×¢²á | µÇ¼ Íü¼ÇÃÜÂ룿 51ctoÊ×Ò³ | ²©¿Í | ÂÛ̳ | ÕÐÆ¸
ÈȵãÎÄÕ [ÒµÄÚ´«ÎÅ]½ñÌ죬7ÔÂ25ÈÕ..
¡¡°ïÖú

Cisco·ÓÉÆ÷VPN»ù±¾ÅäÖÃ


2007-11-04 10:22:34
¡¡±êÇ©£ºÍøÂç¼¼Êõ¡¡¡¡¡¡[ÍÆË͵½¼¼ÊõȦ]

Ò»¡¢hostµ½router
1¡¢ÊµÑéÍøÂçÍØÆË£º

pc£¨vpn client 4.01£©£­£­£­switch£­£­£­router1720 £¨vpn access server£©

pcÅäÖÃ:
ip£º10.130.23.242/28
gw£º10.130.23.246
1720½Ó¿Úip£º
f0£º10.130.23.246/28
lo0£º172.16.1.1/24
1720µÄiosΪc1700-k93sy7-mz.122-8.T5.bin

2¡¢²½Ö裺
1¡¢ÅäÖÃisakmp policy£º
crypto isakmp policy 1
encr 3des
authen pre-share
group 2
2¡¢ÅäÖÃvpn clientµØÖ·³Ø
cry isa client conf address-pool local pool192
ip local pool pool192 192.168.1.1 192.168.1.254
3¡¢ÅäÖÃvpn clientÓйزÎÊý
cry isa client conf group vclient-group
####vclient-group¾ÍÊÇÔÚvpn clientµÄÁ¬½ÓÅäÖÃÖÐÐèÒªÊäÈëµÄgroup authentication name¡£
key vclient-key
####vclient-key¾ÍÊÇÔÚvpn clientµÄÁ¬½ÓÅäÖÃÖÐÐèÒªÊäÈëµÄgroup authentication password¡£
pool pool192 ####clientµÄipµØÖ·´ÓÕâÀïѡȡ
####ÒÔÉÏÁ½¸ö²ÎÊý±ØÐëÅäÖã¬ÆäËû²ÎÊý»¹°üÀ¨domain¡¢dns¡¢winsµÈ£¬¸ù¾ÝÇé¿ö½øÐÐÅäÖá£
4¡¢ÅäÖÃipsec transform-set
cry ipsec trans vclient-tfs esp-3des esp-sha-hmac
5¡¢ÅäÖÃmapÄ£°å
cry dynamic-map template-map 1
set transform-set vclient-tfs ####ºÍµÚËIJ½¶ÔÓ¦
6¡¢ÅäÖÃvpnmap
cry map vpnmap 1 ipsec-isakmp dynamic template-map
#### ʹÓõÚ?*½ÅäÖõ?map Ä£°å
cry map vpnmap isakmp author list vclient-group ####ʹÓõÚÈý²½ÅäÖõIJÎÊýauthorization
cry map vpnmap client conf address respond ####ÏìÓ¦client·ÖÅ䵨ַµÄÇëÇó
7¡¢ÅäÖþ²Ì¬Â·ÓÉ
ip route 192.168.1.0 255.255.255.0 fastethernet0

3¡¢ËµÃ÷¼¸µã£º
£¨1£©ÒòΪ1720Ö»ÓÐÒ»¸öfastethernet¿Ú£¬ËùÒÔÓÃrouter1720ÉϵÄlo0µØÖ·À´Ä£ÄârouterÄÚ²¿ÍøÂç¡£
£¨2£©vpn clientʹÓõÄip poolµØÖ·²»ÄÜÓërouterÄÚ²¿ÍøÂçipµØÖ·Öصþ¡£
£¨3£©10.130.23.0Íø¶ÎÄ£Äâ¹«ÍøµØÖ·£¬172.16.1.0Íø¶ÎÓÃÓÚ1720ÄÚ²¿µØÖ·£¬192.168.1.0Íø¶ÎÓÃÓÚvpnͨµÀ¡£
£¨4£©Ã»ÓÐÕÒµ½ÉèÖÃvpn client»ñÈ¡µÄ×ÓÍøÑÚÂëµÄ°ì·¨¡£¿´À´ÊÇios»¹²»Ö§³ÖÕâ¸ö¹¦ÄÜ¡£
£¨5£©¹ØÓÚsplit tunnel¡£ÅäÖ÷½·¨£ºÊ×ÏÈ£¬ÉèÖÃaccess 133 permit ip 172.16.1.0 0.0.0.255 any£¬ÔÊÐí1720±¾µØÍøÂçÊý¾Ýͨ¹ýtunnel£¬È»ºóÔÚµÚÈý²½ÖèÖÐÌí¼ÓÒ»¸ö²ÎÊý£ºacl 133¡£

4¡¢¸½1720µÄÍêÕûÅäÖãº

VPN1720#sh run
Building configuration...

Current configuration : 1321 bytes
!
version 12.2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname VPN1720
!
enable secret 5 $1$aNmA$b0AqzlCr3MfM5XU0IAmED.
!
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
ip subnet-zero
!
!
no ip domain-lookup
!
ip audit notify log
ip audit po max-events 100
!
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp client configuration address-pool local pool192
!
crypto isakmp client configuration group vclient-group
key vclient-key
domain test.com
pool pool192
!
!
crypto ipsec transform-set vclient-tfs esp-3des esp-sha-hmac
!
crypto dynamic-map template-map 1
set transform-set vclient-tfs
!
!
crypto map vpnmap isakmp authorization list vclient-group
crypto map vpnmap client configuration address respond
crypto map vpnmap 1 ipsec-isakmp dynamic template-map
!
!
!
!
interface Loopback0
ip address 172.16.1.1 255.255.255.240
!
interface FastEthernet0
ip address 10.130.23.246 255.255.255.240
speed auto
crypto map vpnmap
!
interface Serial0
no ip address
shutdown
!
ip local pool pool192 192.168.1.1 192.168.1.254
ip classless
ip route 192.168.1.0 255.255.255.0 FastEthernet0
no ip http server
ip pim bidir-enable
!
!
!
!
line con 0
line aux 0
line vty 0 4
!
no scheduler allocate
end

VPN Client 4.01µÄÅäÖãº
н¨Ò»¸öconnection entry£¬²ÎÊýÖÐnameÈÎÒâÆðÒ»¸ö£¬hostÌîÈëvpn access serverµÄf0µØÖ·10.130.23.246£¬
group auahenticationÖÐnameÌîvclient-group£¬passwordÌîvclient-key.

5¡¢²âÊÔ£º
£¨1£©ÔÚpcÉÏÔËÐÐVPN client£¬Á¬½Óvpn access server¡£
£¨2£©ipconfig/all£¬²é¿´»ñÈ¡µ½µÄipµØÖ·ÓëÆäËû²ÎÊý¡£
£¨3£©ÔÚrouter£¬show cry isa sa,¿´Á¬½ÓÊÇ·ñ³É¹¦¡£
£¨4£©´Órouter£¬ping clientÒѾ­»ñÈ¡µ½µÄipµØÖ·£¬Í¨¹ý¡£
£¨5£©´Óclient£¬ping routerµÄlo0ÅäÖõĵØÖ·172.16.1.1£¬Í¨¹ý¡£
£¨6£©²é¿´vpn clientÈí¼þµÄstatus--statistics,¿ÉÒÔ¿´µ½¼ÓÃÜÓë½âÃܵÄÊý¾ÝÁ¿¡£
£¨7£©1720ÉÏshow cry ip sa, Ò²¿ÉÒԲ鿴¼ÓÃÜÓë½âÃܵÄÊý¾ÝÁ¿¡£


6¡¢³£Óõ÷ÊÔ
show cry isakmp sa
show cry ipsec sa
clear cry sa
clear cry isakmp
debug cry isakmp #####ÕâÊÇ×î³£ÓõÄdebugÃüÁvpnÁ¬½ÓµÄ»ù±¾´íÎ󶼿ÉÒÔÓÃËüÀ´ÕÒµ½
debug cry ipsec
¶þ¡¢easy vpn clientµÄÅäÖã¨network-extension mode£©

ʵÑéÍøÂçÍØÆË£º

router3662£¨vpn client£©£­£­£­switch£­£­£­router1720 £¨vpn access server£©
pc (vpn client 4.01)£­£­£­£­£­£­|

3662½Ó¿Úip:
f0/0£º10.130.23.244/28
f0/1£º172.16.2.1/24
1720½Ó¿Úip£º
f0£º10.130.23.246/28
lo0£º172.16.1.1/24
pcÅäÖÃ:
ip£º10.130.23.242/28
gw£º10.130.23.246
1720µÄiosΪc1700-k93sy7-mz.122-8.T5.bin
3662µÄiosΪc3660-jk9o3s-mz.123-1a.bin

