вот тебе 100% рабочий пример на твой лад:crypto isakmp policy 2
encr 3des
hash md5
authentication pre-share
group 2
lifetime 3600
crypto isakmp key MyKey address X.X.X.X
crypto ipsec transform-set SITE_TO_SITE-set esp-3des esp-md5-hmac
mode transport
crypto map SITE_TO_SITE-map 2 ipsec-isakmp
set peer X.X.X.X
set transform-set SITE_TO_SITE-set
match address CRYPTO_ACL_IPSec
ip access-list extended CRYPTO_ACL_IPSec
permit ip 192.168.0.0 0.0.0.255 10.0.1.0 0.0.0.255
permit icmp 192.168.0.0 0.0.0.255 10.0.1.0 0.0.0.255
permit ip 10.0.1.0 0.0.0.255 192.168.0.0 0.0.0.255
permit icmp 10.0.1.0 0.0.0.255 192.168.0.0 0.0.0.255