欢迎来到天天文库
浏览记录
ID:33864687
大小:308.49 KB
页数:19页
时间:2019-03-01
《vpn分解试验指南_vol.1_basic_vpn_version_1.0.pdf》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、WOLFVPN分解试验指南VOL.1VPN基本部分Version1.0作者:秦柯Email:cq_bomb@hotmail.comSecurityCCIE#137782004年12月30日1目录1.Site-to-SiteVPNP32.PIXFirewallSitetoSiteVPNConfigurationP53.静态VS.动态CryptoMapP74.IPSECoverGREConfigurationP95.GREoverIPSECConfigurationP135.1ciscoIOS12.2(13)T
2、andlaterconfigurationP156.GeographicHAusingipsecBackuppeersP167.ipsec穿越pat(应用层网关)P182Site-to-SiteVPNtopology10.1.1.0/24-router1-172.16.171.10----172.16.171.20-router2-10.1.2.0/24BasicrouteRouter1:iproute0.0.0.00.0.0.0172.16.171.20Router2:iproute0.0.0.00.0.
3、0.0172.16.171.10IKEPhaseIpolicyRouter1:cryptoisakmppolicy1authenticationper-sharedhashmd5encr3desgroup2cryptoisakmpkeyciscoaddress172.16.171.20Router2:cryptoisakmppolicy1authenticationper-sharedhashmd5encr3desgroup2cryptoisakmpkeyciscoaddress172.16.171.10I
4、PSecPhaseIIpolicyRouter1:cryptoipsectransform-setciscoesp-desesp-sha-hmacaccess-list101permitip10.1.1.00.0.0.25510.1.2.00.0.0.255cryptomapcisco10ipsec-isakmpsetpeer172.16.171.20settransform-setciscosetpfsmatchaddress101Router2:cryptoipsectransform-setcisco
5、esp-desesp-sha-hmacaccess-list101permitip10.1.2.00.0.0.25510.1.1.00.0.0.255cryptomapcisco10ipsec-isakmpsetpeer172.16.171.10settransform-setcisco3setpfsmatchaddress101ApplyVPNConfigurationRouter1:interfaces0cryptomapciscoRouter2:interfaces0cryptomapcisco4PI
6、XFirewallSitetoSiteVPNConfigurationTopologyInsideoutsideoutsideinside10.1.1.0/24-PIX1-172.16.171.10----172.16.171.20-PIX2-10.1.2.0/24BasicroutePIX1:Routeoutside00172.16.171.20PIX2:Routeoutside00172.16.171.10DefineIKEPhaseIpolicyPIX1:isakmpenableoutsideisak
7、mppolicy1authenticationpre-shareisakmppolicy1encryption3desisakmppolicy1hashmd5isakmppolicy1group2isakmppolicy1lifetime86400isakmpkeyciscoaddress172.16.171.20PIX2:isakmpenableoutsideisakmppolicy1authenticationpre-shareisakmppolicy1encryption3desisakmppolic
8、y1hashmd5isakmppolicy1group2isakmppolicy1lifetime86400isakmpkeyciscoaddress172.16.171.10DefineIKEPhaseIIpolicyPIX1:access-listvpnaclpermitip10.1.1.0255.255.255.010.1.2.0255.255.255.0cryptoipsectransform-setmy
此文档下载收益归作者所有