1.分支1路由器配置步骤:
#网络互通配置省略,loopback 0~n模拟内网主机
interface LoopBack1
ip address 192.168.1.1 255.255.255.255
#
interface LoopBack2
ip address 192.168.1.2 255.255.255.255
#
interface LoopBack3
ip address 192.168.1.3 255.255.255.255
#配置静态地址转换,先把内网地址转换成10.10.1.0/24网段
nat static outbound net-to-net 192.168.1.1 192.168.1.10 global 10.10.1.0 255.255.255.0
interface GigabitEthernet0/0
ip address 10.10.12.1 255.255.255.0
nat static enable
#配置IPSEC感兴趣流的ACL,匹配转换后的地址10.10.1.0/24访问对端转换后的地址10.10.2.0/24
acl advanced 3000
rule 0 permit ip source 10.10.1.0 0.0.0.255 destination 10.10.2.0 0.0.0.255
#配置IPSEC VPN部分,详细说明略。
ike keychain 1
pre-shared-key address 10.10.23.1 255.255.255.255 key simple 123456
ike proposal 1
encryption-algorithm 3des-cbc
authentication-algorithm md5
ike profile 1
keychain 1
match remote identity address 10.10.23.1 255.255.255.255
proposal 1
ipsec transform-set 1
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5esp
ipsec policy