本文共 1653 字,大约阅读时间需要 5 分钟。
第一步还是先配置ip
pc1server1 IP
路由器
R1interface GigabitEthernet0/0/0ip address 192.168.1.254 255.255.255.0interface GigabitEthernet0/0/1
ip address 100.0.0.1 255.255.255.0 路由ip route-static 0.0.0.0 0.0.0.0 100.0.0.2R2
interface GigabitEthernet0/0/0ip address 100.0.0.2 255.255.255.0interface GigabitEthernet0/0/1
ip address 200.0.0.2 255.255.255.0R3
interface GigabitEthernet0/0/0 ip address 200.0.0.1 255.255.255.0 ipsec policy yfinterface GigabitEthernet0/0/1
ip address 192.168.2.254 255.255.255.0路由ip route-static 0.0.0.0 0.0.0.0 200.0.0.2第二步配置***
R1
ike proposal 1encryption-algorithm 3des-cbcauthentication-algorithm md5authentication-method pre-sharedh group2ike peer 200.0.0.1 v1
pre-shared-key simple teduike-proposal 1remote-address 200.0.0.1acl number 3000 配置acl
rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255ipsec proposal 1
transform ah-espipsec policy yf 1 isakmp
security acl 3000ike-peer 200.0.0.1proposal 1interface GigabitEthernet0/0/1
ipsec policy yfR3
ike proposal 1encryption-algorithm 3des-cbcauthentication-algorithm md5authentication-method pre-sharedh group2ike peer 100.0.0.1 v1
pre-shared-key simple teduike-proposal 1remote-address 100.0.0.1acl number 3000
rule 5 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255ipsec proposal 1
transform ah-espipsec policy yf 1 isakmp
security acl 3000ike-peer 100.0.0.1proposal 1interface GigabitEthernet0/0/0
ipsec policy yf查看与验证:
RIdisplay ike sadisplay ipsec saR3
display ike sadisplay ipsec sa验证***
pc1pingserver1转载于:https://blog.51cto.com/13555885/2070360