MGRE配置及拓扑图看上个实验!
R1:
ip access-list extended 101 #感兴趣流
10 permit ip host 222.100.100.1 host 222.200.200.1
crypto isakmp policy 10 #策略
authentication pre-share
!
!
crypto isakmp key 7 1001173411 address 222.200.200.1 #预共享密钥
crypto ipsec transform-set test esp-3des esp-md5-hmac #IPSec转换集
!
crypto map test 5 ipsec-isakmp #加密图
set peer 222.200.200.1
set transform-set test
match address 101
!
interface GigabitEthernet 0/0 #调用加密图
ip address 222.100.100.1 255.255.255.252
crypto map test
duplex auto
speed auto
!
R3:
ip access-list extended 101
10 permit ip host 222.200.200.1 host 222.100.100.1
!
crypto isakmp policy 10
authentication pre-share
!
!
crypto isakmp key 7 08172a0606 address 222.100.100.1
crypto ipsec transform-set test esp-3des esp-md5-hmac
!
crypto map test 5 ipsec-isakmp
set peer 222.100.100.1
set transform-set test
match address 101
!
interface GigabitEthernet 0/0
ip address 222.200.200.1 255.255.255.252
crypto map test
duplex auto
speed auto
!
Test:
Test2:
Test3: