> Вы бы лучше руками все делали..Так проше и ошибок меньше...
> Сейчас пороюсь и выложу рабочий конфиг...-----------------------------------
crypto isakmp policy 10
encr aes 256
authentication rsa-encr
group 2
lifetime 3600
crypto isakmp keepalive 60 3
------------------------------------
!
!
crypto ipsec transform-set IPSEC esp-aes 256 esp-sha-hmac
-----------------------------------------
crypto map TUNNELTOREMOTE 10 ipsec-isakmp
set peer xxx.xxx.xxx.xxx
set transform-set IPSEC
match address acl_vpn_ccc
-------------------------------------
interface FastEthernet4
description WAN INTERFACE
ip address yyy.yyy.yyy.yyy 255.255.255.252
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
crypto map TUNNELTOREMOTE
----------------------------
interface Vlan1
description LAN INTERFACE
ip address 192.168.20.1 255.255.255.0
ip access-group F1 in
ip nat inside
ip virtual-reassembly
ip nat inside source list acl_nat interface FastEthernet4 overload
ip access-list extended acl_nat
deny ip 192.168.20.0 0.0.0.255 192.168.0.0 0.0.0.255
permit ip 192.168.20.0 0.0.0.255 any
ip access-list extended acl_vpn_ccc
permit ip 192.168.20.0 0.0.0.255 192.168.0.0 0.0.0.255
Только у меня аунтефикация не по паролю, а по сертификатам...