============ схема
-192.168.100.0/24-(515)-- PUBLIC --(501)-192.168.101.0/24-
============
Настройка 515
access-list out permit ip any any
access-list in permit ip any any
access-list dnz permit ip any any
access-list tunnel permit ip 192.168.100.0 255.255.255.0 192.168.101.0 255.255.255.0
ip address outside 1.1.1.2 255.255.255.255
ip address inside 192.168.100.1 255.255.255.0
ip local pool loc_pool 192.168.100.155-192.168.100.254
global (outside) 1 interface
nat (inside) 0 access-list tunnel
nat (inside) 1 192.168.100.0 255.255.255.0 0 0
access-group out in interface outside
access-group in in interface inside
access-group dnz in interface dmz
route outside 0.0.0.0 0.0.0.0 1.1.1.1 1
sysopt connection permit-ipsec
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set ESP-3DES-MD5
crypto map mymap 5 ipsec-isakmp
crypto map mymap 5 match address tunnel
crypto map mymap 5 set peer 2.2.2.2
crypto map mymap 5 set transform-set ESP-3DES-MD5
crypto map mymap 10 ipsec-isakmp dynamic dynmap
crypto map mymap interface outside
isakmp enable outside
isakmp key ******** address 2.2.2.2 netmask 255.255.255.255 no-xauth no-config-mode
isakmp identity address
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
vpngroup mygroup address-pool loc_pool
vpngroup mygroup dns-server 192.168.100.22
vpngroup mygroup idle-time 1800
vpngroup mygroup password ********
vpngroup idle-time idle-time 1800
===============
настройка 501
access-list out permit ip any any
access-list in permit ip any any
access-list tunnel permit ip 192.168.101.0 255.255.255.0 192.168.100.0 255.255.255.0
ip address outside 2.2.2.2 255.255.255.255
ip address inside 192.168.101.1 255.255.255.0
global (outside) 1 interface
nat (inside) 0 access-list tunnel
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
access-group out in interface outside
access-group in in interface inside
route outside 0.0.0.0 0.0.0.0 2.2.2.1 1
sysopt connection permit-ipsec
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map to_515 10 ipsec-isakmp
crypto map to_515 10 match address tunnel
crypto map to_515 10 set peer 1.1.1.2
crypto map to_515 10 set transform-set ESP-3DES-MD5
crypto map to_515 interface outside
isakmp enable outside
isakmp key ******** address 1.1.1.2 netmask 255.255.255.255 no-xauth no-config-mode
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
=========
IPsec поднимается между PIX'ами, пакеты криптуются но такое ощущение что в туннель не попадают! Посылаю один ICMP пакет с машины за 501 пиксом, вижу:
501(config)# sh cry ip sa
interface: outside
Crypto map tag: to_515, local addr. 2.2.2.2
local ident (addr/mask/prot/port): (192.168.101.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.100.0/255.255.255.0/0/0)
current_peer: 1.1.1.2:500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 1, #pkts encrypt: 1, #pkts digest 1
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0
#send errors 1, #recv errors 0
==========
515(config)# sh cry ip sa
interface: outside
Crypto map tag: mymap, local addr. 1.1.1.2
local ident (addr/mask/prot/port): (192.168.100.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.101.0/255.255.255.0/0/0)
current_peer: 2.2.2.2:500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest 0
#pkts decaps: 1, #pkts decrypt: 1, #pkts verify 1
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0
#send errors 0, #recv errors 0
=========
Как сделать нормальное хождение пакетов межу 192.168.100.0/24 и 192.168.101.0/24?
И второй вопрос: коннекчусь к 515 с внешнего адреса Cisco VPN клиентом, получаю IP из пула, машиины в серой сети не вижу, но из серой сети клиента вижу, как лечить?