IPSec配置实例( 二 )


在核心路由器添加新命令如下
Router(config)#crypto isakmp key 0 address 201.3.3.7Router(config)#crypto ipsec transform-set pass2 esp-aes esp-sha-hmacRouter(config)#ip access-list extended xianlu2Router(config-ext-nacl)#permit ip 192.168.0.0 0.0.255.255 10.0.0.0 0.255.255.255Router(config-ext-nacl)#exRouter(config)#crypto map ser2 10 ipsec-isakmp% NOTE: This new crypto map will remain disabled until a peerand a valid access list have been configured.Router(config-crypto-map)#set transform-set pass2Router(config-crypto-map)#set peer 201.3.3.7Router(config-crypto-map)#match address xianlu2Router(config-crypto-map)#exRouter(config)#int f 1/0Router(config-if)#crypto map ser2*Jan 3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON在配货中心路由器上配置参考Sub核心路由器,命令如下:
Router(config)#crypto isakmp enableRouter(config)#crypto isakmp policy 20Router(config-isakmp)#authentication pre-shareRouter(config-isakmp)#encryption aesRouter(config-isakmp)#hash shaRouter(config-isakmp)#group 5Router(config-isakmp)#exRouter(config)#crypto isakmp key 0 address 201.1.1.1Router(config)#crypto ipsec transform-set pass2 esp-aes esp-sha-hmacRouter(config)#ip access-list extended xianlu2Router(config-ext-nacl)#permit ip 10.0.0.0 0.255.255.255 192.168.0.0 0.0.255.255Router(config-ext-nacl)#exRouter(config)#crypto map ser2 10 ipsec-isakmp% NOTE: This new crypto map will remain disabled until a peerand a valid access list have been configured.Router(config-crypto-map)#set transform-set pass2Router(config-crypto-map)#set peer 201.1.1.1Router(config-crypto-map)#match address xianlu2Router(config-crypto-map)#exRouter(config)#int g0/0Router(config-if)#crypto map ser2*Jan 3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON配置完成后测试如下:

IPSec配置实例

文章插图
 




推荐阅读