
我的easy vpn配置了以后,在外网可以拨通了,但是只有外网是单机拨号有公有ip的那种,才能顺利访问外网和公司内网;如果客户端是有经过普通路由器上网,就是客户端也要经过了nat的话,虽然拨通了,但是就不能访问内网了,外网还是没问题的。客户端用的是cisco vpn client5.0.04. 帮我看看配置有没有什么问题,很急的,谢谢4 e! b6 t3 _! A* Q# O$ Z6 d* i
5 P& b/ q9 k3 S- \7 V
$ k+ @4 w+ y6 x' w% F1 U; M$ e
服务器端配置如下,内网网段是192.168.0.0 255.255.0.0
; T0 R: ]' ~. m8 [9 Eaaa new-model L4 ^8 N: |8 a: q
!, h& j& g3 ~9 M3 U6 z. n0 m+ w, J
aaa authentication login noacs line none
* w$ G- L9 h: v1 T7 C6 R3 I# @aaa authentication login vpn-authen local
3 _0 D+ F2 i# G3 }, \" P- k: yaaa authorization network vpn-author local
/ B, d, H+ `+ Jaaa session-id common
4 R9 \, O% s/ q0 l3 N! J! I! ^
% n; s3 T7 V! m$ U% T6 D- s% @crypto isakmp policy 10
( a# o) b F' s* F/ i1 I s hash md5
' b2 W, U9 _/ v9 w0 g" y authentication pre-share
# C' a2 X0 T& p5 @! e group 2
|- L) U D5 ucrypto isakmp xauth timeout 30
- d: `* j$ q; n$ U9 Y! p- N+ |! v!6 Q/ Q* K: k) w% n" I
crypto isakmp client configuration group moblie. w# E+ A0 ^ w, a3 V
key cisco
7 C, p, h5 P7 [3 t" y dns 192.168.3.11, k# l* P6 A/ O( S" T
domain peerservices.com
* I3 s1 M% M& `# [. g( L/ f pool vpn-pool
& b( Y7 y2 E0 a2 W7 P acl 100
. N" n+ z/ `2 x# U!
1 y; i, Z5 E/ l2 P4 S% Xcrypto ipsec transform-set vpn-set esp-des esp-md5-hmac% p. }+ X8 s' q# g4 W
!- x: P0 I; h/ `* l1 _, J, b5 i9 F
crypto dynamic-map vpn-dyn 10" K" s E3 d8 p6 P: d5 J
set transform-set vpn-set- J# R! F$ a+ e4 s {/ K
reverse-route. v0 ]2 W! ~1 C0 n) k
!
! q3 X$ u- M; v1 u3 m0 Qcrypto map cisco client authentication list vpn-authen' H5 O1 ]. U$ @# R5 f4 K
crypto map cisco isakmp authorization list vpn-author, R+ Z | K" }5 z
crypto map cisco client configuration address respond' m) L& a! s7 d4 s, R
crypto map cisco 10 ipsec-isakmp dynamic vpn-dyn) l# L. [: X6 ]& Q
!
# i2 g0 U% Y2 t6 f( i, Bvoice call carrier capacity active. D- ^+ F# x6 v6 j/ O
9 E% l# Y4 B$ a! Z9 G) ^ ^ip local pool vpn-pool 172.16.0.100 172.16.0.200
3 p' g+ ?0 c5 N$ m# w! K f: Y$ h& b- a, k+ A
Extended IP access list 100# L; g1 m+ r# z
permit ip 192.168.1.0 0.0.0.255 any$ I n1 Y. Y) {0 b! D( O
permit ip 192.168.2.0 0.0.0.255 any$ l) n: M5 Y; n+ B2 @5 ]+ q
permit ip 192.168.3.0 0.0.0.255 any
; t; A3 M+ m' R( W+ J& _9 y% t* O' ` permit ip 192.168.4.0 0.0.0.255 any6 b" \! T7 F7 p8 E: Z, p1 w
permit ip 192.168.5.0 0.0.0.255 any* ~4 y) ~' x) n
permit ip 192.168.6.0 0.0.0.255 any# i$ x* s4 ]& ?2 t3 K
- R! I$ r4 a, G" U/ Q1 Z0 oip nat inside source list 111 interface Dialer1 overload8 H7 x9 i" z5 h* ]. D
& H) @& D7 x2 L
Extended IP access list 111
- l8 e1 |+ J9 d0 U! } deny ip 192.168.0.0 0.0.255.255 172.16.0.0 0.0.255.255 (73 matches)
$ }4 j3 ^0 y% U: l2 o7 s6 k* t( ~9 K permit ip 192.168.0.0 0.0.255.255 any (211808 matches) |
|