rock1019
新新人类
帖子
31
精华
0
无忧币 94
积分 105
阅读权限 20
|
发表于:2007-9-27 20:25
标题:如何测试vpn的配置?求解!
<上一帖 |
下一帖>
下面是实验TOP及配置 但内网10.1.1.0/24 不能于内网10.1.2.0/24互通 )
网络1:
内网IP 10.1.1.0/24
外网IP 202.102.1.5/24
网络2:
内网IP 10.1.2.0/24
外网IP 202.102.1.6/24
网络1配置:
!
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname nanjing
!
enable cisco
!
!
crypto isakmp policy 1
encryption des
hash sha
authentication pre-share
group 1
lifetime 14400
crypto isakmp identity address
crypto isakmp key 654321 address 202.102.1.6 654321
crypto isakmp key 654321 address 192.168.1.2
crypto ipsec transform-set tset1 ah-md5-hmac esp-des esp-md5-hmac
!
!
crypto map cmap1 local-address serial 0
crypto map cmap1 1 ipsec-isakmp
set peer 202.102.1.6
set peer 192.168.1.2
set transform-set test1
match address 111
!
!
process-max-time 200
!
interface Tunnel0
ip address 192.168.1.1 255.255.255.0
tunnel source 202.102.1.5
tunnel destination 202.102.1.6
crypto map cmap
!
interface Ethernet0
ip address 10.1.1.1 255.255.255.0
!
interface serial0
ip address 202.102.1.5 255.255.255.0
no ip mroute-cache
no fair-queue
crypto map cmap
!
ip classless
!
access-list 111 permit ip host 202.102.1.5 host 202.102.1.6
access-list 111 permit ip host 202.102.1.6 host 202.102.1.5
access-list 111 permit ip 10.1.1.0 0.0.0.255 202.102.1.0 0.0.0.255
access-list 111 permit ip 10.1.2.0 0.0.0.255 202.102.1.0 0.0.0.255
access-list 111 permit ip 10.1.1.0 0.0.0.255 10.1.2.0 0.0.0.255
access-list 111 permit ip 10.1.2.0 0.0.0.255 10.1.1.0 0.0.0.255
!
line con 0
line aux 0
line vty 0 4
password cisco
login
!
end
!
网络2配置:
!
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname shanghai
!
enable cisco
!
!
crypto isakmp policy 1
encryption des
hash sha
authentication pre-share
group 1
lifetime 14400
crypto isakmp identity address crypto isakmp key 654321 address 202.102.1.5
crypto isakmp key 654321 address 202.102.1.6
crypto isakmp key 654321 address 192.168.1.1
crypto ipsec transform-set tset1 ah-md5-hmac esp-des esp-md5-hmac
!
!
crypto map cmap1 local-address serial 0
crypto map cmap1 1 ipsec-isakmp
set peer 202.102.1.5
set peer 202.102.1.6
set peer 192.168.1.1
set transform-set test1
match address 111
!
!
process-max-time 200
!
interface Tunnel0
ip address 192.168.1.2 255.255.255.0
tunnel source 202.102.1.6
tunnel destination 202.102.1.5
crypto map cmap
!
interface Ethernet0
ip address 10.1.2.1 255.255.255.0
!
interface serial0
ip address 202.102.1.6 255.255.255.0
no ip mroute-cache
no fair-queue
crypto map cmap
!
ip classless
!
access-list 111 permit ip host 202.102.1.5 host 202.102.1.6
access-list 111 permit ip host 202.102.1.6 host 202.102.1.5
access-list 111 permit ip 10.1.1.0 0.0.0.255 202.102.1.0 0.0.0.255
access-list 111 permit ip 10.1.2.0 0.0.0.255 202.102.1.0 0.0.0.255
access-list 111 permit ip 10.1.1.0 0.0.0.255 10.1.2.0 0.0.0.255
access-list 111 permit ip 10.1.2.0 0.0.0.255 10.1.1.0 0.0.0.255
!
line con 0
line aux 0
line vty 0 4
password cisco
login
!
end
!
不知道是否配置有问题,怎样才能使内网10.1.1.0/24与内网10.1.2.0/24互通呢?请大家帮忙看看吧!
|
 千里之外,传递你对震灾人民的关怀 |
|