1、CISCO VPN的搭建实验doc 实验报告实验时间:2009.3.31实验人:ljh实验名称:虚拟专网VPN实验任务和目标:配置企业网络通过VTPH互通实验拓扑及网络规划:实验操作过程及配置说明:1R1的配置信息及学习情况2.ISP的配置信息及学习情况3.R2的配置信息及学习情况4.各PC的配置情况及联通性测试5IPSEC VPN配置的检查 ( R1 )6. IPSEC VPN配置的检查 ( R2 )配置命令:R1的配置:enableconfig terminalhostname R1crypto isakmp policy 1encr 3desauthentication pre-shar
2、elifetime 3600crypto isakmp key ljh address 202.100.2.1crypto ipsec transform-set wen ah-sha-hmac esp-3des esp-sha-hmaccrypto map na 1 ipsec-isakmpset peer 202.100.2.1set transform-set wenmatch address 101interface Ethernet0/0ip address 172.16.1.1 255.255.255.248no shutdown full-duplexinterface Seri
3、al1/0ip address 202.100.1.1 255.255.255.0no shutdownserial restart-delay 0crypto map naip route 0.0.0.0 0.0.0.0 202.100.1.2access-list 101 permit ip 172.16.1.0 0.0.0.7 192.168.1.0 0.0.0.7ISP的配置:enableconfig terminalhostname ISPinterface Serial1/0ip address 202.100.1.2 255.255.255.0no shutdowninterfa
4、ce Serial1/1ip address 202.100.2.2 255.255.255.0no shutdownrouter ospf 10network 202.100.1.0 0.0.0.255 area 0network 202.100.2.0 0.0.0.255 area 0R2的配置:enableconfig terminalhostname R2crypto isakmp policy 1encr 3desauthentication pre-sharelifetime 3600crypto isakmp key ljh address 202.100.1.1crypto i
5、psec transform-set wen ah-sha-hmac esp-3des esp-sha-hmaccrypto map na 1 ipsec-isakmpset peer 202.100.1.1set transform-set wenmatch address 101interface Ethernet0/0ip address 192.168.1.1 255.255.255.248no shutdownfull-duplexinterface Serial1/1ip address 202.100.2.1 255.255.255.0no shutdownserial restart-delay 0crypto map naip route 0.0.0.0 0.0.0.0 202.100.2.2access-list 101 permit ip 192.168.1.0 0.0.0.7 172.16.1.0 0.0.0.7
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1