R1环回1.1.1.1 R3环回3.3.3.3 R2为公网
R1与R2的环回通过ipsec vpn 通信
效果
R1
crypto isakmp policy 10
encr 3des
authentication pre-share
group 5
crypto isakmp key 6 ccie address 23.0.0.1
!
!
crypto ipsec transform-set ccie esp-3des esp-md5-hmac
mode tunnel
crypto map anquan 1 ipsec-isakmp
set peer 23.0.0.1
match address 101
interface Loopback0
ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet0/0
ip address 12.0.0.1 255.255.255.0
duplex half
crypto map anquan
ip route 0.0.0.0 0.0.0.0 FastEthernet0/0
!
access-list 101 permit ip host 1.1.1.1 host 3.3.3.3
!
R3
crypto isakmp policy 10
encr 3des
authentication pre-share
group 5
crypto isakmp key 6 ccie address 12.0.0.1
!
!
crypto ipsec transform-set ccie esp-3des esp-md5-hmac
mode tunnel
crypto map anquan 1 ipsec-isakmp
set peer 12.0.0.1
match address 101
!
interface Loopback0
ip address 3.3.3.3 255.255.255.255
!
interface FastEthernet0/0
ip address 23.0.0.1 255.255.255.0
crypto map anquan
ip route 0.0.0.0 0.0.0.0 FastEthernet0/0
!
access-list 101 permit ip host 3.3.3.3 host 1.1.1.1
!