实验版本:ASA 9.17(1)10
实验拓扑:
设计需求:
1):在 两台ASA之间建立ipsc vpn,使得192.168.10.0 ,172.16.20.0网段可以互访 2):192.168.10.0 和172.16.20.0 网段可以上网,上网路径与VPN访问路径分割(访问8.8.8.8)
配置:
ISP 8.8.8.8 路由器配置:
interface Ethernet0/1 ip address 202.202.202.254 255.255.255.0 duplex auto interface Ethernet0/3 ip address 101.101.101.254 255.255.255.0 duplex auto interface Loopback0 ip address 8.8.8.8 255.255.255.255
ASA01配置:
上网配置
interface GigabitEthernet0/0
nameif outside
security-level 0
ip address 101.101.101.1 255.255.255.0
interface GigabitEthernet0/1
nameif intside
security-level 100
ip addr