資源描述:
《ger over ipsec 穿越 nat》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在行業(yè)資料-天天文庫。
1、龍旭網(wǎng)絡(luò)GREOVERIPSEC穿越NAT1、實驗環(huán)境:2、實驗配置:Branch1:[RT1]discur#sysnameRT1#ikelocal-namer1#ikepeerr3exchange-modeaggressivepre-shared-keycipherTEzJOUGCmuE=id-typename6內(nèi)部資料嚴禁傳播龍旭網(wǎng)絡(luò)remote-namer3remote-address1.0.0.60nattraversal#ipsecproposal1#ipsecpolicy11isakmpsecurityacl3000ike-peerr3proposal1#aclnumber3000
2、rule0permitgresource192.168.1.10destination172.16.1.10#interfaceSerial0/2/0link-protocolpppipaddress10.0.1.1255.255.255.0ipsecpolicy1#interfaceLoopBack0ipaddress192.168.11.1255.255.255.255#6內(nèi)部資料嚴禁傳播龍旭網(wǎng)絡(luò)interfaceLoopBack1ipaddress192.168.1.1255.255.255.255#interfaceTunnel0ipaddress10.0.2.1255.255.255
3、.0sourceLoopBack1destination172.16.1.1#iproute-static0.0.0.00.0.0.010.0.1.2iproute-static172.1.1.1255.255.255.255Tunnel0#NAT:[NAT]discur#sysnameNAT#nataddress-group011.0.0.111.0.0.10#aclnumber2000rule0permitsource10.0.1.00.0.0.255#interfaceSerial0/2/06內(nèi)部資料嚴禁傳播龍旭網(wǎng)絡(luò)link-protocolpppipaddress10.0.1.2255
4、.255.255.0#interfaceSerial0/2/2link-protocolpppnatoutbound2000address-group0ipaddress1.0.0.1255.255.255.0#Center:[RT3]discur#sysnameRT3#ikelocal-namer3#ikepeerr1exchange-modeaggressivepre-shared-keycipherTEzJOUGCmuE=id-typenameremote-namer16內(nèi)部資料嚴禁傳播龍旭網(wǎng)絡(luò)nattraversal#ipsecproposal1#ipsecpolicy-templat
5、er31ike-peerr1proposal1#ipsecpolicy11isakmptemplater3#interfaceSerial0/2/0link-protocolpppipaddress1.0.0.60255.255.255.0ipsecpolicy1#interfaceLoopBack0ipaddress172.1.1.1255.255.255.255#interfaceLoopBack1ipaddress172.16.1.1255.255.255.255#interfaceTunnel06內(nèi)部資料嚴禁傳播龍旭網(wǎng)絡(luò)ipaddress10.0.2.2255.255.255.0sou
6、rceLoopBack1destination192.168.1.1#iproute-static11.0.0.0255.0.0.01.0.0.1iproute-static192.168.1.1255.255.255.2551.0.0.1iproute-static192.168.11.1255.255.255.255Tunnel0#1、測試:ping-a192.168.11.1172.1.1.1PING172.1.1.1:56databytes,pressCTRL_CtobreakReplyfrom172.1.1.1:bytes=56Sequence=1ttl=255time=2
7、6msReplyfrom172.1.1.1:bytes=56Sequence=2ttl=255time=5msReplyfrom172.1.1.1:bytes=56Sequence=3ttl=255time=5msReplyfrom172.1.1.1:bytes=56Sequence=4ttl=255time=20msReplyfrom172.1.1.1:bytes=56Sequence=5ttl