Добрый день. Есть 2 циски 871. Пытаюсь между ними завязать ipsec, но что-т не фига не получается. Конфиг первой
crypto isakmp policy 10
authentication pre-share
crypto isakmp key key address 10.128.14.2
!
!
crypto ipsec transform-set myset esp-3des esp-md5-hmac
mode transport
!
crypto map myvpn 10 ipsec-isakmp
! Incomplete
set peer 10.128.14.2
set transform-set myset
match address 101
interface FastEthernet0
no cdp enable
!
interface FastEthernet1
no cdp enable
!
interface FastEthernet2
shutdown
no cdp enable
!
interface FastEthernet3
shutdown
no cdp enable
!
interface FastEthernet4
ip address 10.2.4.66 255.255.255.252
ip nat outside
ip virtual-reassembly
no ip route-cache
duplex auto
speed auto
no cdp enable
no cdp enable
crypto map myvpn
!
interface Vlan1
ip address 192.168.63.100 255.255.255.0
ip nat inside
ip virtual-reassembly
no ip route-cache
!
ip route 192.168.111.2 255.255.255.255 192.168.111.73
ip route 192.168.111.73 255.255.255.255 10.128.14.2
!
no ip http server
no ip http secure-server
ip nat inside source list 122 interface FastEthernet4 overload
ip nat inside source static 192.168.63.100 10.2.4.66 route-map nonat
!
access-list 122 deny ip 192.168.63.0 0.0.0.255 192.168.111.0 0.0.0.255
access-list 122 permit ip 192.168.63.0 0.0.0.255 any
access-list 150 deny ip host 192.168.63.100 192.168.111.0 0.0.0.255
access-list 150 permit ip host 192.168.63.100 any
!
!
route-map nonat permit 10
match ip address 150
и второй:
crypto isakmp policy 10
authentication pre-share
crypto isakmp key key address 10.2.4.66
!
!
crypto ipsec transform-set myset esp-3des esp-md5-hmac
!
crypto map myvpn 10 ipsec-isakmp
! Incomplete
set peer 10.2.4.66
set transform-set myset
!
archive
log config
hidekeys
interface FastEthernet0
!
interface FastEthernet1
shutdown
!
interface FastEthernet2
shutdown
!
interface FastEthernet3
shutdown
!
interface FastEthernet4
ip address 10.128.14.2 255.255.255.252
ip nat outside
ip virtual-reassembly
no ip route-cache
duplex auto
speed auto
crypto map myvpn
!
interface Vlan1
ip address 192.168.111.73 255.255.255.0
ip nat inside
ip virtual-reassembly
no ip route-cache
!
no ip forward-protocol nd
!
no ip http server
no ip http secure-server
ip nat inside source list 122 interface FastEthernet4 overload
!
access-list 101 permit ip 192.168.111.0 0.0.0.255 192.168.63.0 0.0.0.255
access-list 122 deny ip 192.168.111.0 0.0.0.255 192.168.63.0 0.0.0.255
access-list 122 permit ip 192.168.111.0 0.0.0.255 any
access-list 175 deny ip 192.168.111.0 0.0.0.255 192.168.63.0 0.0.0.255
access-list 175 permit ip 192.168.111.0 0.0.0.255 any
!
!
Собственно из 111-ой подсети я должен видеть 63-ю, но вижу я только ip интерфейсов своей циски. И с самих цисок я вижу интерфейсы соседа и все... сетей не видно :(
Подскажите в чем может быть проблема?
Заранее спасибо.