資源描述:
《ipsec over gre原理及配置》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在教育資源-天天文庫。
1、ipsecovergre步驟:1.創(chuàng)建tunnel口,配置ip,source,destination2.默認路由指向出口下一跳3.使用路由協(xié)議,把路由ping通(環(huán)回口,要加密的數(shù)據(jù)的ip)4.建立vpn,并在tunnel口上綁定map廢話不多說,直接上配置:R1配置:hostnameR1!cryptoisakmppolicy10hashmd5authenticationpre-sharegroup2cryptoisakmpkeyzhangaddress3.3.3.3!!cryptoipsectransform-setmytransesp-
2、3desesp-md5-hmac!cryptomapmymaplocal-addressLoopback0cryptomapmymap10ipsec-isakmpsetpeer3.3.3.3settransform-setmytransmatchaddressVPN!interfaceTunnel0ipaddress172.16.1.1255.255.255.0tunnelsourceFastEthernet0/0tunneldestination23.1.1.2tunnelkey123cryptomapmymap!interfaceLoo
3、pback0ipaddress1.1.1.1255.255.255.0!interfaceLoopback10ipaddress192.168.1.1255.255.255.0!interfaceFastEthernet0/0ipaddress12.1.1.1255.255.255.0duplexautospeedauto!routerospf1router-id1.1.1.1log-adjacency-changesnetwork1.1.1.00.0.0.255area0network172.16.1.00.0.0.255area0net
4、work192.168.1.00.0.0.255area0neighbor3.3.3.3!noiphttpservernoiphttpsecure-serveriproute0.0.0.00.0.0.012.1.1.2!ipaccess-listextendedVPNpermitip192.168.1.00.0.0.255192.168.3.00.0.0.255!endR2配置:hostnameR2interfaceFastEthernet0/0ipaddress12.1.1.2255.255.255.0duplexautospeedaut
5、o!interfaceFastEthernet1/0ipaddress23.1.1.1255.255.255.0duplexautospeedauto!endR3配置:hostnameR3!cryptoisakmppolicy10hashmd5authenticationpre-sharegroup2cryptoisakmpkeyzhangaddress1.1.1.1!cryptoipsectransform-setmytransesp-3desesp-md5-hmac!cryptomapmymaplocal-addressLoopback
6、0cryptomapmymap10ipsec-isakmpsetpeer1.1.1.1settransform-setmytransmatchaddressVPN!interfaceTunnel0ipaddress172.16.1.2255.255.255.0tunnelsourceFastEthernet0/0tunneldestination12.1.1.1tunnelkey123cryptomapmymap!interfaceLoopback0ipaddress3.3.3.3255.255.255.0!interfaceLoopbac
7、k10ipaddress192.168.3.1255.255.255.0!interfaceFastEthernet0/0ipaddress23.1.1.2255.255.255.0duplexautospeedauto!routerospf1router-id3.3.3.3log-adjacency-changesnetwork3.3.3.00.0.0.255area0network172.16.1.00.0.0.255area0network192.168.3.00.0.0.255area0neighbor1.1.1.1!iproute
8、0.0.0.00.0.0.023.1.1.1!ipaccess-listextendedVPNpermitip192.168.3.00.0.0.255192.168.1.00.0