思科防火墙PIX8.0 L2LVPN解决地址重叠测试(2)(2)
2013-07-04 01:41
浏览:
ip address 202.100.1.10 255.255.255.0
no shut
interface Ethernet0/1
ip address 202.100.2.10 255.255.255.0
no shut
D.PIX80_Branch防火墙:
interface Ethernet0
nameif Inside
security-level 100
ip address 172.16.1.1 255.255.255.0
no shut
interface Ethernet1
nameif Outside
security-level 0
ip address 202.100.2.1 255.255.255
no shut
route Outside 0.0.0.0 0.0.0.0 202.100.2.10
access-list OUTSIDE extended permit icmp any any
access-group OUTSIDE in interface Outside
E.ERP_Branch路由器:
interface Ethernet0/0
ip address 172.16.1.3 255.255.255.0 secondary
ip address 172.16.1.2 255.255.255.0
no shut
ip route 0.0.0.0 0.0.0.0 172.16.1.1
五.防火墙NAT配置:
A.PIX80_HQ防火墙:
①PAT:
access-list PAT extended permit ip 172.16.1.0 255.255.255.0 any
nat (Inside) 1 access-list PAT
global (Outside) 1 interface
②NAT免除:
access-list NAT0 extended permit ip host 172.16.1.2 host 10.1.2.2
nat (Inside) 0 access-list NAT0
B.PIX80_Branch防火墙:
①PAT:
access-list PAT extended permit ip 172.16.1.0 255.255.255.0 any
nat (Inside) 1 access-list PAT
global (Outside) 1 interface
②静态策略NAT:
access-list VPN-NAT extended permit ip host 172.16.1.2 host 10.1.1.2
static (Inside,Outside) 10.1.2.2 access-list VPN-NAT
③outside的NAT:
static (Outside,Inside) 10.1.1.2 172.16.1.2 netmask 255.255.255.255
----这样当总部未经NAT转换的172.16.1.2到底分别outside接口解密之后,进入内网地址就转换为10.1.1.2
六.L2L VPN配置:
A.PIX80_HQ防火墙:
①第一阶段策略:
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash md5
group 2
tunnel-group 202.100.2.1 type ipsec-l2l
tunnel-group 202.100.2.1 ipsec-attributes
pre-shared-key cisco
②第二阶段转换:
crypto ipsec transform-set transet esp-des esp-md5-hmac
③感兴趣流:
access-list VPN extended permit ip 172.16.1.0 255.255.255.0 10.1.2.0 255.255.0.0
- -
-
- 相关推荐
-
- CCNA证书实验一(CISCO路由器的基本操作)
- Cisco 3640系列IPsec VPN简单配置
- 思科默认路由以及浮动路由
- 双线接入下的cisco路由器和交换机的配置方法
- Cisco 配置STP与VTP
- IPv6在路由、PC上的配置教程
- 思科路由器L2L、EzVPN旁挂方式部署测试
- ADSL并用CISCO路由器自建PPPoe Server上网
- 实例讲解 思科RIP动态路由基本配置
- 思科Easy VPN的运用
- 思科防火墙PIX8.0 L2LVPN解决地址重叠测试(2)
- 用思科做HSRP
- CISCO组播RPF逆向路径转发实验原理
- 【实例】CCNA EIGRP路由协议的配置
- cisco 2960如何保存配置到本地,适用其他思科路由
- 半年热点
-
melogin.cn页面进不去怎么办
浏览: 196
【教程】华为TC5200路由器怎么设置
浏览: 196
【视频】如何通过手机设置TP-LINK无线路由器上网
浏览: 127
华为荣耀路由Pro2使用设置方法
浏览: 164
【教程】怎么在手机上修改路由器的WIFI密码
浏览: 147
【视频教程】迅捷(Fast)路由器如何设置?
浏览: 104
手机如何设置TP-LINK路由器?
浏览: 97
自己家里的wifi密码怎么改
浏览: 95
遇到无法登录tplogin.cn的情况,怎么办?
浏览: 119
192.168.1.1打不开怎么办(二)
浏览: 174
192.168.1.1打不开怎么办(一)
浏览: 158