【正文】
set transformset tim 配置端口的應用 reverseroute crypto map tom client authentication list eza(創(chuàng)建 Crypto Map) crypto map tom isakmp authorization list ezo crypto map tom client configuration address respond 9 crypto map tom 10 ipsecisakmp dynamic ezmap crypto map tom 11 ipsecisakmp set peer (指定了此 Crypto Map 所對應的 VPN 鏈路對端的 IP 地址) set transformset tim match address 101 no ip domainlookup interface FastEther0/0(配置端口 IP) ip address ip nat inside duplex auto speed auto interface FastEther0/1 ip address ip nat outside duplex auto speed auto crypto map tom interface Vlan1 no ip address shutdown ip local pool wzf ip nat inside source list 100 interface FastEther0/1 overload ip nat inside source static tcp 80 80 ip classless ip route accesslist 100 deny ip accesslist 100 permit ip any accesslist 101 permit ip line con 0 exectimeout 0 0 logging synchronous login 10 line vty 0 4 login end 分公司路由器配置 為路由命名并賦予 IP hostname fenbu ip dhcp excludedaddress ip dhcp pool zongbu work defaultrouter dnsserver 配置 IKE 協(xié)商策略與參數(shù) crypto isakmp policy 10 encr 3des hash md5 authentication preshare crypto isakmp key tom address 配置 IPsec 訪問列表與傳輸模式 crypto ipsec transformset tim esp3des espmd5hmac crypto map tom 10 ipsecisakmp set peer set transformset tim match address 101 no ip domainlookup 配置端口的應用 interface FastEther0/0 ip address ip nat outside duplex auto speed auto crypto map tom interface FastEther0/1 ip address ip nat inside 11 duplex auto speed auto interface Vlan1 no ip address shutdown ip nat inside source list 100 interface FastEther0/0 overload ip classless ip route accesslist 100 deny ip accesslist 100 permit ip any accesslist 101 permit ip line con 0 exectimeout 0 0 logging synchronous line vty 0 4 login end Inter 路由器配置 hostname Inter ip dhcp excludedaddress ip dhcp pool wifi work defaultrouter dnsserver no ip domainlookup ip nameserver interface FastEther0/0 ip address duplex auto speed auto interface FastEther0/1 ip address duplex auto 12 speed auto interface Ether1/0 ip address duplex auto speed auto interface Ether1/1 ip address duplex auto speed auto interface Vlan1