²½Ö裺
1¡¢ÅäÖÃ1720·ÓÉÆ÷£¬²ÎÕÕʵÑéÒ»£¬ÉèÖÃΪvpn server¡£
2¡¢ÅäÖÃ3662·ÓÉÆ÷£¬ÉèÖÃvpn client²ÎÊý
cry ip client ezvpn vclient ####¶¨Òåcrypto-ezvpn name
mode network-extension ####ÉèÖÃÎªÍøÂçÀ©Õ¹Ä£Ê½
group vclient-group key vclient-key ####ÉèÖõǼvpn serverµÄ×éÃûÓë×é¿ÚÁî
peer 10.130.23.246 ####ÉèÖÃvpn serverµÄipµØÖ·£¬Èç¹ûÆôÓÃdns£¬Ôò¿ÉÒÔÓÃhostname
connect auto ####ÉèÖÃΪ×Ô¶¯Á¬½Ó¡£Èç¹ûÉèΪÊÖ¶¯£¬Ôò±ØÐëʹÓÃcry ip client ezvpn connect vclientÃüÁîÀ´Æô¶¯vpnͨµÀ¡£
local-address F0/0 ####ÉèÖÃvpnͨµÀ±¾µØµØÖ·£¬Ñ¡ÓÃf0/0£¬¿ÉÒÔ±£Ö¤vpn serverÕÒµ½Ëü
3¡¢¶¨Òå¼ÓÃÜÊý¾ÝÈë¿Ú£¬ÕâÀïΪf0/1
inter f0/1
cry ip client ezvpn vclient inside
4¡¢¶¨Òå¼ÓÃÜÊý¾Ý³ö¿Ú£¬ÕâÀïΪÁ¬½Óvpn serverµÄf0/0
inter f0/0
cry ip client ezvpn vclient outside
5¡¢ÔÚ1720ÉÏÉèÖþ²Ì¬Â·ÓÉ£¬µØÖ··¶Î§Îª3662·Óɱ¾µØÍøÂçµÄµØÖ·
ip route 172.16.2.0 255.255.255.0 f0
6¡¢ÉèÖÃip dhcp·þÎñ ####ciscoÍÆ¼öʹÓÃdhcpÀ´½øÐб¾µØÍøÂçipµÄ·ÖÅä¡£´Ë²½Öè¿ÉÑ¡¡£
service dhcp ####Æô¶¯dhcp ·þÎñ
ip dhcp pool dhcppool ####¶¨Òådhcp pool name
network 172.16.2.0 /24 ####¶¨Òå¿É·ÖÅäµÄIPµØÖ·¶Î
default-router 172.16.2.1 ####¶¨Òådhcp clientµÄĬÈÏÍø¹Ø
lease 1 0 0 ####ÉèÖÃip±£Áôʱ¼ä
import all ####Èç¹ûÅäÖÃÁËÉϼ¶dhcp£¬server£¬Ôò½ÓÊÜÆäËùÓвÎÊý
ip dhcp excluded-address 172.16.2.1 ####½«routerÉϵĵØÖ·Åųý


²âÊÔ£º
£¨1£©ÅäÖúÃ3662ÉϵÄvpn clientºó£¬×Ô¶¯½øÐÐvpnÁ¬½Ó¡£¿ÉÒÔͨ¹ýdebug cry isa¡¢deb cry ip client ezvpn¡¢deb cry ipµÈdebugÃüÁîÊä³öµÄÐÅÏ¢²é¿´¹ý³ÌÓë½á¹û¡£
£¨2£©ÔÚ1720ÉÏÀ©Õ¹ping£¬source 10.130.23.246 destination 172.16.2.1£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ·¢ÏÖÊý¾ÝûÓнøÐмÓÃÜ¡£
£¨3£©ÔÚ1720ÉÏÀ©Õ¹ping£¬source 172.16.1.1 destination 172.16.2.1£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ·¢ÏÖÊý¾Ýͨ¹ý¼ÓÃܽøÐд«Êä¡£
£¨4£©ÔÚ3660ÉÏÀ©Õ¹ping£¬source 172.16.2.1 destination 172.16.1.1£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ·¢ÏÖÊý¾Ýͨ¹ý¼ÓÃܽøÐд«Êä¡£
£¨5£©ÔÚ3660ÉÏÀ©Õ¹ping£¬source 10.130.23.244 destination 172.16.1.1£¬²»Í¨¡£²é¿´show cry ip sa£¬¿ÉÒÔ·¢ÏÖÊý¾Ý²»Í¨¹ý¼ÓÃÜ¡£
£¨6£©Æô¶¯pc vpn client£¬ping 172.16.1.1£¬Í¨¹ý¡£ÔÚ1720Éϲ鿴show cry ip sa£¬¿ÉÒÔ¿´µ½Êý¾Ýͨ¹ý¼ÓÃܽøÐд«Êä¡£
£¨7£©ÔÚpc vpn client£¬ping 172.16.2.1£¬Í¨¹ý¡£ÔÚ1720ºÍ3662Éϲ鿴show cry ip sa£¬¿ÉÒÔ¿´µ½Êý¾Ýͨ¹ý¼ÓÃܽøÐд«Êä¡£ÔÚ1720ÉÏshow cry isa sa£¬¿ÉÒÔ¿´µ½Á½¸övpnÁ¬½Ó¡£
£¨8£©ÔÚ3660ÉÏÀ©Õ¹ping£¬source 172.16.2.1 destination 192.168.1.10£¨pc vpn client»ñµÃµÄip£©£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ·¢ÏÖÊý¾Ýͨ¹ý¼ÓÃܽøÐд«Êä¡£

