最簡(jiǎn)環(huán)境下的IPsec VPN配置舉例
對(duì)于初學(xué)網(wǎng)絡(luò)設(shè)備配置的人來(lái)說(shuō)VPN是個(gè)難點(diǎn),在配置時(shí)總會(huì)出現(xiàn)這樣那樣的問(wèn)題,在網(wǎng)上看到很多配置都是綜合應(yīng)用,出錯(cuò)時(shí)就不知道那些地方出錯(cuò)了,下面在Packet tracer5.3下用最簡(jiǎn)單的環(huán)境進(jìn)行配置。
第一:首先保證內(nèi)網(wǎng)能夠訪問(wèn)外網(wǎng)(地址轉(zhuǎn)換)
配置PC機(jī)IP
school-vpn上作如下配置:
- int F0/0
- ip address 192.168.1.254 255.255.255.0
- ip nat inside
- int F0/1
- ip address 100.1.1.1 255.255.255.0
- ip nat outside
- crypto map school-map(VPN配置完成最后再配)
- p nat inside source list 1 interface FastEthernet0/1 overload 端口復(fù)用
- access-list 1 permit 192.168.1.0 0.0.0.255 (允許 192.168.1.0/24網(wǎng)段訪問(wèn)外網(wǎng))
- ip route 0.0.0.0 0.0.0.0 FastEthernet0/1 (缺省路由)
ISP上作如下配置:
- int F0/0
- ip address 100.1.1.2 255.255.255.0
- int F0/1
- ip address 200.1.1.1 255.255.255.0
進(jìn)行測(cè)試:內(nèi)網(wǎng)可以連到外網(wǎng)上
第二:進(jìn)行IPSEC-vpn配置
school-vpn上作如下配置:
- aaa new-model
- aaa authentication login vpn-a local
- aaa authorization network vpn-o local 進(jìn)行3A認(rèn)證
- username vpn password 0 vpn 建立用戶以及密碼
- crypto isakmp policy 10 建立ipsec安全參數(shù)配置
- hash md5
- authentication pre-share
- crypto isakmp client configuration group vpng easyvpn的組及密碼配置,vpngroup為組名
- key vpn 群組密碼
- pool vpn-p VPN用戶的地址池
- ip local pool vpn-p 192.168.100.1 192.168.100.10 建立分配給VPN用戶的地址池
- crypto ipsec transform-set school-set esp-3des esp-md5-hmac Ipsec階段2配置
- crypto dynamic-map d-map 10 動(dòng)態(tài)加密圖
- set transform-set school-set
- reverse-route 反向路由注入
- crypto map school-map client authentication list vpn-a Easyvpn用戶的認(rèn)證授權(quán)配置
- crypto map school-map isakmp authorization list vpn-o
- crypto map school-map client configuration address respond
- crypto map school-map 10 ipsec-isakmp dynamic d-map
最后在端口上綁定:
- interface FastEthernet0/1
- crypto map school-map
校外工作人員從外網(wǎng)登錄到內(nèi)網(wǎng):