配置预共享密钥,密钥是admin ,远程对等体的IP地址为192.168.1.2
r2(config)#crypto isakmp enable
r2(config)#
r2(config)#
r2(config)#cry
r2(config)#crypto is
r2(config)#crypto isakmp p
r2(config)#crypto isakmp p?
peer policy profile
r2(config)#crypto isakmp policy 10
r2(config-isakmp)#authentication pre-share
r2(config-isakmp)#authentication pre
r2(config-isakmp)#encryption ?
3des Three key triple DES
aes AES - Advanced Encryption Standard.
des DES - Data Encryption Standard (56 bit keys).
r2(config-isakmp)#encryption 3des
r2(config-isakmp)#group 5
r2(config-isakmp)#hash sha
r2(config-isakmp)#lifetime ?
<60-86400> lifetime in seconds
r2(config-isakmp)#lifetime 86400
r2(config-isakmp)#exit
r2(config)#crypto isakmp key admin add 192.168.1.1
第三步:配置IPSEC变换集
r1(config)#crypto ipsec transform-set r1set esp-3des esp-md5-hmac 创建一个交换集是ipsec,交换集定义数据流量如何被保护如果不配置连接模式,默认是TUNNEL,mode tunnel
r1(cfg-crypto-trans)#exit
r1(config)#crypto map r1vpn 10 ipsec-isakmp 创建一张MAP表r1vpn,并关联优先集为10的isakmp设置
% NOTE: This new crypto map will remain disabled until a peer
and a valid access list have been configured.
r1(config-crypto-map)#set peer 192.168.1.2 配置对等体的地址
r1(config-crypto-map)#set transform-set r1set 将交换集与r1vpn表关联
r1(config-crypto-map)#match add ?
<100-199> IP access-list number
<2000-2699> IP access-list number (expanded range)
WORD Access-list name
r1(config-crypto-map)#match add 100将拓展访问控制列表应用到r1vpn中去
(引用扩展ACL)
r2(config)#crypto ipsec transform-set r2set esp-3des esp-md5-hmac
r2(cfg-crypto-trans)#exit
r2(config-crypto-map)#set peer 192.168.1.1 配置对等体的地址
r2(config-crypto-map)#set transform-set r2set
r2(config-crypto-map)#match address 100
r2(config)#cry map r2vpn 10 ipsec-isakmp
% NOTE: This new crypto map will remain disabled until a peer
and a valid access list have been configured.
r2(config-crypto-map)#match address 100
第四步:定义触发流量,即IPSEC连接保护何种流量
r1#conf t
Enter configuration commands, one per line. End with CNTL/Z.
r1(config)#acce 100 per icmp 1.1.1.1 0.0.0.0 2.2.2.2 0.0.0.0
定义对icmp的数据进行IPSEC保护
r1(config)#int e0/0
r1(config-if)#cry map r1vpn 将加密映射应运与接口
*Mar 1 01:26:09.023: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
r2(config)#access-list 100 per icmp 2.2.2.2 0.0.0.0 1.1.1.1 0.0.0.0
配置r2上ACL 必须为r1上的镜像
r2(config)#int e0/0
r2(config-if)#cry map r2vpn
责任编辑:小草