WIN10充当Client的IKEv2认证方式

server

  • ip local pool Win7Pool 123.1.1.100 123.1.1.200
  • crypto ikev2 authorization policy Lxf-IKEv2-Author-Win
  • pool Win7Pool
  • crypto pki certificate map Lxf-CertMap-Win 10
  • subject-name co cn = TCPIPWIN10
  • !
  • crypto ikev2 proposal Lxf-IKEv2-Proposal-Win
  • encryption aes-cbc-256
  • integrity sha1
  • group 2
  • !
  • crypto ikev2 policy Lxf-IKEv2-Policy
  • proposal Lxf-IKEv2-Proposal-Win
  • !
  • crypto ikev2 profile Lxf-IKEv2-Profile-Win
  • match certificate Lxf-CertMap-Win
  • identity local fqdn Server.qytang.com
  • authentication remote rsa-sig
  • authentication local rsa-sig
  • pki trustpoint CA
  • aaa authorization group cert list Lxf-Local-Grp-Auth-List Lxf-IKEv2-Author-Win
  • virtual-template 2
  • !
  • crypto ipsec transform-set Lxf-IPSec-Trans-Win esp-aes 256 esp-sha-hmac
  • mode tunnel
  • crypto ipsec profile Lxf-IPSec-Win-Profile
  • set transform-set Lxf-IPSec-Trans-Win
  • set ikev2-profile Lxf-IKEv2-Profile-Win
  • !
  • interface Virtual-Template2 type tunnel
  • ip unnumbered GigabitEthernet1
  • tunnel mode ipsec ipv4
  • tunnel protection ipsec profile Lxf-IPSec-Win-Profile
  • -------------------------------------------------------------------------------
  • aaa group server radius Lxf-ISE
  • server-private 61.128.1.241 key cisco
  • aaa authentication login Lxf-EAP-List group Lxf-ISE
  • aaa authorization network Lxf-EAP-List group Lxf-ISE
  • crypto ikev2 name-mangler Lxf-Name-Mangler
  • eap suffix delimiter @
  • !
  • crypto ikev2 proposal Lxf-IKEv2-EAP-Win10
  • encryption aes-cbc-256
  • integrity sha1
  • group 2
  • !
  • crypto ikev2 policy Lxf-Ikev2-EAP-Policy
  • proposal Lxf-IKEv2-EAP-Win10
  • !
  • !
  • !
  • crypto ikev2 profile Lxf-IKEv2-EAP-Profile
  • match identity remote address 0.0.0.0
  • authentication local rsa-sig
  • authentication remote eap query-identity
  • pki trustpoint CA
  • aaa authentication eap Lxf-EAP-List
  • aaa authorization group eap list Lxf-EAP-List name-mangler Lxf-Name-Mangler
  • virtual-template 3
  • !
  • crypto ipsec transform-set Lxf-IPsec-EAP-Win10 esp-aes 256 esp-sha-hmac
  • mode tunnel!
  • !
  • crypto ipsec profile Lxf-IPsec-EAP-Profile
  • set transform-set Lxf-IPsec-EAP-Win10
  • set ikev2-profile Lxf-IKEv2-EAP-Profile
  • !
  • interface Virtual-Template3 type tunnel
  • ip unnumbered GigabitEthernet1
  • tunnel mode ipsec ipv4
  • tunnel protection ipsec profile Lxf-IPsec-EAP-Profile
  • !

Client 设置

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

期待未来的男孩

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值