資源描述:
《cisco vpn完全配置手冊1》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在行業(yè)資料-天天文庫。
1、最詳盡的ciscoVPN完全配置手冊(1)VPN配置手冊---Vpn?Access?ServerVPN?配置之一:vpn?access?server網(wǎng)絡(luò)拓?fù)洌?PC---------Router---------Router???PC配置:?IP?Address:10.1.1.1/24?Default?Gateway:10.1.1.254R1接口ip:?(VPN?Access?Server)?FastEthernet?0/0:20.1.1.254/24?Serial?1/0:172.16.1
2、.1/24R2接口ip:?(Private?Network)?Serial?1/0::172.16.1.2/24?FastEthernet?0/0:10.1.1.254/242610的IOS為c2600-jk8o3s-mz.122-8.T5.binR1步驟:?1.配置isakmp?policy:?crypto?isakmp?policy?1?hash?md5?authentication?pre-share?group?22.配置vpn?client地址池?crypto?isakmp?client?configur
3、ation?address-pool?local?pool192?ip?local?pool?pool192?192.168.1.1?192.168.1.2543.配置vpn?client有關(guān)參數(shù)?crypto?isakmp?client?configuration?group?vclient-group?(vclient-group就是在vpn?client的連接配置中需要輸入的group?authentication?name。)?key?vclient-key?(vclient-key就是在vpn?clien
4、t的連接配置中需要輸入的group?authentication?password。)?pool?pool192?(client的ip地址從這里選取?)?(以上兩個參數(shù)必須配置,其他參數(shù)還包括domain、dns、wins等,根據(jù)情況進(jìn)行配置。)4.配置ipsec?transform-set?crypto?ipsec?transform-set?vclient-tfs?esp-des?esp-md5-hmac5.配置map模板?cry?dynamic-map?template-map?1?set?transform
5、-set?vclient-tfs?(和第四步對應(yīng))6.配置vpnmap?cry?map?vpnmap?1?ipsec-isakmp?dynamic?template-map?(使用第五步配置的map模板?)?crypto?map?vpnmap?isakmp?authorization?list?vclient-group?(使用第三步配置的參數(shù)authorization)?crypto?map?vpnmap?client?configuration?address?respond?(響應(yīng)client分配地址的請求)
6、說明幾點:?(1)vpn?client使用的ip?pool地址不能與Router內(nèi)部網(wǎng)絡(luò)ip地址重疊。?(2)172.16.1.0?網(wǎng)段模擬公網(wǎng)地址,10.1.1.0、20.1.1.0?網(wǎng)段用于內(nèi)部地址,192.168.1.0?網(wǎng)段用于vpn通道。R1的配置:r1#?r1#sh?run?Building?configuration...Current?configuration?:?1521?bytes?!?version?12.2?service?timestamps?debug?uptime?service?t
7、imestamps?log?uptime?no?service?password-encryption?!?hostname?r1?!?Enable?Password?cisco?!?ip?subnet-zero?!?ip?audit?notify?log?ip?audit?po?max-events?100?!?crypto?isakmp?policy?1?hash?md5?authentication?pre-share?group?2?crypto?isakmp?client?configuration?ad
8、dress-pool?local?pool192?!?crypto?isakmp?client?configuration?group?vclient-group?key?vclient-key-cisco?pool?vclient-pool?!?crypto?ipsec?transform-set?vclient-tfs?esp-des?esp-md5-h