1、两个路由器实现VPN访问的配置两个路由器实现VPN访问的配置1、网络结构图2、路由器的配置 21 Cisco2621路由器的配置 routeren router#hostname cisco2621 cisco2611#conf t cisco2611(config)#inter fa 0/0 cisco2611(config)#ip address 192.168.100.1 255.255.255.0 cisco2611(config)#inter fa 0/1 cisco2611(config)#ip address 219.137.26.166 255.255.255.248 cisc
2、o2611(config)#ip router 0.0.0.0 0.0.0.0 219.137.26.161 22 Cisco2621路由器的配置 routeren router#hostname cisco2621 cisco2621#conf t cisco2621(config)#inter e 0/0 cisco2621(config)#ip address 219.137.26.132 255.255.255.248cisco2621(config)#no ip directed-broadcastcisco2621(config)# ip nat inside cisco2621(
3、config)#inter e 0/1 cisco2621(config)#ip address 219.137.26.161 255.255.255.248cisco2621(config)#no ip directed-broadcastcisco2621(config)# ip nat outsidecisco2621(config)#access-list 1 permit 192.168.100.0 0.0.0.255cisco2621(config)#ip nat pool Onlyone 219.137.26.165 219.137.26.165 netmask 255.255.
4、255.248cisco2621(config)#ip nat inside source list 1 pool Onlyone overloadcisco2621(config)#ip classless cisco2621(config)#ip router 0.0.0.0 0.0.0.0 219.137.26.1293、客户端的配置 31首先安装VPN Client软件 安装完成后重新启动系统,然后在网络属性可以看到有check point Securemote一项。 32 安装SAP Client软件 33 配置VPN Client配置安装完成后在任务栏会生成如下图标:鼠标右击该图标
5、,选择Configure,出现如下窗口:选中Sites,运行Create New,会出现如下窗口:在Name / 后输入接入IP地址218.19.148.37(VPN服务器的对外IP地址),然后按OK完成。输入用户名及密码:caiy1/password,然后会出现(此表示连接正常)点击“OK”后应出现如下图所示:然后点击“OK“选中Tools,运行Configure Client Mode,会出现如下窗口:选中Connect Mode模式,按OK完成。改变模式后退出并重新运行VPN-1SecureClient。连接鼠标右击任务栏图标,选择Connect,会出现如下窗口:点击Connect按钮,
6、即可连接成功。注意DNS服务器设成10.16.5.8,否则无法解析内部域名,如:pub1.agd.ydb;如果安装了Microsoft Firewall Client,必须Disable掉,否则无法连接到接入点218.19.148.37。 34 测试连通性 VPN Client连接完成后打开IE输入输入用户及密码:gddemo/demogd4、Cisco2611的配置清单2611 configuartionshow runBuilding configuration.Current configuration:!version 12.0service timestamps debug upti
7、meservice timestamps log uptimeservice password-encryption!hostname Shujuju!boot system flash enable secret 5 $1$Y74w$WcY1OPY87PHMu03Nw2nal/!ip subnet-zero!voice-port 1/0/0voice-port 1/0/1!voice-port 1/1/0!voice-port 1/1/1!process-max-time 200!interface Ethernet0/0 ip address 192.168.100.1 255.255.2
8、55.0 no ip directed-broadcast ip nat inside!interface Serial0/0 bandwidth 1024 no ip address no ip directed-broadcast encapsulation ppp shutdown!interface Ethernet0/1 ip address 219.137.26.166 255.255.255.248 no ip directed-broadcast ip nat outside!ip nat pool Onlyone 219.137.26.165 219.137.26.165 n
9、etmask 255.255.255.252ip nat inside source list 1 pool Onlyone overloadip classlessip route 0.0.0.0 0.0.0.0 219.137.26.161no ip http server!access-list 1 permit 192.168.100.0 0.0.0.255snmp-server engineID local 000000090200003080942560snmp-server community 123456!#$% RO 80privilege configure level 3 line!line con 0 login transport input noneline aux 0line vty 0 4 no login!no scheduler allocate
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1