Router 0 模拟成Internet网(其实,就是没有私有IP地址路由的路由器,在说通俗点,现在×××技术常用来解决总部与分部跨越Internet网解决内部私有地址的连通性)
Router 1 为总部,Router 2为分部。
IP规划:
Router 0 FastEthernet0/0 200.1.1.1 FastEthernet0/1 100.1.1.1
Router 1 FastEthernet0/0 192.168.1.1 FastEthernet0/1 100.1.1.2
Router 2 FastEthernet0/0 200.1.1.2 FastEthernet0/1 192.168.2.1
PC2: 192.168.2.10/24
实验要求让总部和分布的私有地址能通信!(大家可以按我的配置做一遍,红色为×××配置关键代码,在没配置×××时,PC1 是不能与PC2 相互Ping通),pc1和pc2能ping通外网
Router0 的配置(Internet):
interface FastEthernet0/0
ip address 200.1.1.1 255.255.255.0
no shutdown
interface FastEthernet0/1
ip address 100.1.1.1 255.255.255.0
no shutdown
Router 1的配置:
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
crypto isakmp key 2046 address 200.1.1.2
crypto ipsec transform-set tim esp-3des esp-md5-hmac
access-list 101 permit ip 192.168.1.0
crypto map tom 10 ipsec-isakmp
set peer 200.1.1.2
set transform-set tim
match address 101
interface FastEthernet0/0
ip address 192.168.1.1 255.255.255.0
no shutdown
interface FastEthernet0/1
ip address 100.1.1.2 255.255.255.0
no shutdown
crypto map tom
ip route
Router 2的配置:
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
crypto isakmp key 2046 address 100.1.1.2
crypto ipsec transform-set tim esp-3des esp-md5-hmac
!
crypto map tom 10 ipsec-isakmp
set peer 100.1.1.2
set transform-set tim
match address 101
access-list 101 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
interface FastEthernet0/0
ip address 200.1.1.2 255.255.255.0
no shutdown
crypto map tom
interface FastEthernet0/1
ip address 192.168.2.1 255.255.255.0
no shutdown
ip route