配置中也顺便加入了NAT部分的配置。

1、在r1上配置IPSec VPN。
hostname r1
!
crypto isakmp policy 10
encr 3des
authentication pre-share
hash sha
group 2
crypto isakmp key cisco1234 address 218.1.1.1
!
crypto ipsec transform-set ccsp esp-3des esp-sha-hmac
mode tunnel
!
crypto map cisco 10 ipsec-isakmp
set peer 218.1.1.1
set transform-set ccsp
match address 102
!
interface Loopback0
ip address 10.1.1.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
interface Serial0/0
ip address 173.16.1.5 255.255.255.252
ip nat outside
ip virtual-reassembly
crypto map cisco
!
ip route 0.0.0.0 0.0.0.0 173.16.1.6
!
ip nat inside source list 101 interface Serial0/0 overload
!
access-list 101 deny ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
access-list 101 permit ip 10.1.1.0 0.0.0.255 any
!定义NAT感兴趣流,要将IPSec流量在NAT中去掉
本帖隐藏的内容需要回复才可以浏览