设为首页收藏本站

美丽的网站-英华家电维修论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

查看: 552|回复: 0
打印 上一主题 下一主题

路由器-路由器以及VPN Client之间的VPN

[复制链接]
跳转到指定楼层
楼主
发表于 2011-3-28 08:33:47 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
screen.width-333)this.width=screen.width-333" border=0>Cisco 2611 Routervpn2611#show runBuilding configuration...Current configuration : 2265 bytes!version 12.2service timestamps debug uptimeservice timestamps log uptimeno service password-encryption!hostname vpn2611!!--- Enable aaa for user authentication !--- and group authorization.aaa new-model!!!--- To enable X-Auth for user authentication, !--- enable the aaa authentication commands.aaa authentication login userauthen local!--- To enable group authorization, enable !--- the aaa authorization commands.aaa authorization network groupauthor local aaa session-id common!!--- For local authentication of the IPSec user, !--- create the user with password.username cisco password 0 ciscoip subnet-zero!!!ip audit notify logip audit po max-events 100!!--- Create an Internet Security Association and !--- Key Management Protocol (ISAKMP) !--- policy for Phase 1 negotiations for the VPN 3.x clients.crypto isakmp policy 3encr 3desauthentication pre-sharegroup 2!!--- Create an ISAKMP policy for Phase 1 !--- negotiations for the LAN-to-LAN tunnels.crypto isakmp policy 10hash md5authentication pre-share!--- Specify the PreShared key for the LAN-to-LAN tunnel. !--- Make sure that you use !--- no-xauth parameter with your ISAKMP key.crypto isakmp key cisco123 address 172.18.124.199 no-xauth!!--- Create a group that will be used to !--- specify the WINS, DNS servers' address!--- to the client, along with the pre-shared !--- key for authentication.crypto isakmp client configuration group 3000clientkey cisco123dns 10.10.10.10wins 10.10.10.20domain cisco.compool ippool!!!--- Create the Phase 2 Policy for actual data encryption.crypto ipsec transform-set myset esp-3des esp-md5-hmac !!--- Create a dynamic map and apply !--- the transform set that was created above.crypto dynamic-map dynmap 10set transform-set myset !!!--- Create the actual crypto map, and !--- apply the aaa lists that were created !--- earlier. Also create a new instance for your !--- LAN-to-LAN tunnel. Specify the peer IP address, !--- transform set and an Access Control List (ACL) for this !--- instance.crypto map clientmap client authentication list userauthencrypto map clientmap isakmp authorization list groupauthorcrypto map clientmap client configuration address respondcrypto map clientmap 1 ip       1/3 123下一页尾页
分享到:  QQ好友和群QQ好友和群 QQ空间QQ空间 腾讯微博腾讯微博 腾讯朋友腾讯朋友 微信微信
收藏收藏 分享分享 支持支持 反对反对
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

关闭

站长推荐上一条 /1 下一条

QQ|手机版|粤ICP备13038386号|粤ICP备13038386号|美丽的网站-英华家电维修论坛 ( 粤ICP备13038386号 )     站长邮箱 505966338@qq.com

GMT+8, 2025-5-4 08:45 , Processed in 0.131081 second(s), 22 queries .

Powered by Discuz! X3.2

© 2001-2013 Comsenz Inc.

快速回复 返回顶部 返回列表