The OpenNET Project / Index page

[ новости /+++ | форум | теги | ]



"IPSec tunnel"
Версия для распечатки Пред. тема | След. тема
Форум Маршрутизаторы CISCO и др. оборудование.
Исходное сообщение [ Отслеживать ]

. "IPSec tunnel" +/
Сообщение от Алексей (??), 23-Дек-10, 09:34 
Вот конфиг одной из сторон:
!
! Last configuration change at 12:10:15 MSK Wed Dec 22 2010 by support
! NVRAM config last updated at 12:11:39 MSK Wed Dec 22 2010 by support
!
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname vpn_to_toto
!
boot-start-marker
boot system flash c870-advsecurityk9-mz.124-15.T6.bin
boot-end-marker
!
logging buffered 4096
logging console critical
enable secret 5 ********************************
!
no aaa new-model
clock timezone MSK 3
clock summer-time MSK recurring last Sun Mar 2:00 last Sun Oct 2:00
!
!
dot11 syslog
no ip source-route
no ip cef
!
!
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
no ip bootp server
no ip domain lookup
ip domain name **************.net
!
!
!
file prompt quiet
username support privilege 15 secret 5 *******************************
!
!
crypto isakmp policy 10
encr aes 256
authentication pre-share
group 2
crypto isakmp key *************** address xxx.xxx.xxx.xxx
crypto isakmp keepalive 60 3
!
!
crypto ipsec transform-set IPSEC esp-aes 256 esp-sha-hmac
!
crypto ipsec profile TUNNEL
set transform-set IPSEC
!
!
crypto map TUNNELTOTC 10 ipsec-isakmp
set peer xxx.xxx.xxx.xxx
set transform-set IPSEC
match address acl_vpn
!
archive
log config
  hidekeys
!
!
ip ssh time-out 60
ip ssh authentication-retries 2
ip ssh source-interface Vlan1
ip ssh version 2
!
!
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0.1 point-to-point
pvc 0/35
  pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
ip address 192.168.0.184 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1412
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname **************
ppp chap password 7 ************
ppp pap sent-username ********* password 7 **************
crypto map TUNNELTOTC
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
!
no ip http server
no ip http secure-server
ip nat inside source list acl_nat interface Dialer0 overload
!
ip access-list extended acl_nat
deny   ip 192.168.0.0 0.0.0.255 192.168.2.0 0.0.0.255
permit ip 192.168.0.0 0.0.0.255 any
ip access-list extended acl_vpn
permit ip 192.168.0.0 0.0.0.255 192.168.2.0 0.0.0.255
!
access-list 2 permit 192.168.0.1
access-list 2 permit 192.168.0.3
access-list 2 permit 192.168.0.5
access-list 2 deny   any log
dialer-list 1 protocol ip permit
no cdp run
!
!
!
control-plane
!
!
line con 0
login local
no modem enable
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
access-class 2 in
login local
transport input ssh
transport output ssh
!
no scheduler max-task-time
ntp clock-period 17175014
ntp server 192.168.0.1
end


Ответить | Правка | Наверх | Cообщить модератору

Оглавление
IPSec tunnel, Алексей, 22-Дек-10, 09:18  [смотреть все]
Форумы | Темы | Пред. тема | След. тема



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру