Cisco 路由器 VPN典型配置

网络 路由交换
对于思科路由器,如果进行VPN配置,要进行怎样的配置呢?下面文章主要从SHOW RUN中介绍了配置的具体操作步骤和基本的配置命令。

本文通过VPN技术实现对两部分网络的互联,模拟ISP,贴近实用性,文章主要向我们展示了具体的操作步骤,主要是输入的基本命令。

本实验借助于Cisco 2600 路由器,通过VPN技术实现蓝色学苑,一分部和二分部之间的网络互联,为了贴近实用性,中间仍然通过Cisco 3640 模拟ISP 。

通过在网络基础部分的介绍,各位应该对VPN技术有了一定的认识,在VPN的实现中主要有两个方面:建立VPN Tunnel和IPSec的加密

Cisco 2600 with GRE Tunnel
Current configuration
!
version 12.0
sevice timestamps debug uptime
sevice timestamps log uptime
sevice password-encryption
!
hostname bluestudy1
!
enable passsword cisco
!
memory-size iomem 25
ip subnet-zero
no ip domain-lookup
!
interface Tunnel0
ip address 172.16.101.1 255.255.255.0
no ip directed-broadcast
ip mtu 1467
tunnel sourece 199.1.1.2
tunnel destination 199.1.2.2
!
interface serial0/0
no ip address
no ip directed-broadcast
encapsulation frame-relay
no ip mroute-cache
frame-relay lmi-type ansi
!
interface serial0/0.1 point-to-point
description connected to internet
ip address 199.1.1.2 255.255.255.248
no ip directed-broadcast
ip nat outside
no arp frame-relay
frame-relay interface-dlci 111
!
!
interface ethernet0/0
ip address 172.16.1.1 255.255.255.0
no ip directed-broadcast
ip nat inside
!
router eigrp 100
network 172.16.0.0
!
router rip
version 2
network 172.16.0.0
no auto-summary
!
ip nat pool bluestudy 199.1.1.3 199.1.1.10 netmask 255.255.255.248
ip nat inside sourece list 2 pool bluestudy overload
ip nat inside sourece static 172.16.1.3 199.1.1.5
ip classless
ip route 0.0.0.0 0.0.0.0 srial0/0.1
ip http server
!
access-list 2 permit 172.16.1.0 0.0.0.255
snmp-server community public RO
!
line con 0
exec-timeout 0 0
password cisco
login
transport input none
line aux 0
line vty 0 4
password cisco
login
!
end#p#

Cisco 2600 Configuration with IPSec
Current configuration
!
version 12.0
sevice timestamps debug uptime
sevice timestamps log uptime
sevice password-encryption
!
hostname bluestudy1
!
enable passsword cisco
!
memory-size iomem 25
ip subnet-zero
no ip domain-lookup
!
crypto isakmp key policy 1
authentication pre-share
group 2
crypto isakmp key slurpee-machine address 172.16.101.2
!
crypto ipsec transform-set test ah-sha-hmac esp-des esp-sha-hmac
!
set transform-set test
!
crypto map bluestudy 10 ipsec-isakmp
set peer 172.16.101.2
set transform-set test
match address 101
!
interface Tunnel0
ip address 172.16.101.1 255.255.255.0
no ip directed-broadcast
ip mtu 1467
tunnel sourece 199.1.1.2
tunnel destination 199.1.2.2
crypto map bluestudy
!
interface serial0/0
no ip address
no ip directed-broadcast
encapsulation frame-relay
no ip mroute-cache
frame-relay lmi-type ansi
!
interface serial0/0.1 point-to-point
description connected to internet
ip address 199.1.1.2 255.255.255.248
no ip directed-broadcast
ip nat outside
no arp frame-relay
frame-relay interface-dlci 111
!
!
interface ethernet0/0
ip address 172.16.1.1 255.255.255.0
no ip directed-broadcast
ip nat inside
!
router eigrp 100
network 172.16.0.0
!
router rip
version 2
network 172.16.0.0
no auto-summary
!
ip nat pool bluestudy 199.1.1.3 199.1.1.10 netmask 255.255.255.248
ip nat inside sourece list 2 pool bluestudy overload
ip nat inside sourece static 172.16.1.3 199.1.1.5
ip classless
ip route 0.0.0.0 0.0.0.0 srial0/0.1
ip http server
!
access-list 2 permit 172.16.1.0 0.0.0.255
access-list 101 permit ip 172.16.1.0 0.0.0.255 172.16.2.0 0.0.0.255(对方网络,只有到这个网络的信息包才加密)
snmp-server community public RO
!
line con 0
exec-timeout 0 0
password cisco
login
transport input none
line aux 0
line vty 0 4
password cisco
login
!
end

 

【编辑推荐】

  1. 思科精睿系列网络产品煤炭行业解决方案
  2. 思科助力天津大学打造稳定网络
  3. Avaya频推新品 紧盯微软与思科
  4. 思科:把握移动互联网产业契机
  5. 思科将最新网络架构引入区域市场
责任编辑:chenqingxiang 来源: IT168
相关推荐

2009-12-01 10:35:50

Cisco 路由器VP

2009-04-14 09:48:00

cisco路由器配置

2010-08-06 10:21:38

路由器配置

2012-03-02 14:17:03

2010-08-03 11:35:06

2012-03-20 10:05:57

Cisco路由器路由器DNS

2010-08-04 13:27:07

路由器配置

2011-04-01 16:03:18

IOS路由器

2011-07-21 11:00:14

2011-07-21 11:13:12

2010-08-26 09:55:25

Cisco路由器DHCP

2010-08-12 08:57:25

2009-12-11 15:21:15

华为路由器CISCO路由器

2011-03-07 17:34:35

IGRP

2010-08-23 09:21:34

路由器WCCP

2010-08-26 15:40:08

Cisco路由器DHC

2011-07-29 09:24:31

路由器配置

2009-12-02 15:58:55

Cisco路由器配置命

2010-08-03 13:28:57

2009-12-21 10:15:57

点赞
收藏

51CTO技术栈公众号