1. 拓撲: 總部爲固定IP ,分部爲ADSL 撥號上網
2. 要求: 分部要與總部實現IPSec *** 總部經過dynamic map配置,分部靜態配置便可網絡
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
【配置NAT ,內部用戶能夠上網】app
access-list ***acl extended permit ip 192.168.1.0 255.255.255.0 192.168.10.0 255.255.255.0
access-list ***acl extended permit ip 192.168.1.0 255.255.255.0 192.168.20.0 255.255.255.0
access-list nonat extended permit ip 192.168.1.0 255.255.255.0 192.168.10.0 255.255.255.0
access-list nonat extended permit ip 192.168.1.0 255.255.255.0 192.168.20.0 255.255.255.0
nat (inside) 0 access-list nonat
【配置***的感興趣流量以及,NAT旁路,讓***的流量不走NAT】ide
crypto isakmp policy 10
authentication pre-share
encryption des
hash md5
group 2
lifetime 86400spa
crypto ipsec transform-set myset esp-des esp-md5-hmac3d
tunnel-group DefaultL2LGroup ipsec-attributes
pre-shared-key ccieh3c.com
【紅色部分爲系統默認的組,動態L2L,必須在這下面配置】orm
crypto dynamic-map cisco 10 match address ***acl
crypto dynamic-map cisco 10 set transform-set myset
crypto dynamic-map cisco 10 set reverse-route
crypto map mp 10 ipsec-isakmp dynamic cisco
crypto map mp interface outside
crypto isakmp enable outsideblog
access-list *** extended permit ip 192.168.20.0 255.255.255.0 host 192.168.1.254
access-list nonat extended permit ip 192.168.20.0 255.255.255.0 host 192.168.1.254ip
global (outside) 1 interface
nat (inside) 0 access-list nonat
nat (inside) 1 0.0.0.0 0.0.0.0md5
crypto isakmp policy 10
authentication pre-share
encryption des
hash md5
group 2ci
tunnel-group 120.1.1.1 type ipsec-l2l
tunnel-group 120.1.1.1 ipsec-attributes
pre-shared-key ccieh3c.taobao.com
crypto ipsec transform-set myset esp-des esp-md5-hmac
crypto isakmp key cisco address 100.1.1.1
crypto map mp 1 match address ***
crypto map mp 1 set peer 100.1.1.1
crypto map mp 1 set transform-set myset
crypto map mp interface outside
crypto isakmp enable outside
crypto ikev1 enable outside
crypto ikev1 policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
說明:與傳統的8.0相同,多了一個IKEV1的參數,由於8.4之後支持IKEV2了,因此區分開來。
tunnel-group DefaultL2LGroup ipsec-attributes
ikev1 pre-shared-key ccieh3c.taobao.com
說明:這裏必須使用系統默認的組來作動態L2L。
crypto ipsec ikev1 transform-set trans esp-des esp-md5-hmac
crypto dynamic-map dyl2l 1000 set ikev1 transform-set trans
crypto map l2l 1000 ipsec-isakmp dynamic dyl2l
crypto map l2l interface outside
說明:這裏必須用動態map調用轉換集,而後用靜態map關聯動態。
配置內部網絡訪問Internet的NAT
object network inside
subnet 2.2.2.0 255.255.255.0
nat (inside,outside) dynamic interface
NAT旁路【讓***的流量不通過NAT轉換】
object network inside-***
subnet 192.168.1.0 255.255.255.0
object network outside-***1
subnet 192.168.20.0 255.255.255.0
object network outside-***2
subnet 192.168.10.0 255.255.255.0
nat (inside,outside) source static inside-*** inside-*** destination static outside-***1 outside-***1
nat (inside,outside) source static inside-*** inside-*** destination static outside-***2 outside-***2
本文轉載於公衆號:網絡之路博客