IKEv1配置執行個體(二)

來源:互聯網
上載者:User

標籤:ikev2


650) this.width=650;" height="318" src="http://b116.photo.store.qq.com/psb?/dd6cf90d-9cf5-423f-a387-c4b5be2610ea/zk.Lv.0Ybcb2Im1HutdFs9KGFASz42vRWI*Cf6wg0ts!/b/dC3lLkWxDAAA&ek=1&kp=1&pt=0&bo=kANOAQAAAAABAPs!&t=5&su=064279809&sce=0-12-12&rf=2-9" width="870" style="margin:0px;padding:0px;border-width:0px;border-style:none;vertical-align:top;width:847px;height:309.593px;" alt="dC3lLkWxDAAA&ek=1&kp=1&pt=0&bo=kANOAQAAA" />

將site1換成ASA防火牆:

ASA配置如下:

ASA(config)# show run int 

!

interface GigabitEthernet0

 nameif Inside

 security-level 100

 ip address 10.1.1.1 255.255.255.0 

!

interface GigabitEthernet1

 nameif Outside

 security-level 0

 ip address 202.100.1.1 255.255.255.0


#step1 配置路由:

ASA(config)# show run route

route Outside 0.0.0.0 0.0.0.0 202.100.1.10 1

route Inside 0.0.0.0 0.0.0.0 10.1.1.10 tunneled


#step2 配置ISAKMP策略

crypto ikev1 policy 10

 authentication pre-share

 encryption 3des

 hash md5

 group 2

#step3 配置ISAKMP預共用密碼:

ASA(config)# show run tunnel-group 

tunnel-group 61.128.1.1 type ipsec-l2l

tunnel-group 61.128.1.1 ipsec-attributes

 ikev1 pre-shared-key L2Lkey


 #step4 配置感興趣流:
access-list vpn extended permit ip 1.1.1.0 255.255.255.0 2.2.2.0 255.255.255.0

#step5 配置轉換集:
 crypto ipsec ikev1 transform-set Trans esp-des esp-md5-hmac

 #step6配置crypto map
 
crypto map cry-map 10 match address vpn

crypto map cry-map 10 set peer 61.128.1.1 

crypto map cry-map 10 set ikev1 transform-set Trans
 
#step7 調用 crypto map

crypto map cry-map interface Outside

 

測試:

PC1#ping 2.2.2.2 source 1.1.1.1 repeat 100

Type escape sequence to abort.

Sending 100, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:

Packet sent with a source address of 1.1.1.1 

!!!!.!!!!.!!!.!!!!!!!!!!!!!!!.!!!!.!!!.!!!!!!!!!!!!!!!.!!!!!!!!!!!.!!!

!.!!!.!!!!!!!!!!!!!!!.!!!!.!!!

Success rate is 88 percent (88/100), round-trip min/avg/max = 60/79/124 ms


telnet測試:

Site2#telnet 1.1.1.1 /source-interface lo 0 

Trying 1.1.1.1 ... Open

User Access Verification

Password: 

PC1>

查看防火牆:

ASA(config)# show run all sysopt 

no sysopt connection timewait

sysopt connection tcpmss 1380

sysopt connection tcpmss minimum 0

sysopt connection permit-vpn

sysopt connection reclassify-vpn

no sysopt connection preserve-vpn-flows

no sysopt radius ignore-secret

no sysopt noproxyarp Inside

no sysopt noproxyarp Outside

預設所有的vpn流量是允許存取的
所以兩邊都是通的

修改防火牆:
ASA(config)# no sysopt connection permit-vpn 

 測試:

(1)Site2#telnet 1.1.1.1 /source-interface lo 0 

Trying 1.1.1.1 ... 

% Connection timed out; remote host not responding

(2)
PC1#ping 2.2.2.2 source 1.1.1.1           

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:

Packet sent with a source address of 1.1.1.1 

.....

Success rate is 0 percent (0/5) 

做存取控制:
讓site2可以telnet到PC1

 
ASA(config)#access-list out_in_telnet extended permit tcp 2.2.2.0 255.255.255.0 1.1.1.0 255.255.255.0 eq 23

 ASA(config)#access-group out_in_telnet in interface out

 

Site2#telnet 1.1.1.1 /source-interface lo 0 

Trying 1.1.1.1 ... Open

User Access Verification

Password: 

PC1>


本文出自 “迷荼” 部落格,謝絕轉載!

IKEv1配置執行個體(二)

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.