˵Ã÷£º
£¨1£©²»Í¬Æ½Ì¨£¬²»Í¬ios°æ±¾£¬easy vpn clientµÄÅäÖÃÓÐËù²»Í¬¡£ÌرðÊǼÓÃÜÊý¾ÝÈë³ö½Ó¿ÚµÄÅäÖã¬ÅäÖýӿÚǰºó£¬ÓÃshow cry ip client ezvpnÀ´²é¿´ÓëÑéÖ¤¡£
£¨2£©network-extensionģʽ£¬vpn serverºÍvpn clientÁ½¶ËµÄÄÚ²¿ÍøÂçÖ®¼ä¿ÉÒÔͨ¹ýipµØÖ·»¥Ïà·ÃÎÊ¡£
£¨3£©ÒÔÉÏÅäÖþùûÓÐÆôÓÃsplit tunnel¡£ÉèÖÃsplit tunnelµÄ·½·¨:Ê×ÏȲο¼ÊµÑ飨һ£©£¬ÉèÖÃacl 133ºÍcry isa client conf groupÖеIJÎÊý£¬Íê³Éºó£¬¿ÉÒÔʵÏÖ²âÊÔ£¨1£©£­£¨5£©¡£ÒªÊµÏÖPc vpn clientºÍ3662 vpn client »¥Í¨£¬¼´²âÊÔ£¨6£©£­£¨8£©£¬»¹ÒªÔÚ1720 µÄacl 133ÖÐÌí¼ÓÁ½Ìõ£¬·Ö±ðÊÇaccess 133 permit ip 192.168.1.0 0.0.0.255 any¡¢access 133 permit ip 172.16.2.0 0.0.0.255 any¡£
£¨4£©ÐÞ¸Ä1720ÅäÖúó£¬ÐèÒª¸´Î»vpnͨµÀ£¬²Å¿ÉÒÔÆð×÷Óá£ÔÚpc¶Ë£¬ÊÇͨ¹ýdisconnectÔÙconnectÀ´ÊµÏÖ£»ÔÚ3662ÉÏ£¬Í¨¹ýclear cry ip client ezvpnÀ´¸´Î»¡£


³£Óõ÷ÊÔÃüÁ
show cry ip client ezvpn
clear cry ip client ezvpn
deb cry ip client ezvpn
show cry ip sa
deb cry isa
show cry isa sa

Èý¡¢easy vpn clientµÄÅäÖã¨client mode£©

ʵÑéÍøÂçÍØÆËͬʵÑ飨¶þ£©

ʵÑé²½Öè²Î¿¼ÊµÑ飨¶þ£©£¬ÆäÖеڶþ²½£¬½«mode network-extension¸ÄΪmode client¡£

²âÊÔ£º
£¨1£©ÅäÖúÃ3662ÉϵÄvpn clientºó£¬×Ô¶¯½øÐÐvpnÁ¬½Ó¡£¿ÉÒÔͨ¹ýdebug cry isa¡¢deb cry ip client ezvpn¡¢deb cry ipµÈdebugÃüÁîÊä³öµÄÐÅÏ¢²é¿´¹ý³ÌÓë½á¹û¡£
£¨2£©ÔÚ1720ÉÏÀ©Õ¹ping£¬source 10.130.23.246 destination 172.16.2.1£¬²»Í¨¡£
£¨3£©ÔÚ1720ÉÏÀ©Õ¹ping£¬source 172.16.1.1 destination 172.16.2.1£¬²»Í¨¡£ÕâÊÇÒòΪ3662¶ËipÊý¾ÝÁ÷ÊÇͨ¹ýnat½øÐд«Êä¡£
£¨4£©ÔÚ3660ÉÏÀ©Õ¹ping£¬source 172.16.2.1 destination 172.16.1.1£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ·¢ÏÖÊý¾Ýͨ¹ý¼ÓÃܽøÐд«Êä¡£ÔÚ1720ÉÏ´ò¿ªdeb ip icmp£¬¿ÉÒÔ¿´µ½echo replyÐÅÏ¢µÄdstµØÖ·Îª192.168.1.19£¨vpn client ´Óvpn server»ñÈ¡µÄipµØÖ·£©¡£
£¨5£©ÔÚ3660ÉÏÀ©Õ¹ping£¬source 10.130.23.244 destination 172.16.1.1£¬²»Í¨¡£

