NBMA Network Dynamic IPsec VPN

Source: Internet
Author: User

NBMA Network Dynamic IPsec VPN R1-sever # show runip domain name sina.com !! Username sunzhixiong password 0 cisco !! Crypto isakmp policy 10 hash md5 authentication pre-share group 2 lifetime 3600 crypto isakmp key ilovetg2008 address 172.16.10.0 255.255.255.0 !! Crypto ipsec transform-set sun1 ah-md5-hmac esp-des esp-md5-hmac comp-lzs !! Crypto dynamic-map sun1 10 set security-association lifetime kilobytes 102400 set transform-set sun1 set pfs group2 match address VPN !! Crypto map sun 10 ipsec-isakmp dynamic sun1 !! Interface Loopback1 ip address 1.1.1.1 255.255.0 !! Interface Serial1/0 ip address 172.16.10.1 255.255.255.0 encapsulation frame-relay serial restart-delay 0 crypto map sun !!! Router ospf 1 router-id 1.1.1.1 log-adjacency-changes network 1.1.1.1 0.0.0.0 area 0 network 172.16.10.1 0.0.0.0 area 0 neighbor 172.16.10.3 neighbor 172.16.10.2 !! Ip access-list extended VPN permit tcp host 1.1.1.1 host 2.2.2.2 permit tcp host 1.1.1.1 host 3.3.3.3! Line con 0 exec-timeout 0 0 logging synchronousline aux 0 line vty 0 4 login local transport input telnet ssh !! EndFR_SW1 # show run !! Frame-relay switching !! Interface Tunnel0 no ip address tunnel source FastEthernet0/0 tunnel destination 100.1.1.3! Interface FastEthernet0/0 ip address 100.1.1.2 255.255.0 duplex auto speed auto! Interface Serial1/0 no ip address encapsulation frame-relay serial restart-delay 0 clock rate 64000 frame-relay lm-type cisco frame-relay intf-type dce frame-relay route 102 interface Serial1 /2 201 frame-relay route 103 interface Tunnel0 130 !! Interface Serial1/2 no ip address encapsulation frame-relay serial restart-delay 0 clock rate 64000 frame-relay lm-type cisco frame-relay intf-type dce frame-relay route 201 interface Serial1 /0 102 !! EndFR_SW2 # show run !! Frame-relay switching !!! Interface Tunnel0 no ip address tunnel source FastEthernet0/0 tunnel destination 100.1.1.2! Interface FastEthernet0/0 ip address 100.1.1.3 255.255.0 duplex auto speed auto! Interface Serial1/0 no ip address shutdown serial restart-delay 0! Interface Serial1/3 no ip address encapsulation frame-relay serial restart-delay 0 clock rate 64000 frame-relay lm-type cisco frame-relay intf-type dce frame-relay route 301 interface Tunnel0 130 !! Endclient2 # show run! Crypto isakmp policy 10 hash md5 authentication pre-share group 2 lifetime 3600 crypto isakmp key ilovetg2008 address 172.16.10.0 255.255.255.0! Crypto ipsec security-association lifetime kilobytes 102400! Crypto ipsec transform-set sun2 ah-md5-hmac esp-des esp-md5-hmac comp-lzs! Crypto map sun2 10 ipsec-isakmp set peer 172.16.10.1 set transform-set sun2 set pfs group2 match address VPN !!!! Interface Loopback2 ip address 2.2.2.2 255.255.255.0 !! Interface Serial1/2 ip address 172.16.10.2 255.255.255.0 encapsulation frame-relay ip ospf priority 0 serial restart-delay 0 frame-relay LR-type cisco crypto map sun2 !! Router ospf 1 router-id 2.2.2.2 log-adjacency-changes network 2.2.2.0 0.0.0.255 area 0 network 172.16.10.2 0.0.0.0 area 0! Ip access-list extended VPN permit tcp host 2.2.2.2 host 1.1.1.1client3 # show run! Ip ssh source-interface Loopback3!! Crypto isakmp policy 10 hash md5 authentication pre-share group 2 lifetime 3600 crypto isakmp key ilovetg2008 address 172.16.10.1! Crypto ipsec security-association lifetime kilobytes 102400! Crypto ipsec transform-set sun3 ah-md5-hmac esp-des esp-md5-hmac comp-lzs! Crypto map sun3 10 ipsec-isakmp set peer 172.16.10.1 set transform-set sun3 set pfs group2 match address VPNinterface Loopback3 ip address 3.3.3.3 255.255.255.0 !! Interface Serial1/3 ip address 