
对Telnet数据流进行加密,对其他IP数据流进行认证
1、London路由器上连通性配置
London(config)#interface Loopback0
London(config-if)#ip address 10.1.1.1 255.255.255.0
London(config)#interface Serial0/0
London(config-if)#ip address 173.16.1.1 255.255.255.252
London(config-if)#no shutdown
London(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.2
2、Denver路由器上连通性配置
Denver(config)#interface Loopback0
Denver(config-if)#ip address 10.2.2.1 255.255.255.0
Denver(config)#interface Serial0/0
Denver(config-if)#ip address 173.16.1.5 255.255.255.252
Denver(config-if)#no shutdown
Denver(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.6
3、London路由器配置IPsec
London(config)#crypto isakmp enable
London(config)#crypto isakmp policy 10
London(config-isakmp)#hash md5
London(config-isakmp)#authentication pre-share
London(config-isakmp)#encryption 3des
London(config-isakmp)#group 2
London(config)#crypto isakmp key cisco1234 address 173.16.1.5
London(config)#crypto ipsec transform-set encrypt esp-des esp-md5-hmac
London(config)#crypto ipsec transform-set authent ah-md5-hmac
London (cfg-crypto-trans)#mode tunnel
London(config)#crypto map cisco 10 ipsec-isakmp
London(config-crypto-map)#set peer 173.16.1.5
London(config-crypto-map)#set transform-set encrypt
London(config-crypto-map)#match address 101 (对匹配ACL101的流量进行加密)
London(config)#crypto map cisco 20 ipsec-isakmp
London(config-crypto-map)#set peer 173.16.1.5
London(config-crypto-map)#set transform-set authent
London(config-crypto-map)#match address 102 (对匹配ACL102的流量进行认证)
London(config)#access-list 101 permit tcp 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 eq 23
London(config)#access-list 102 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
London(config)#interface Serial0/0
London(config-if)#crypto map cisco
4、Denver路由器配置IPsec
Denver(config)#crypto isakmp enable
Denver(config)#crypto isakmp policy 10
Denver(config-isakmp)#hash md5
Denver(config-isakmp)#authentication pre-share
Denver(config-isakmp)#encryption 3des
Denver(config-isakmp)#group 2
Denver(config)#crypto isakmp key cisco1234 address 173.16.1.1
Denver(config)#crypto ipsec transform-set encrypt esp-des esp-md5-hmac
Denver(config)#crypto ipsec transform-set authent ah-md5-hmac
Denver(cfg-crypto-trans)#mode tunnel
Denver(config)#crypto map cisco 10 ipsec-isakmp
Denver(config-crypto-map)#set peer 173.16.1.1
Denver(config-crypto-map)#set transform-set encrypt
Denver(config-crypto-map)#match address 101 (对匹配ACL101的流量进行加密)
Denver(config)#crypto map cisco 20 ipsec-isakmp
Denver(config-crypto-map)#set peer 173.16.1.1
Denver(config-crypto-map)#set transform-set authent
Denver(config-crypto-map)#match address 102 (对匹配ACL102的流量进行认证)
Denver(config)#access-list 101 permit tcp 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255 eq 23
Denver(config)#access-list 102 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255
Denver(config)#interface Serial0/0
Denver(config-if)#crypto map cisco
1、London路由器上连通性配置
London(config)#interface Loopback0
London(config-if)#ip address 10.1.1.1 255.255.255.0
London(config)#interface Serial0/0
London(config-if)#ip address 173.16.1.1 255.255.255.252
London(config-if)#no shutdown
London(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.2
2、Denver路由器上连通性配置
Denver(config)#interface Loopback0
Denver(config-if)#ip address 10.2.2.1 255.255.255.0
Denver(config)#interface Serial0/0
Denver(config-if)#ip address 173.16.1.5 255.255.255.252
Denver(config-if)#no shutdown
Denver(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.6
3、London路由器配置IPsec
London(config)#crypto isakmp enable
London(config)#crypto isakmp policy 10
London(config-isakmp)#hash md5
London(config-isakmp)#authentication pre-share
London(config-isakmp)#encryption 3des
London(config-isakmp)#group 2
London(config)#crypto isakmp key cisco1234 address 173.16.1.5
London(config)#crypto ipsec transform-set encrypt esp-des esp-md5-hmac
London(config)#crypto ipsec transform-set authent ah-md5-hmac
London (cfg-crypto-trans)#mode tunnel
London(config)#crypto map cisco 10 ipsec-isakmp
London(config-crypto-map)#set peer 173.16.1.5
London(config-crypto-map)#set transform-set encrypt
London(config-crypto-map)#match address 101 (对匹配ACL101的流量进行加密)
London(config)#crypto map cisco 20 ipsec-isakmp
London(config-crypto-map)#set peer 173.16.1.5
London(config-crypto-map)#set transform-set authent
London(config-crypto-map)#match address 102 (对匹配ACL102的流量进行认证)
London(config)#access-list 101 permit tcp 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 eq 23
London(config)#access-list 102 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
London(config)#interface Serial0/0
London(config-if)#crypto map cisco
4、Denver路由器配置IPsec
Denver(config)#crypto isakmp enable
Denver(config)#crypto isakmp policy 10
Denver(config-isakmp)#hash md5
Denver(config-isakmp)#authentication pre-share
Denver(config-isakmp)#encryption 3des
Denver(config-isakmp)#group 2
Denver(config)#crypto isakmp key cisco1234 address 173.16.1.1
Denver(config)#crypto ipsec transform-set encrypt esp-des esp-md5-hmac
Denver(config)#crypto ipsec transform-set authent ah-md5-hmac
Denver(cfg-crypto-trans)#mode tunnel
Denver(config)#crypto map cisco 10 ipsec-isakmp
Denver(config-crypto-map)#set peer 173.16.1.1
Denver(config-crypto-map)#set transform-set encrypt
Denver(config-crypto-map)#match address 101 (对匹配ACL101的流量进行加密)
Denver(config)#crypto map cisco 20 ipsec-isakmp
Denver(config-crypto-map)#set peer 173.16.1.1
Denver(config-crypto-map)#set transform-set authent
Denver(config-crypto-map)#match address 102 (对匹配ACL102的流量进行认证)
Denver(config)#access-list 101 permit tcp 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255 eq 23
Denver(config)#access-list 102 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255
Denver(config)#interface Serial0/0
Denver(config-if)#crypto map cisco
转载于:https://blog.51cto.com/allens21/52533