欢迎来到天天文库
浏览记录
ID:11593934
大小:235.00 KB
页数:16页
时间:2018-07-12
《ipsec vpn对等体冗余之hsrp冗余实验配置》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、IpsecVPN对等体冗余之HSRP冗余(无状态化故障切换)实验配置SPOKE,Internal-router的loopback0接口模拟内部网络,VPNHUB1,VPNHUB2模拟VPNgateway,并且他们之间允许HSRP以提供VPNgateway的冗余,VPNHUB1,VPNHUB2的HSRPtrack接口为其自身的loopback0。SPOKE启用VPN失效对等体检测(DPD),以此检测远程VPNgateway是否存活,进而delete失效对等体的SA,当有感兴趣流时重新发起IPSECVP
2、N连接,连接到冗余的VPNgateway上。由于本实验使用的IOS不支持SSP,因此无法模拟状态化故障切换。VPNHUB间进行的是无状态好故障切换。VPNgateway内部网络运行OSPF协议,并且需要将VPNreverse-routeredistribute进OSPF以便内部网络获悉SPOKE端内部网络路由。SPOKEconfigurationSPOKE#shrunBuildingconfiguration...Currentconfiguration:1396bytes!version12.4s
3、ervicetimestampsdebugdatetimemsecservicetimestampslogdatetimemsecnoservicepassword-encryption!hostnameSPOKE!boot-start-markerboot-end-marker!!noaaanew-modelmemory-sizeiomem5!!ipcefnoipdomainlookup!!!!!!!!cryptoisakmppolicy10hashmd5authenticationpre-sha
4、regroup2cryptoisakmpkeyxinjialoveaddress172.16.2.1#HSRPstandbyvirtualIPcryptoisakmpkeepalive103periodic!!cryptoipsectransform-setxinjialoveesp-desesp-md5-hmac!cryptomapxinjialove10ipsec-isakmpsetpeer172.16.2.1settransform-setxinjialovematchaddress100!!
5、!!interfaceLoopback0ipaddress1.1.1.1255.255.255.255!interfaceFastEthernet0/0noipaddressshutdownduplexautospeedauto!interfaceSerial1/0noipaddressshutdownserialrestart-delay0!interfaceSerial1/1ipaddress172.16.1.1255.255.255.0serialrestart-delay0cryptomap
6、xinjialove!interfaceSerial1/2noipaddressshutdownserialrestart-delay0!interfaceSerial1/3noipaddressshutdownserialrestart-delay0!interfaceFastEthernet2/0noipaddressshutdownduplexautospeedauto!iphttpservernoiphttpsecure-server!iproute0.0.0.00.0.0.0Serial1
7、/1!!access-list100permitiphost1.1.1.1host5.5.5.5!!control-plane!!!!!!linecon0loggingsynchronouslineaux0linevty04!!endVPNHUB1configurationVPNHUB1#shrunBuildingconfiguration...Currentconfiguration:1578bytes!version12.4servicetimestampsdebugdatetimemsecse
8、rvicetimestampslogdatetimemsecnoservicepassword-encryption!hostnameVPNHUB1!boot-start-markerboot-end-marker!!noaaanew-model!resourcepolicy!ipcef!!!!noipdomainlookup!!!!!!!!cryptoisakmppolicy10hashmd5authenticationpre-sharegroup2cryptois
此文档下载收益归作者所有