建立如上图所示拓扑图,下面是相关的操作

hostname r1
!
!
!
!
!
!
!
!
crypto isakmp policy 1
 encr 3des
 hash md5
 authentication pre-share
!
crypto isakmp key cisco address 10.1.1.2
!
!
crypto ipsec transform-set mytrans esp-3des
!
crypto map mymap 1 ipsec-isakmp
 set peer 10.1.1.2
 set transform-set mytrans
 match address 111
!
!
!
!
!
spanning-tree mode pvst
!
!
!
!
interface FastEthernet0/0
 ip address 10.1.1.1 255.255.255.0
 ip nat outside
 duplex auto
 speed auto
 crypto map mymap
!
interface FastEthernet0/1
 ip address 192.168.1.1 255.255.255.0
 ip nat inside
 duplex auto
 speed auto
!
interface Vlan1
 no ip address
 shutdown
!
router rip
 network 10.0.0.0
 network 192.168.1.0
!
ip nat pool mynat 10.1.1.1 10.1.1.1 netmask 255.255.255.255
ip nat inside source list 112 pool mynat overload
ip classless
ip route 192.168.2.0 255.255.255.0 10.1.1.2
!
!
access-list 111 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 112 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 112 permit ip 192.168.1.0 0.0.0.255 any                    

    由于在此路由器中配置了NAT转换,故 在此要进行隧道分离,不然无法正常进行***连接,在NAT转换中拒绝crypto map 中match address 匹配的数据流。
hostname r2
!
!
!
!
!
!
!
!
crypto isakmp policy 1
 encr 3des
 hash md5
 authentication pre-share
!
crypto isakmp key cisco address 10.1.1.1
!
!
crypto ipsec transform-set mytrans esp-3des
!
crypto map mymap 1 ipsec-isakmp
 set peer 10.1.1.1
 set transform-set mytrans
 match address 111
!
!
!
!
!
spanning-tree mode pvst
!
!
!
!
interface FastEthernet0/0
 ip address 10.1.1.2 255.255.255.0
 ip nat outside
 duplex auto
 speed auto
 crypto map mymap
!
interface FastEthernet0/1
 ip address 192.168.2.1 255.255.255.0
 ip nat inside
 duplex auto
 speed auto
!
interface Vlan1
 no ip address
 shutdown
!
router rip
 network 10.0.0.0
 network 192.168.2.0
!
ip classless
ip route 192.168.1.0 255.255.255.0 10.1.1.1
!
!
access-list 111 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 112 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 112 permit ip 192.168.2.0 0.0.0.255 any

   由于在此路由器中配置了NAT转换,故 在此要进行隧道分离,不然无法正常进行***连接,在NAT转换中拒绝crypto map 中match address 匹配的数据流。
交流探讨MSN:tianyahaijiao8888@hotmail.com