Easy VPN on vro

Source: Internet
Author: User
Tags domain lookup

 

Company intranet configuration: GS_in # show running-configBuilding configuration... Current configuration: 879 bytes! Version 12.4 service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption! Hostname GS_in! Boot-start-markerboot-end-marker! No aaa new-modelmemory-size iomem 5! Ip cefno ip domain lookup! Interface Loopback1 ip address 4.4.4.4 255.255.255.0! Interface Serial0/0 ip address 10.1.1.4 255.255.255.0 serial restart-delay 0! Interface Serial0/1 no ip address shutdown serial restart-delay 0! Interface Serial0/2 no ip address shutdown serial restart-delay 0! Interface Serial0/3 no ip address shutdown serial restart-delay 0! Ip http serverno ip http secure-server! Ip route 0.0.0.0 0.0.0.0 10.1.1.1! Control-plane! Line con 0 exec-timeout 0 0 logging synchronousline aux 0 line vty 0 4 no loginline vty 5 15 no login! End EzVPN_server configuration: EzVPN_Server # show running-configBuilding configuration... Current configuration: 1597 bytes! Version 12.4 service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption! Hostname EzVPN_Server! Boot-start-markerboot-end-marker! Aaa new-model! Aaa authentication login cisco1 local group radiusaaa authorization network cisco2 local group radius! Aaa session-id commonmemory-size iomem 5! Ip cefno ip domain lookup! Username chinaccie password 0 chinaccie! Crypto isakmp policy 1 encr 3des authentication pre-share group 2! Crypto isakmp client configuration group chinaccie key cisco123 dns 202.196.32.1 domain zzti.edu.cn pool net10! Crypto ipsec transform-set ccie esp-3des esp-sha-hmac! Crypto dynamic-map mymap 1 set transform-set ccie reverse-route! Crypto map ezvpn client authentication list cisco1crypto map ezvpn isakmp authorization list cisco2crypto map ezvpn client configuration address respondcrypto map ezvpn 1 ipsec-isakmp dynamic mymap! Interface Serial0/0 ip address 10.1.1.1 255.255.0 serial restart-delay 0! Interface Serial0/1 ip address 12.1.1.1 255.255.0 serial restart-delay 0 crypto map ezvpn! Interface Serial0/2 no ip address shutdown serial restart-delay 0! Interface Serial0/3 no ip address shutdown serial restart-delay 0! Ip local pool net10 10.1.1.100 10.1.1.200ip http serverno ip http secure-server! Ip route 0.0.0.0 0.0.0.0 12.1.1.2ip route 4.4.4.0 255.255.255.0 10.1.1.4! Control-plane! Line con 0 exec-timeout 0 0 logging synchronousline aux 0 line vty 0 4! End Internet network configuration: Internet # show running-configBuilding configuration... Current configuration: 824 bytes! Version 12.4 service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption! Hostname Internet! Boot-start-markerboot-end-marker! No aaa new-modelmemory-size iomem 5! Ip cefno ip domain lookup! Interface Loopback0 ip address 2.2.2.2 255.255.255.0! Interface Serial0/0 no ip address shutdown serial restart-delay 0! Interface Serial0/1 ip address 12.1.1.2 255.255.0 serial restart-delay 0! Interface Serial0/2 ip address 23.1.1.2 255.255.0 serial restart-delay 0! Interface Serial0/3 no ip address shutdown serial restart-delay 0! Ip http serverno ip http secure-server! Control-plane! Line con 0 exec-timeout 0 0 logging synchronousline aux 0 line vty 0 4! End NAT_enable configuration: NAT_enable # show running-configBuilding configuration... Current configuration: 1225 bytes! Version 12.4 service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption! Hostname NAT_enable! Boot-start-markerboot-end-marker! No aaa new-modelmemory-size iomem 5! Ip cefno ip dhcp use vrf connectedip dhcp excluded-address 30.1.1.3! Ip dhcp pool net30 network 30.1.1.0 255.255.255.0 default-router 30.1.1.3 dns-server 202.196.32.1! Interface Serial0/0 no ip address shutdown serial restart-delay 0! Interface Serial0/1 no ip address shutdown serial restart-delay 0! Interface Serial0/2 ip address 23.1.1.3 255.255.0 ip nat outside ip virtual-reassembly serial restart-delay 0! Interface Serial0/3 no ip address ip virtual-reassembly shutdown serial restart-delay 0! Interface FastEthernet1/0 ip address 30.1.1.3 255.255.255.0 ip nat inside ip virtual-reassembly duplex auto speed auto! Ip http serverno ip http secure-server! Ip route 0.0.0.0 0.0.0.0 23.1.1.2! Ip nat inside source list 3 interface Serial0/2 overload! Access-list 3 permit any! Control-plane! Line con 0 exec-timeout 0 0 logging synchronousline aux 0 line vty 0 4 login! End

This article is from the "IT dream-qi-sharing" blog

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.