您的位置广东网盟 > 文章资讯 > 企业网络 > 文章内容

VPN及其配置示例

作者:佚名  来源:本站整理  发布时间:2008-5-15 15:06:35
ot bootldr bootflash:c7100-boot-mz.120-1.1.T
    boot config slot0:hq-sanjose-cfg-small
    no logging buffered
    !
    crypto isakmp policy 1
    authentication pre-share
    lifetime 84600
    crypto isakmp key test12345 address 172.24.2.5
    crypto isakmp key test67890 address 172.23.2.7
    !
    crypto ipsec transform-set proposal1 ah-sha-hmac esp-des esp-sha-hmac
    ode transport
    !
    crypto ipsec transform-set proposal4 ah-sha-hmac esp-des esp-sha-hmac
    !
    !
    crypto map s1first local-address Serial1/0
    crypto map s1first 1 ipsec-isakmp
    set peer 172.24.2.5
    set transform-set proposal1
    match address 101
    !
    crypto map s4second local-address Serial2/0
    crypto map s4second 2 ipsec-isakmp
    set peer 172.23.2.7
    set transform-set proposal4
    match address 111
    !
    interface Tunnel0
    bandwidth 180
    ip address 172.17.3.3 255.255.255.0
    no ip directed-broadcast
    tunnel source 172.17.2.4
    tunnel destination 172.24.2.5
    crypto map s1first
    !
    interface FastEthernet0/0
    ip address 10.1.3.3 255.255.255.0
    no ip directed-broadcast
    no keepalive
    full-duplex
    no cdp enable
    !
    interface FastEthernet0/1
    ip address 10.1.6.4 255.255.255.0
    no ip directed-broadcast
    ip nat inside
    no keepalive
    full-duplex
    no cdp enable
    !
    interface Serial1/0
    ip address 172.17.2.4 255.255.255.0
    no ip directed-broadcast
    no ip mroute-cache
    no keepalive
    fair-queue 64 256 0
    framing c-bit
    cablelength 10
    dsu bandwidth 44210
    clock source internal
    no cdp enable
    crypto map s1first
    !
    interface Serial2/0
    ip address 172.16.2.2 255.255.255.0
    no ip directed-broadcast
    ip nat outside
    no ip mroute-cache
    no keepalive
    fair-queue 64 256 0
    framing c-bit
    cablelength 10
    dsu bandwidth 44210
    clock source internal
    no cdp enable
    crypto map s4second
    !
    router bgp 10
    network 10.2.2.2 mask 255.255.255.0
    network 172.16.2.0 mask 255.255.255.0
    !
    ip route 10.1.4.0 255.255.255.0 Tunnel0
    !
    ip nat inside source static 10.1.6.5 10.2.2.2
    !
    access-list 101 permit gre host 172.17.2.4 host 172.24.2.5
    access-list 111 permit ip host 10.2.2.2 host 10.1.5.3
    !
    line con 0
    transport input none
    line aux 0
    line vty 0 4
    login
    !
    end
    Business Partner Router 配置:
    bus-ptnr# show running-config
    Building configuration...

    Current configuration:
    !
    version 12.0
    service timestamps debug uptime
    service timestamps log uptime
    no service password-encryption
    !
    hostname bus-ptnr
    !
    boot system flash bootflash:
    boot bootldr bootflash:c7100-boot-mz.120-1.1.T
    boot config slot0:bus-ptnr-cfg-small
    no logging buffered
    !
    crypto isakmp policy 1
    authentication pre-share
    lifetime 84600
    crypto isakmp key test67890 address 172.16.2.2
    !
    crypto ipsec transform-set proposal4 ah-sha-hmac esp-des esp-sha-hmac
    !
    !
    crypto map s4second local-address Serial1/0
    crypto map s4second 2 ipsec-isakmp

    set peer 172.16.2.2
    set transform-set proposal4
    match address 111
    !
    interface FastEthernet0/0
    ip address 10.1.5.2 255.255.255.0
    no ip directed-broadcast
    no keepalive
    full-duplex
    no cdp enable
    !
    interface Serial1/0
    ip address 172.23.2.7 255.255.255.0
    no ip directed-broadcast
    no ip mroute-cache
    no keepalive
    fair-queue 64 256 0
    framing c-bit
    cablelength 10
    dsu bandwidth 44210
    clock source internal
    no cdp enable
    crypto map s4second
    !
    router bgp 10
    network 10.1.5.0 mask 255.255.255.0
    network 172.16.2.0 mask 255.255.255.0
    !
    access-list 111 permit ip host 10.1.5.3 host 10.2.2.2
    !
    line con 0
    transport input none
    line aux 0
    line vty 0 4
 

上一页  [1] [2] 

Tags:广东网盟  
  •         用户名: 验证码: 验证码,看不清楚请点击刷新验证码 (注“”为必填内容。)


    文章评论: [ 查看全部 ] 网友评论
    关于网盟 | 网站帮助 | 广告合作 | 下载声明 | 友情连接 | 联系方式

    Copyright © 2003-2008 Gdwg.Net. All Rights Reserved .
    中国广东网管联盟设计维护.网站备案:粤ICP备08020875号