思科防火墙PIX8.0 L2LVPN解决地址重叠测试(2)(3)
2013-07-04 01:41
浏览:
也可以写得更详细:
access-list VPN extended permit ip host 172.16.1.2 host 10.1.2.2
④配置crypto map并应用:
crypto map crymap 10 match address VPN
crypto map crymap 10 set peer 202.100.2.1
crypto map crymap 10 set transform-set transet
crypto map crymap interface Outside
⑤在接口启用isakmp:
crypto isakmp enable Outside
B.PIX80_Branch防火墙:
①第一阶段策略:
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash md5
group 2
tunnel-group 202.100.1.1 type ipsec-l2l
tunnel-group 202.100.1.1 ipsec-attributes
pre-shared-key cisco
②第二阶段转换:
crypto ipsec transform-set transet esp-des esp-md5-hmac
③感兴趣流:
access-list VPN extended permit ip 10.1.2.0 255.255.255.0 172.16.1.0 255.255.0.0
也可以写得更详细:
access-list VPN extended permit ip host 10.1.2.2 host 172.16.1.2
④配置crypto map并应用:
crypto map crymap 10 match address VPN
crypto map crymap 10 set peer 202.100.1.1
crypto map crymap 10 set transform-set transet
crypto map crymap interface Outside
⑤在接口启用isakmp:
crypto isakmp enable Outside
七.测试:
A.连接公网测试:
①ERP_HQ路由器:
ERP_HQ#ping 202.100.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 202.100.1.10, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/94/292 ms
ERP_HQ#
Internet#debug ip icmp
ICMP packet debugging is on
Internet#
*Mar 2 07:36:11.648: ICMP: echo reply sent, src 202.100.1.10, dst 202.100.1.1
*Mar 2 07:36:11.768: ICMP: echo reply sent, src 202.100.1.10, dst 202.100.1.1
*Mar 2 07:36:11.856: ICMP: echo reply sent, src 202.100.1.10, dst 202.100.1.1
*Mar 2 07:36:12.096: ICMP: echo reply sent, src 202.100.1.10, dst 202.100.1.1
*Mar 2 07:36:12.132: ICMP: echo reply sent, src 202.100.1.10, dst 202.100.1.1
②ERP_Brach路由器:
ERP_Branch#ping 202.100.2.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 202.100.2.10, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/92/344 ms
ERP_Branch#
Internet#debug ip icmp
- -
-
- 相关推荐
- 半年热点
-
tplogin.cn修改wifi密码
浏览: 59
电脑如何设置TP-LINK路由器?
浏览: 146
192.168.1.1打不开怎么办(二)
浏览: 174
【教程】怎么在手机上修改路由器的WIFI密码
浏览: 147
TP-LINK无线、有线路由器详细设置教程
浏览: 74
小米路由器AC2100连不上网怎么办?
浏览: 198
Fast(迅捷)无线路由器怎么设置
浏览: 172
腾达路由器怎么安装设置?Tenda路由器怎么设置
浏览: 93
192.168.0.1路由器密码设置
浏览: 170
192.168.0.1路由器接线方法
浏览: 78
TP-LINK路由器设置教程
浏览: 70
Fast(迅捷)无线路由器设置教程
浏览: 173
【视频教程】迅捷(Fast)路由器如何设置?
浏览: 104