˵Ã÷£º
£¨1£©client ģʽ£¬vpn client¶ËÄÚ²¿ÍøÂç²ÉÓÃnat·½Ê½Óëvpn server½øÐÐͨÐÅ£¬vpn client¶ËÍøÂç¿ÉÒÔ·ÃÎÊserver¶ËÍøÂç×ÊÔ´£¬server¶ËÍøÂç²»ÄÜ·ÃÎÊclient¶ËÄÚ²¿ÍøÂç×ÊÔ´¡£
£¨2£©clientÓënetwork-extensionÁ½ÖÖģʽ£¬show cry ip sa£¬¿ÉÒÔ¿´µ½local identÊDz»Í¬µÄ¡£
£¨3£©clientģʽÏ£¬ÓÃshow ip nat statistics£¬¿ÉÒÔ¿´µ½natµÄÅäÖÃÓëÊý¾ÝÁ÷Á¿¡£
£¨4£©¹ØÓÚsplit tunnel£¬clientģʽµÄeasy vpn client£¬ÓëpcµÄvpn clientÀàËÆ£¬ÅäÖÃsplit tunnelµÄ·½·¨Ò²Ïàͬ¡£

³£Óõ÷ÊÔÃüÁ
show cry ip client ezvpn
clear cry ip client ezvpn
deb cry ip client ezvpn
show cry ip sa
deb cry isa
show cry isa sa
show ip nat statistics
ËÄ¡¢site to site vpnµÄÅäÖ㨲ÉÓÃpre-share£©


ʵÑéÍøÂçÍØÆË£º

router3662£­£­£­switch£­£­£­router1720

3662½Ó¿Úip:
f0/0£º10.130.23.244/28
f0/1£º172.16.2.1/24
1720½Ó¿Úip£º
f0£º10.130.23.246/28
lo0£º172.16.1.1/24
1720µÄiosΪc1700-k93sy7-mz.122-8.T5.bin
3662µÄiosΪc3660-jk9o3s-mz.123-1a.bin

²½Ö裺
ÒÔ1720ΪÀý½øÐÐÅäÖÃ
£¨1£©ÅäÖþ²Ì¬Â·ÓÉ ####ÔÚÅäÖÃvpn֮ǰ£¬ÐèÒª±£Ö¤Á½·½µÄÍøÂç¿ÉÒÔ»¥Ïà·ÃÎÊ¡£
ip route 172.16.2.0 255.255.255.0 10.130.23.244
£¨2£©¶¨Òå¼ÓÃÜÊý¾ÝµÄacl
access 144 permit ip 172.16.1.0 0.0.0.255 172.16.2.0 0.0.0.255
£¨3£©¶¨Òåisakmp policy
cry isa policy 1
authentication pre-share ####²ÉÓÃpre-share key½øÐÐÑéÖ¤
####authentication²ÎÊý±ØÐëÅäÖã¬ÆäËû²ÎÊýÈçgroup¡¢hash¡¢encr¡¢lifetimeµÈ£¬Èç¹û½øÐÐÅäÖã¬ÐèҪעÒâÁ½¸ö·ÓÉÆ÷ÉϵĶÔÓ¦²ÎÊýÅäÖñØÐëÏàͬ¡£
£¨4£©¶¨Òåpre-share key
cry isa key pre-share-key address 10.130.23.244
####ÆäÖÐpre-share-key Ϊkey£¬Á½¸ö·ÓÉÆ÷ÉÏÒªÒ»Ñù
####ÆäÖÐ10.130.23.244Ϊpeer·ÓÉÆ÷µÄipµØÖ·¡£
£¨5£©¶¨Òåtransform-set
cry ipsec transform-set vpn-tfs esp-3des esp-sha-hmac
####ÆäÖÐvpn-tfsΪtransform-set name£¬ºóÃæÁ½ÏîΪ¼ÓÃÜ´«ÊäµÄËã·¨
mode transport/tunnel #####tunnelΪĬÈÏÖµ£¬´ËÅäÖÿÉÑ¡
£¨6£©¶¨Òåcrypto map entry
cry map vpn-map 10 ipsec-isakmp
####ÆäÖÐvpn-mapΪmap name£¬10 ÊÇentry ºÅÂ룬ipsec-isakmp±íʾ²ÉÓÃisakmp½øÐÐÃÜÔ¿¹ÜÀí
match address 144 ####¶¨Òå½øÐмÓÃÜ´«ÊäµÄÊý¾Ý£¬ÓëµÚ¶þ²½¶ÔÓ¦
set peer 10.130.23.244 ####¶¨Òåpeer·ÓÉÆ÷µÄip
set transform-set vpn-tfs ####ÓëµÚ?*½¶ÔÓ?br />; ####Èç¹ûÒ»¸ö½Ó¿ÚÉÏÒª¶ÔÓ¦¶à¸övpn peer£¬¿ÉÒÔ¶¨Òå¶à¸öentry£¬Ã¿¸öentry¶ÔÓ¦Ò»¸öpeer
£¨7£©½«crypto mapÓ¦Óõ½½ÓÚÉ?br />; inter f0 #####vpnͨµÀÈë¿Ú
cry map vpn-map
£¨8£©Í¬Ñù·½·¨ÅäÖÃ3662·ÓÉÆ÷¡£

