锐捷的IPSec vpn的配置命令
crypto isakmp policy 1
encryption 3des
authentication pre-share
crypto isakmp key 7 ruijie address 34.1.1.4
crypto ipsec transform-set RCIE esp-aes-256 esp-md5-hmac
crypto map MAP 10 ipsec-isakmp
set peer 34.1.1.4
set transform-set RCIE
match address 100
interface GigabitEthernet 0/1
crypto map MAP
R2
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
crypto isakmp keepalive 5 periodic
crypto isakmp policy 1
authentication pre-share
encryption 3des
crypto isakmp key 0 ruijie address 34.0.0.4
crypto ipsec transform-set myset esp-des esp-md5-hmac
crypto map mymap 5 ipsec-isakmp
set peer 34.0.0.4
set transform-set myset
match address 101
int g 0/1
crypto map mymap
ip route 192.168.20.0 255.255.255.0 23.0.0.3
R4
access-list 101 permit ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
crypto isakmp keepalive 5 periodic
crypto isakmp policy 1
authentication pre-share
encryption 3des
crypto isakmp key 0 ruijie address 23.0.0.2
crypto ipsec transform-set myset esp-des esp-md5-hmac
crypto map mymap 5 ipsec-isakmp
set peer 23.0.0.2
set transform-set myset
match address 101
int g 0/1
crypto map mymap
ip route 192.168.10.0 255.255.255.0 34.0.0.3