1. 程式人生 > 實用技巧 >×××實驗配置1 思科路由器IPSEC ××× 傳統配置

×××實驗配置1 思科路由器IPSEC ××× 傳統配置

170205282.jpg

Site1:

!

!
version12.4
servicetimestampsdebugdatetimemsec
servicetimestampslogdatetimemsec
noservicepassword-encryption
!
hostnameSite1
!
boot-start-marker
boot-end-marker
!
!
noaaanew-model
memory-sizeiomem5
!
!
ipcef
noipdomainlookup
ipdomainnamelab.local
!
!
ipauth-proxymax-nodata-conns3
ipadmissionmax-nodata-conns3
!
!
!
!

!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
cryptoisakmppolicy10
encr3des
hashmd5
authenticationpre-share
group2
cryptoisakmpkeyL2KEYaddress61.128.1.1
!

!
cryptoipsectransform-setTransesp-desesp-md5-hmac
!
cryptomapcry-map10ipsec-isakmp
setpeer61.128.1.1
setsecurity-associationlifetimeseconds1800
settransform-setTrans
setpfsgroup2
matchaddress***
!

!
!
!
interfaceFastEthernet0/0
ipaddress10.1.1.1255.255.255.0
duplexauto
speedauto
!
interfaceFastEthernet1/0
ipaddress202.100.1.1255.255.255.0
duplexauto
speedauto
cryptomapcry-map

!
interfaceFastEthernet2/0
noipaddress
shutdown
duplexauto
speedauto
!
interfaceFastEthernet3/0
noipaddress
shutdown
duplexauto
speedauto
!
noiphttpserver
noiphttpsecure-server
!
ipforward-protocolnd
iproute1.1.1.0255.255.255.010.1.1.10
iproute2.2.2.0255.255.255.0202.100.1.10
iproute61.128.1.1255.255.255.255202.100.1.10
!
!
!
ipaccess-listextended***
permitip1.1.1.00.0.0.2552.2.2.00.0.0.255
!

!
!
control-plane
!
!
!
!
!
!
!
!
!
!
linecon0
exec-timeout00
privilegelevel15
loggingsynchronous
lineaux0
exec-timeout00
privilegelevel15
loggingsynchronous
linevty04
login
!
!
end

Site2:

!

!
version12.4
servicetimestampsdebugdatetimemsec
servicetimestampslogdatetimemsec
noservicepassword-encryption
!
hostnameSite2
!
boot-start-marker
boot-end-marker
!
!
noaaanew-model
memory-sizeiomem5
!
!
ipcef
noipdomainlookup
ipdomainnamelab.local
!
!
ipauth-proxymax-nodata-conns3
ipadmissionmax-nodata-conns3
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
cryptoisakmppolicy10
encr3des
hashmd5
authenticationpre-share
group2
cryptoisakmpkeyL2KEYaddress202.100.1.1
!
!
cryptoipsectransform-setciscoesp-desesp-md5-hmac
!
cryptomapcisco10ipsec-isakmp
setpeer202.100.1.1
settransform-setcisco
matchaddress***
!

!
!
!
interfaceLoopback0
ipaddress2.2.2.2255.255.255.0
!
interfaceFastEthernet0/0
noipaddress
shutdown
duplexauto
speedauto
!
interfaceFastEthernet1/0
noipaddress
shutdown
duplexauto
speedauto
!
interfaceFastEthernet2/0
ipaddress61.128.1.1255.255.255.0
duplexauto
speedauto
cryptomapcisco
!
interfaceFastEthernet3/0
noipaddress
shutdown
duplexauto
speedauto
!
noiphttpserver
noiphttpsecure-server
!
ipforward-protocolnd
iproute1.1.1.0255.255.255.061.128.1.10
iproute202.100.1.1255.255.255.25561.128.1.10
!
!
!
ipaccess-listextended***
permitip2.2.2.00.0.0.2551.1.1.00.0.0.255
!
!

!
control-plane
!
!
!
!
!
!
!
!
!
!
linecon0
exec-timeout00
privilegelevel15
loggingsynchronous
lineaux0
exec-timeout00
privilegelevel15
loggingsynchronous
linevty04
login
!
!
end

轉載於:https://blog.51cto.com/ccie18405/1213869