1720µÄÍêÕûÅäÖãº
VPN1720#sh run
Building configuration...

Current configuration : 1217 bytes
!
version 12.2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname VPN1720
!
logging buffered 4096 debugging
no logging rate-limit
enable password CISCO
!
username vclient1 password 0 vclient1
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
ip subnet-zero
!
!
ip domain-name fjbf.com
!
ip audit notify log
ip audit po max-events 100
!
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp key pre-share-key address 10.130.23.244
!
!
crypto ipsec transform-set vpn-tfs esp-3des esp-sha-hmac
!
crypto map vpn-map 10 ipsec-isakmp
set peer 10.130.23.244
set transform-set vpn-tfs
match address 144
!
!
!
!
interface Loopback0
ip address 172.16.1.1 255.255.255.0
!
interface FastEthernet0
ip address 10.130.23.246 255.255.255.240
speed auto
crypto map vpn-map
!
interface Serial0
no ip address
encapsulation ppp
no keepalive
no fair-queue
!
ip classless
ip route 172.16.2.0 255.255.255.0 10.130.23.244
no ip http server
ip pim bidir-enable
!
!
access-list 144 permit ip 172.16.1.0 0.0.0.255 172.16.2.0 0.0.0.255
!
!
line con 0
exec-timeout 0 0
speed 115200
line aux 0
line vty 0 4
login
!
end

²âÊÔ£º
£¨1£©Î´½«mapÓ¦Óõ½½Ó¿Ú֮ǰ£¬ÔÚ1720£¬À©Õ¹ping£¬source 10.130.23.246 destination 172.16.2.1£¬Í¨¹ý¡£À©Õ¹ping£¬source 172.16.1.1 destination 172.16.2.1£¬Í¨¹ý¡£
£¨2£©mapÓ¦Óõ½½Ó¿ÚÖ®ºó£¬ÔÚ1720£¬À©Õ¹ping£¬source 10.130.23.246 destination 172.16.2.1£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ¿´µ½Êý¾ÝûÓÐͨ¹ývpn ͨµÀ½øÐд«Ê䣬ÒòΪ²»·ûºÏacl 144¡£
£¨3£©mapÓ¦Óõ½½Ó¿ÚÖ®ºó£¬ÔÚ1720£¬À©Õ¹ping£¬source 172.16.1.1 destination 172.16.2.1£¬Í¨¹ý¡£²é¿´show cry ip sa£¬¿ÉÒÔ¿´µ½Êý¾Ýͨ¹ývpn ͨµÀ½øÐд«Êä¡£
£¨4£©ÔÚ3662ÉÏͬÑù½øÐвâÊÔ¡£

˵Ã÷£º
£¨1£©²ÉÓÃpre-share·½Ê½¼ÓÃÜÊý¾Ý£¬ÅäÖüòµ¥£¬Êý¾Ý´«ÊäЧÂʽϸߣ¬µ«Êǰ²È«ÐÔ²»¸ß¡£
£¨2£©¼ÓÃÜÊý¾Ýǰºó£¬Í¨¹ýping´ó°üµÄ·½Ê½²âÊÔ£¬¿ÉÒÔ·¢ÏÖÕâÖÖÀûÓÃÈí¼þ½øÐÐÊý¾Ý¼ÓÃܵķ½Ê½£¬ÑÓʱ½Ï´ó¡£Èç¹ûÐèÒª¿ªÕ¹voip¡¢ip ÊÓѶ»áÒéµÈÒµÎñ£¬½¨ÒéÑ¡ÅävpnÄ£¿é½øÐÐÓ²¼þ¼ÓÃÜ¡£

