欢迎来到天天文库
浏览记录
ID:39465131
大小:102.00 KB
页数:13页
时间:2019-07-04
《L2TP OVER IPSEC(LNS地址在内网,通过公网映射)》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、L2TPOVERIPSEC(LNS地址在内网,通过公网映射)组网LAC公网地址为202.109.207.163,LNS在用户内网地址为172.20.210.10,通过映射为公网地址117.27.234.103。用户需求:PC用户通过PPPOE拨号到LAC出发L2TP隧道建立,同时要求做IPSEC加密。配置:LAC:discu#version5.20,Release2512P04#sysnamelac#l2tpenable#domaindefaultenablesystem#ipv6#telnetserver
2、enable#port-securityenable#password-recoveryenable#aclnumber3500rule5permitipsource202.109.207.1630destination172.20.210.100rule10permitipsource172.20.210.100destination202.109.207.1630#vlan1#Ddomainh3c.comauthenticationppplocalaccess-limitdisablestateactiveidl
3、e-cutdisableself-service-urldisabledomainsystemaccess-limitdisablestateactiveidle-cutdisableself-service-urldisable#ikepeerlacexchange-modeaggressivepre-shared-keycipher$c$3$1x8s/6RGe2wayz2b/ilLMlHyJ86Kag==id-typenameremote-namelnsremote-address117.27.234.103lo
4、cal-address202.109.207.163local-namelacnattraversal#ipsectransform-setlacencapsulation-modetunneltransformespespauthentication-algorithmsha1espencryption-algorithm3des#ipsecpolicylac1isakmpsecurityacl3500ike-peerlactransform-setlac#user-groupsystemgroup-attribu
5、teallow-guest#local-useradminpasswordcipher$c$3$EiAlBrd/gVGFvSMRAmLoJwgze3wHlYa1BQ==authorization-attributelevel3service-typetelnetservice-typeweblocal-usertestpasswordcipher$c$3$SQ3SM2FRQoXeMijjRitI72ToSwbJ9f09xw==service-typeppp#l2tp-group1tunnelpasswordciphe
6、r$c$3$TVsHV3HQRBs5eubLlDPrKCp8o8kwnA==tunnelnamelacstartl2tpip172.20.210.10domainh3c.com#interfaceAux0asyncmodeflowlink-protocolppp#interfaceCellular0/0asyncmodeprotocollink-protocolppp#interfaceVirtual-Template1pppauthentication-modepapchapdomainh3c.com#interf
7、aceNULL0#interfaceVlan-interface1pppoe-serverbindVirtual-Template1ipaddress192.168.1.1255.255.255.0#interfaceGigabitEthernet0/0portlink-moderouteipaddress202.109.207.163255.255.255.248ipsecpolicylac#interfaceGigabitEthernet0/1portlink-modebridge#interfaceGigabi
8、tEthernet0/2portlink-modebridge#interfaceGigabitEthernet0/3portlink-modebridge#interfaceGigabitEthernet0/4portlink-modebridge#iproute-static0.0.0.00.0.0.0202.109.207.161ipro
此文档下载收益归作者所有