
我的easy vpn配置了以后,在外网可以拨通了,但是只有外网是单机拨号有公有ip的那种,才能顺利访问外网和公司内网;如果客户端是有经过普通路由器上网,就是客户端也要经过了nat的话,虽然拨通了,但是就不能访问内网了,外网还是没问题的。客户端用的是cisco vpn client5.0.04. 帮我看看配置有没有什么问题,很急的,谢谢& P8 W$ O" j5 q1 C. P4 d2 X
$ D0 _ s3 k Y# J. `
; H; q. f! T+ l& Q服务器端配置如下,内网网段是192.168.0.0 255.255.0.0! ]& i6 p- f% R
aaa new-model
/ [- T; S( F3 R3 C3 C# F$ K!' N; x: o) A4 N
aaa authentication login noacs line none
. x5 [3 m4 a& Z; _* jaaa authentication login vpn-authen local
$ w9 O) H) O; R) [) Caaa authorization network vpn-author local
+ P3 Z" h; C$ E) laaa session-id common+ _4 y$ n- L' h. r9 U1 E& U
: S* L' Y$ x: j* G% l
crypto isakmp policy 10
) ]% t' ?4 z3 Y2 @/ f hash md5: G' F) |" ?: B, I
authentication pre-share
& o1 T( u" a# f) c1 J# h+ g group 2* g# M7 ^; m3 V5 V: ]" b
crypto isakmp xauth timeout 30& k% @ F$ K+ u5 R4 W
!- N; m: w2 w: R0 j$ \* Q
crypto isakmp client configuration group moblie
" O% }4 |* t, V' f. \ key cisco
& k. Y+ b/ S u1 f dns 192.168.3.11" b/ y4 }; l/ i p* i6 `7 f- M9 g; k
domain peerservices.com* N) b; W1 q/ U
pool vpn-pool
( f+ J3 a0 j; C/ D6 \5 Y; ~* n acl 1005 @# S; \: \7 V" ^/ m
!
7 m' ], p# J. zcrypto ipsec transform-set vpn-set esp-des esp-md5-hmac8 _/ q9 @% _ g+ t/ S& o
!
, I+ Z) D+ N4 H- j2 Ycrypto dynamic-map vpn-dyn 10
. x7 ?* F# S x4 P9 R X: v2 Z set transform-set vpn-set. ?9 T- M( ^' O$ A$ S0 H
reverse-route
. V- W |# O( {!+ [" D+ C( K: x. }$ A) w9 z
crypto map cisco client authentication list vpn-authen8 o4 q) `# v8 i% k2 U1 I% I6 ?8 N0 x6 L
crypto map cisco isakmp authorization list vpn-author
0 O% S/ x2 V P1 o) Ecrypto map cisco client configuration address respond* b2 _8 l+ g& k1 h G- D
crypto map cisco 10 ipsec-isakmp dynamic vpn-dyn' ]) W0 Q) ?9 n2 [- R
!
. _( ~% g2 H) zvoice call carrier capacity active
% `3 r. Y# K, N3 V/ ^, S/ T$ A3 C& a3 P+ s8 I- Q4 `9 s. z5 y$ {
ip local pool vpn-pool 172.16.0.100 172.16.0.200
3 h: J4 c/ K0 A5 K |& g+ B4 x!$ B2 D' z# A" ~: q
Extended IP access list 100
( \4 D& {- p$ ]8 D0 {& f1 h permit ip 192.168.1.0 0.0.0.255 any
- J( j; a3 u3 G: p1 t permit ip 192.168.2.0 0.0.0.255 any1 Y& p$ e X- M {
permit ip 192.168.3.0 0.0.0.255 any
6 B7 U, m5 O+ j2 F) [$ P$ ` Z2 y permit ip 192.168.4.0 0.0.0.255 any
: H6 f+ C! n# i! [ permit ip 192.168.5.0 0.0.0.255 any
& Z U D4 \. L2 V, v. u% o' t permit ip 192.168.6.0 0.0.0.255 any
0 _8 [6 Y! A* l9 {/ O5 ?* f d2 L% K- \% ^! F
ip nat inside source list 111 interface Dialer1 overload; f2 z K& o e# j2 q0 `
1 n# }: g8 u5 o' S* N; f6 t4 u
Extended IP access list 1114 N- l4 a. ^' |* m1 o5 m4 g
deny ip 192.168.0.0 0.0.255.255 172.16.0.0 0.0.255.255 (73 matches)
- ]6 b- f A' s2 B5 V" S: E) C7 p/ e permit ip 192.168.0.0 0.0.255.255 any (211808 matches) |
|