³£Óõ÷ÊÔÃüÁ
show cry isa sa
show cry ip sa
show cry engine configuration
show cry engine connections active
show cry engine connections flow
deb cry isa
deb cry ip
Îå¡¢site to site vpnµÄÅäÖ㨲ÉÓÃrsa-encrypted£©

ʵÑéÍøÂçÍØÆË£º

router3662£­£­£­switch£­£­£­router1720

3662½Ó¿Úip:
f0/0£º10.130.23.244/28
f0/1£º172.16.2.1/24
1720½Ó¿Úip£º
f0£º10.130.23.246/28
lo0£º172.16.1.1/24
1720µÄiosΪc1700-k93sy7-mz.122-8.T5.bin
3662µÄiosΪc3660-jk9o3s-mz.123-1a.bin

²½Ö裺
ÒÔ1720ΪÀý½øÐÐÅäÖÃ
£¨1£©ÅäÖþ²Ì¬Â·ÓÉ ####ÔÚÅäÖÃvpn֮ǰ£¬ÐèÒª±£Ö¤Á½·½µÄÍøÂç¿ÉÒÔ»¥Ïà·ÃÎÊ¡£
ip route 172.16.2.0 255.255.255.0 10.130.23.244
£¨2£©¶¨Òå¼ÓÃÜÊý¾ÝµÄacl
access 144 permit ip 172.16.1.0 0.0.0.255 172.16.2.0 0.0.0.255
£¨3£©Éú³Érsa key
cry key generate rsa general-keys ####Éú³ÉGeneral Purpose rsa Key
»òÕß cry key generate rsa usage-keys ####·Ö±ðÉú³Érsa signing keyºÍrsa encryption key
ÕâÀï ͳһÓÃgeneral purpose key
£¨4£©¸´ÖÆpeer routerµÄpublic keyµ½±¾µØrouterÖÐ
£¨A£©ÔÚ3662ÉÏÉú³Égeneral purpose key
£¨B£©ÔÚ3662ÉÏshow cry key mypubkey rsa£¬¸´ÖÆÆäÖеÄGeneral Purpose Key
£¨C£©ÔÚ1720ÉÏ£¬cry key pubkey-chain rsa ####ÉèÖÃpublic key
addressed-key 10.130.23.244 ####ÉèÖùØÁª10.130.23.244ipµØÖ·µÄkey
key-string ####¶¨Òåkey´®
Õ³Ìù´Ó3662Éϸ´ÖƵÄGeneral Purpose Key
#####Èç¹ûµÚÈý²½Éú³ÉÁËÁ½ÖÖkey£¬ÔòÕâÀï¸´ÖÆÕ³ÌùµÄ£¬Ó¦¸ÃÊÇEncryption Key£¨Èý¸ökeyÖеĵڶþ¸ö£©
£¨5£©¶¨Òåisakmp policy
cry isa policy 1
authentication rsa-encr ####²ÉÓÃrsa Encryption key½øÐÐÑéÖ¤
####authentication²ÎÊý±ØÐëÅäÖã¬ÆäËû²ÎÊýÈçgroup¡¢hash¡¢encr¡¢lifetimeµÈ£¬Èç¹û½øÐÐÅäÖã¬ÐèҪעÒâÁ½¸ö·ÓÉÆ÷ÉϵĶÔÓ¦²ÎÊýÅäÖñØÐëÏàͬ¡£
£¨6£©¶¨Òåtransform-set
cry ipsec transform-set vpn-tfs esp-3des esp-sha-hmac
####ÆäÖÐvpn-tfsΪtransform-set name£¬ºóÃæÁ½ÏîΪ¼ÓÃÜ´«ÊäµÄËã·¨
mode transport/tunnel #####tunnelΪĬÈÏÖµ£¬´ËÅäÖÿÉÑ¡
£¨7£©¶¨Òåcrypto map entry
cry map vpn-map 10 ipsec-isakmp
####ÆäÖÐvpn-mapΪmap name£¬10 ÊÇentry ºÅÂ룬ipsec-isakmp±íʾ²ÉÓÃisakmp½øÐÐÃÜÔ¿¹ÜÀí
match address 144 ####¶¨Òå½øÐмÓÃÜ´«ÊäµÄÊý¾Ý£¬ÓëµÚ¶þ²½¶ÔÓ¦
set peer 10.130.23.244 ####¶¨Òåpeer·ÓÉÆ÷µÄip
set transform-set vpn-tfs ####ÓëµÚ?*½¶ÔÓ?br />; ####Èç¹ûÒ»¸ö½Ó¿ÚÉÏÒª¶ÔÓ¦¶à¸övpn peer£¬¿ÉÒÔ¶¨Òå¶à¸öentry£¬Ã¿¸öentry¶ÔÓ¦Ò»¸öpeer£»Í¬Ñù£¬pubkeyÒ²Òª¶ÔÓ¦½øÐÐÉèÖá£
£¨7£©½«crypto mapÓ¦Óõ½½Ó¿ÚÉÏ
inter f0 #####vpnͨµÀÈë¿Ú
cry map vpn-map
£¨8£©Í¬Ñù·½·¨ÅäÖÃ3662·ÓÉÆ÷¡£


