云计算专业isakmp实验:
拓扑图如下:
各路由器的配置命令如下:
AR1:
system-view
sysname ISP
interface g0/0/0
ip address 66.66.66.2 29
interface g0/0/1
ip address 6.6.6.2 29
AR2:
system-view
sysname CQ
interface g0/0/0
ip address 6.6.6.1 29
interface g0/0/2
ip address 192.168.6.1 24
ip route-static 0.0.0.0 0.0.0.0 6.6.6.2
ipsec proposal 100
encapsulation-mode tunnel
transform esp
esp authentication-algorithm sha1
esp encryption-algorithm 3des
ike proposal 10
authentication-method pre-share
authentication-algorithm sha1
encryption-algorithm 3des
dh group14
ike peer shanghai v1
pre-shared-key cipher Aa123456
exchange-mode main
ike-proposal 10
local-address 6.6.6.1
remote-address 66.66.66.1
ipsec policy CQ-SH 10 isakmp
security acl 3000
proposal 100
ike-peer shanghai
interface g0/0/0
ipsec policy CQ-SH
acl 3000
rule 5 permit ip source 192.168.6.0 0.0.0.255 destination 192.168.66.0 0.0.0.255
AR3:
system-view
sysname SH
interface g0/0/1
ip address 66.66.66.1 29
interface g0/0/2
ip address 192.168.66.1 24
ip route-static 0.0.0.0 0.0.0.0 66.66.66.2
ipsec proposal 111
encapsulation-mode tunnel
transform esp
esp authentication-algorithm sha1
esp encryption-algorithm 3des
ike proposal 11
authentication-method pre-share
authentication-algorithm sha1
encryption-algorithm 3des
dh group14
ike peer chongqing v1
pre-shared-key cipher Aa123456
exchange-mode main
ike-proposal 11
local-address 66.66.66.1
remote-address 6.6.6.1
ipsec policy SH-CQ 11 isakmp
security acl 3000
proposal 111
ike-peer chongqing
interface g0/0/1
ipsec policy SH-CQ
acl 3000
rule 5 permit ip source 192.168.66.0 0.0.0.255 destination 192.168.6.0 0.0.0.255
PC机的配置如下:
菜菜的代码,希望能够帮助到你哟!