172.16.10.3 255.255.255.0 encapsulation frame-relay ip ospf priority 0 serial restart-delay 0 frame-relay LR-type cisco crypto map sun3! Router ospf 1 router-id 3.3.3.3 log-adjacency-changes network 3.3.3.3 0.0.0.0 area 0 network 172.16.10.3 0.0.0.0 area 0! Ip access-list extended VPN permit tcp host 3.3.3.3 host 1.1.1.1 !! R1-sever # show crypto isakmp sadst src state conn-id slot limit 172.16.10.3 QM_IDLE 1 0 limit 172.16.10.2 QM_IDLE 2 0 ACTIVER1-sever # show crypto ipsec sainterface: Serial1/0 Crypto map tag: sun, local addr 172.16.10.1 protected vrf: (none) local ident (addr/mask/prot/port): (1.1.1.1/000000000000255/6/0) remote ident (addr/mask/prot/port ): (2.2.2.2/255.255.255.255/6/0) current_peer 172.16.10.2 port 500 PERMIT, flags ={}# pkts encaps: 15, # pkts encrypt: 15, # pkts digest: 15 # pkts decaps: 16, # pkts decrypt: 16, # pkts verify: 16 # pkts compressed: 0, # pkts decompressed: 0 # pkts not compressed: 15, # pkts compr. failed: 0 # pkts not decompressed: 16, # pkts decompress failed: 0 # send errors 0, # recv errors 0 local crypto endpt.: 172.16.10.1, remote crypto endpt.: 172.16.10.2 path mtu 1500, ip mtu 1500, ip mtu idb Serial1/0 current outbound spi: 0x5B7079B3 (1534097843) protected vrf: (none) local ident (addr/mask/prot/port): (1.1.1.1/255.255.255.255/6/0) remote ident (addr/mask/prot/port): (3.3.3.3/255.255.255.255/6/0) current_peer 172.16.10.3 port 500 PERMIT, flags ={}# pkts encaps: 17, # pkts encrypt: 17, # pkts digest: 17 # pkts decaps: 16, # pkts decrypt: 16, # pkts verify: 16 # pkts compressed: 0, # pkts decompressed: 0 # pkts not compressed: 17, # pkts compr. failed: 0 # pkts not decompressed: 16, # pkts decompress failed: 0 # send errors 0, # recv errors 0 local crypto endpt.: 172.16.10.1, remote crypto endpt.: 172.16.10.3 path mtu 1500, ip mtu 1500, ip mtu idb Serial1/0 current outbound spi: 0x9D287D8D (2636676493) client2 # show crypto isakmp sadst src state conn-id slot restart QM_IDLE 1 0 ACTIVEclient2 # show crypto ipsec sainterface: Serial1/2 Crypto map tag: sun2, local addr restart protected vrf: (none) local ident (addr/mask/prot/port): (2.2.2.2/255.255.255.255/6/0) remote ident (addr/mask/prot/port ): (1.1.1.1/255.255.255.255/6/0) current_peer 172.16.10.1 port 500 PERMIT, flags = {origin_is_acl, }# pkts encaps: 16, # pkts encrypt: 16, # pkts digest: 16 # pkts decaps: 15, # pkts decrypt: 15, # pkts verify: 15 # pkts compressed: 0, # pkts decompressed: 0 # pkts not compressed: 16, # pkts compr. failed: 0 # pkts not decompressed: 15, # pkts decompress failed: 0 # send errors 2, # recv errors 0 local crypto endpt.: 172.16.10.2, remote crypto endpt.: 172.16.10.1 path mtu 1500, ip mtu 1500, ip mtu idb Serial1/2 current outbound spi: 0xE3FF8E06 (3825176070) client3 # show crypto isakmp sadst src state conn-id slot restart QM_IDLE 1 0 ACTIVEclient3 # show crypto ipsec sainterface: Serial1/3 Crypto map tag: sun3, local addr restart protected vrf: (none) local ident (addr/mask/prot/port): (3.3.3.3/255.255.255.255/6/0) remote ident (addr/mask/prot/port ): (1.1.1.1/255.255.255.255/6/0) current_peer 172.16.10.1 port 500 PERMIT, flags = {origin_is_acl, }# pkts encaps: 16, # pkts encrypt: 16, # pkts digest: 16 # pkts decaps: 17, # pkts decrypt: 17, # pkts verify: 17 # pkts compressed: 0, # pkts decompressed: 0 # pkts not compressed: 16, # pkts compr. failed: 0 # pkts not decompressed: 17, # pkts decompress failed: 0 # send errors 2, # recv errors 0 local crypto endpt.: 172.16.10.3, remote crypto endpt.: 172.16.10.1 path mtu 1500, ip mtu 1500, ip mtu idb Serial1/3 current outbound spi: 0xA8BB7A1 (176928673)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.