前言:本次实验为《网络系统管理》赛项专题,采用的实验设备为锐捷设备,文章是本人在操作和实验中的总结和经验所写,若有什么不对的地方还请各位大佬多多指教!!!
目录
网络拓扑如下(咳咳,只是采用GNS3去搭建,实验的环境为锐捷设备):
配置如下:
配置接口IP
R1配置IP R1(config)#interface GigabitEthernet 0/0 R1(config-if)#ip address 200.2.1.2 255.255.255.252 R1(config)#interface loo 0 R1(config-if)#ip address 195.1.10.254 255.255.255.0 R1(config)#interface loo 1 R1(config-if)#ip address 195.1.20.254 255.255.255.0 R2配置IP R1(config)#interface GigabitEthernet 0/0 R1(config-if)#ip address 200.2.1.1 255.255.255.252 R3(config)#interface GigabitEthernet 0/1 R3(config-if)#ip address 200.1.1.1 255.255.255.252 R3配置IP R3(config)#interface GigabitEthernet 0/0 R3(config-if)#ip address 200.1.1.2 255.255.255.252 R3(config)#interface loo 0 R3(config-if)#ip address 192.1.10.254 255.255.255.0 R3(config)#interface loo 1 R3(config-if)#ip address 192.1.20.254 255.255.255.0
配置IP sec
R1配置R1(config)#crypto isakmp policy 10R1(isakmp-policy)#encryption 3desR1(isakmp-policy)#authentication pre-shareR1(isakmp-policy)#group 2R1(isakmp-policy)#hash md5R1(isakmp-policy)#exR1(config)#crypto isakmp key 0 test address 200.1.1.2R1(config)#crypto ipsec transform-set myset esp-3des esp-md5-hmacR1(config)#cry ipsec profile R1 #profile名字为R1(名字可以自定义)R1(config-crypto-map)#set transform-set myset #调用 transform-setR3配置R3(config)#crypto isakmp policy 10R3(isakmp-policy)#encryption 3desR3(isakmp-policy)#authentication pre-shareR3(isakmp-policy)#group 2R3(isakmp-policy)#hash md5R3(isakmp-policy)#exR3(config)#crypto isakmp key 0 test address 200.2.1.2R3(config)#crypto ipsec transform-set myset esp-3des esp-md5-hmac