypto map crypto map crypto map crypto map crypto map mymapmymap mymap 10 ipsec10 ipsec10 ipsec10 ipsec10 ipsec -isakmp dynamic isakmp dynamic isakmp dynamic isakmp dynamic isakmp dynamic isakmp dynamic isakmp dynamic isakmp dynamic dymap dymap crypto map crypto map crypto map crypto map crypto map crypto map mymapmymap mymap interface outsideinterface outsideinterface outsideinterface outsideinterface outsideinterface outside interface outsideinterface outsideinterface outside interface outsideinterface outside crypto ikev1 enable outside crypto ikev1 enable outside crypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outside crypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outsidecrypto ikev1 enable outside crypto ikev1 enable outsidecrypto ikev1 enable outside sysopt connection per sysopt connection persysopt connection per sysopt connection persysopt connection persysopt connection persysopt connection per sysopt connection persysopt connection persysopt connection persysopt connection persysopt connection per sysopt connection permitmitmit-vpnvpn // 默认自动放行 默认自动放行 VPNVPN 解密后所有流量 tunnel tunneltunneltunnel-group DefaultL2LGroup ipsec group DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsec group DefaultL2LGroup ipsec group DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsec group DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsec group DefaultL2LGroup ipsecgroup DefaultL2LGroup ipsec -attributes attributes attributesattributes attributesattributesattributes ikev1 preikev1 preikev1 preikev1 preikev1 preikev1 preikev1 pre ikev1 pre-shared sharedshared-key key key cisco123 cisco123 cisco123cisco123cisco123cisco123 附 链接:https://pan.baidu.com/s/1i4X2hHb 密码:
购买主题
已有 1 人购买
本主题需向作者支付 20 金币 才能浏览
|
相关帖子
|
| |
| |
| |
| |
| |
| |
| |