在核心路由器添加新命令如下
Router(config)#crypto isakmp key 0 address 201.3.3.7Router(config)#crypto ipsec transform-set pass2 esp-aes esp-sha-hmacRouter(config)#ip access-list extended xianlu2Router(config-ext-nacl)#permit ip 192.168.0.0 0.0.255.255 10.0.0.0 0.255.255.255Router(config-ext-nacl)#exRouter(config)#crypto map ser2 10 ipsec-isakmp% NOTE: This new crypto map will remain disabled until a peerand a valid access list have been configured.Router(config-crypto-map)#set transform-set pass2Router(config-crypto-map)#set peer 201.3.3.7Router(config-crypto-map)#match address xianlu2Router(config-crypto-map)#exRouter(config)#int f 1/0Router(config-if)#crypto map ser2*Jan 3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
在配货中心路由器上配置参考Sub核心路由器,命令如下:
Router(config)#crypto isakmp enableRouter(config)#crypto isakmp policy 20Router(config-isakmp)#authentication pre-shareRouter(config-isakmp)#encryption aesRouter(config-isakmp)#hash shaRouter(config-isakmp)#group 5Router(config-isakmp)#exRouter(config)#crypto isakmp key 0 address 201.1.1.1Router(config)#crypto ipsec transform-set pass2 esp-aes esp-sha-hmacRouter(config)#ip access-list extended xianlu2Router(config-ext-nacl)#permit ip 10.0.0.0 0.255.255.255 192.168.0.0 0.0.255.255Router(config-ext-nacl)#exRouter(config)#crypto map ser2 10 ipsec-isakmp% NOTE: This new crypto map will remain disabled until a peerand a valid access list have been configured.Router(config-crypto-map)#set transform-set pass2Router(config-crypto-map)#set peer 201.1.1.1Router(config-crypto-map)#match address xianlu2Router(config-crypto-map)#exRouter(config)#int g0/0Router(config-if)#crypto map ser2*Jan 3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
配置完成后测试如下:
文章插图
推荐阅读
- iQOO|神U骁龙870加持!iQOO Neo6 SE详细配置曝光:80W快充毫不缩水
- 苹果|价格6799起 iPhone 14 Max详细配置曝光:升级90Hz刘海屏+6GB RAM
- 苹果|五年来正面首次大改!iPhone 14 Pro外观图、配置全曝光:屏占比大增
- 雷蛇|全球首款!雷蛇公布2K 240Hz高刷屏笔记本:CPU/显卡配置到顶
- Object JavaScript 高级入门 对象 对象 实例
- Centos8/Alma8 网络配置工具nmcli使用说明
- 玩转华为ENSP模拟器系列 | 配置静态LSP示例
- 网站nginx配置限制单个IP访问频率,预防DDOS恶意攻击
- 苹果|标准版成丐中丐!iPhone 14系列配置图出炉:低配依然60Hz刘海屏、无缘A16
- 淘宝购物信息泄漏导致的诈骗实例