《防火墙 or 路由器ipsec公开课.docx》由会员分享,可在线阅读,更多相关《防火墙 or 路由器ipsec公开课.docx(6页珍藏版)》请在taowenge.com淘文阁网|工程机械CAD图纸|机械工程制图|CAD装配图下载|SolidWorks_CaTia_CAD_UG_PROE_设计图分享下载上搜索。
1、Building configuration.Current configuration: iversion 1.3.3Hservice timestamps log dateservice timestamps debug date no service password-encryptioni *hostname R2i *I *gbsc group defaultiI crypto isakmp key 123123123 192.168.1.1 255.255.255.255I *I *crypto isakmp policy 10hash md5i *crypto ipsec tra
2、nsform-set onetransform-type esp-des esp-md5-hmac i crypto map my 10 ipsec-isakmpset peer 192.168.1.1set transform-set onematch address 101i I ainterface FastEthernetO/Ono ip addressno ip directed-broadcasti *interface GigaEthernetO/3ip address 192.168.2.1 255.255.255.0no ip directed-broadcast iinte
3、rface GigaEthernetO/4ip address 192.168.1.2 255.255.255.0no ip directed-broadcastcrypto map my interface GigaEthernetO/5no ip addressno ip directed-broadcasti *interface GigaEthernetO/6no ip addressno ip directed-broadcasti *interface SerialO/1no ip addressno ip directed-broadcasti *interface Serial
4、O/2no ip addressno ip directed-broadcasti interface AsyncO/Ono ip addressno ip directed-broadcastip route default 192.168.1.1 p access-list extended 101permit ip 192.168.2.0 255.255.255.0 192.168.0.0 255.255.255.0P2提议恒新建 身编辑 1&删除恒新建,身编辑而删除名稀P1生存时间 86400购证算法 认证力幅翼能| DH组nid5ore-share des1得息制徐夜式冷盘本地ID融
5、ID身编辑而删除IKE VPN酉造步骤1:对端-T|页,总页数i 导编辑#Bfl对端名称:ipsec接口:ethernetO/O模式:。主模式野蛮模式类型:。静态IP动态IP用户组对端1P地址:192.168.1.2本地ID:。无FQDNO U-FQDN o ASN1-DN对端ID:0无FQDN U-FQDN ASN1-DN提议1:P1V预共享密钥:(5127)字符基本配置高级配置总数为1步骤2:隧道确定 取消/IKE VPN0JgQ步骤1:对端步骤2:隧道基本配置Q高级配贵名称:p2模式: tunnel transportP2提议:代理ID:本地IP/掩码:远程IP/推码:服务:P27自动
6、修手工192.168.0.02424AnyY192.168.2.0Any确定取消1忙新建而删除 状态IP/描码下一跌下一糠接口协议优先权度里路由权值目的路由 源路由 源接口路由后嘴息isp路由策略路由o.o.o.o/o192.168.0.0/24192.168.0.1/32192.168.1.0/24192.168.1.1/32192.168.100.0/24192.168.100.1/32ethernetO/O ethernetO/1 ethemetO/1 ethemetO/O ethemetO/O ethernetO/4 ethernetO/4直连00主机00直连00主机00111111接
7、口配置常规Q属性 高级 RIP高级选项DHCP.DDNS.管理方式 Telnet SSH 团 Ping 切 HTTP 叨 HTTPS SNMP删除隧道绑定酉i!置 隧道类型:VPN名称:网关:添加而删除VPN名称类型同美P2ipseca接口名称状态获取类型IP/掩码I安全域接入用户/I喷流入帚宽(bps)藻出帚及(bps)IethernetO/O电电粉态192.168.1.1/24untrust000ethernetO/1也也玲态192.168.0.1/24trust000ethernetO/2静态0.0.0.0/0NULL000ethernetO/3静态0.0.0.0/0NULL000ethernetO/4也除态192.168.100.1/24trust000图tunnel 1龄态0.0.0.0/0trust000vswitchifl静态0.0.0.0/0NULL000嚏安3盛