1720ÍêÕûÅäÖãº

VPN1720#sh run
Building configuration...

Current configuration : 1490 bytes
!
version 12.2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname VPN1720
!
logging buffered 4096 debugging
no logging rate-limit
enable password CISCO
!
username vclient1 password 0 vclient1
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
ip subnet-zero
!
!
ip domain-name fjbf.com
!
ip audit notify log
ip audit po max-events 100
!
crypto isakmp policy 1
encr 3des
authentication rsa-encr
group 2
!
!
crypto ipsec transform-set vpn-tfs esp-3des esp-sha-hmac
!
crypto key pubkey-chain rsa
addressed-key 10.130.23.244
address 10.130.23.244
key-string
305C300D 06092A86 4886F70D 01010105 00034B00 30480241 00BF3672 CB4D69EF
D131C023 C93EA4C5 7E09FBDB 23E9F910 EF04344A 2A4D1956 4E49DADC 5FAAE102
DBEDE13D 7911B1AD 23545B13 8EBB4791 E527B259 F87E605F 2D020301 0001
quit
!
crypto map vpn-map 10 ipsec-isakmp
set peer 10.130.23.244
set transform-set vpn-tfs
match address 144
!
!
!
!
interface Loopback0
ip address 172.16.1.1 255.255.255.0
!
interface FastEthernet0
ip address 10.130.23.246 255.255.255.240
speed auto
crypto map vpn-map
!
interface Serial0
no ip address
encapsulation ppp
no keepalive
no fair-queue
!
ip classless
ip route 172.16.2.0 255.255.255.0 10.130.23.244
no ip http server
ip pim bidir-enable
!
!
access-list 144 permit ip 172.16.1.0 0.0.0.255 172.16.2.0 0.0.0.255
!
!
line con 0
exec-timeout 0 0
speed 115200
line aux 0
line vty 0 4
login
!
end


˵Ã÷£º
£¨1£©²ÉÓÃrsa encrypted·½Ê½¼ÓÃÜ´«ÊäÊý¾Ý£¬Ä¬ÈÏkey³¤¶ÈΪ512×Ö½Ú£¬×î¸ß¿ÉÉèΪ2048×Ö½Ú¡£°²È«ÐÔÄܽϸߡ£
£¨2£©100MË«¹¤½»»»ÍøÂçÖУ¬ÔÚË«Ïòͬʱping 15000×ֽڵĴó°ü½øÐвâÊÔʱ£¬1720µÄcpuʹÓÃÂÊÒ»¶È¸ß´ï90£¥×óÓÒ£¬3662µÄʹÓÃÂÊԼΪ25£¥£¬Á½Ì¨Â·ÓÉÆ÷ÄÚ´æÊ¹ÓÃÂÊÔò±ä»¯²»´ó¡£¿É¼ûÓÃrsa encrypted·½Ê½¼ÓÃÜ£¬¶ÔµÍ¶Ë·ÓÉÆ÷µÄcpuÐÔÄÜÓ°ÏìºÜ´ó¡£

³£Óõ÷ÊÔÃüÁ
show cry ip sa
show cry isa sa
deb cry isa
deb cry ip
clear cry isa
clear cry sa




    ÎÄÕÂÆÀÂÛ
 
2007-12-11 10:16:22
ÎÒÏÖÔÚ×îÐèÒªµÄ¾ÍÊÇÕâ¸ö

 

·¢±íÆÀÂÛ

êÇ   ³Æ£º
ÑéÖ¤Â룺 ¡¡µã»÷ͼƬ¿ÉË¢ÐÂÑéÖ¤Âë¡¡¡¡²©¿Í¹ý2¼¶£¬ÎÞÐèÌîдÑéÖ¤Âë
ÄÚ   ÈÝ£º