1、實(shí)驗(yàn)拓?fù)?/p>
專業(yè)從事網(wǎng)站設(shè)計(jì)、做網(wǎng)站,高端網(wǎng)站制作設(shè)計(jì),微信小程序定制開發(fā),網(wǎng)站推廣的成都做網(wǎng)站的公司。優(yōu)秀技術(shù)團(tuán)隊(duì)竭力真誠服務(wù),采用H5技術(shù)+CSS3前端渲染技術(shù),響應(yīng)式網(wǎng)站設(shè)計(jì),讓網(wǎng)站在手機(jī)、平板、PC、微信下都能呈現(xiàn)。建站過程建立專項(xiàng)小組,與您實(shí)時(shí)在線互動(dòng),隨時(shí)提供解決方案,暢聊想法和感受。2、基礎(chǔ)網(wǎng)絡(luò)配置
R1配置:
ip dhcp excluded-address 13.1.1.1 13.1.1.2
ip dhcp pool net13
network 13.1.1.0 255.255.255.0
default-router 13.1.1.1
interface FastEthernet0/0
ip address 12.1.1.1 255.255.255.0
interface FastEthernet1/0
ip address 13.1.1.1 255.255.255.0
R2配置:
interface FastEthernet0/0
ip address 12.1.1.2 255.255.255.0
interface FastEthernet1/0
ip address 172.16.1.254 255.255.255.0
ip route 0.0.0.0 0.0.0.0 12.1.1.1
R3配置:
interface Loopback0
ip address 3.3.3.3 255.255.255.0
interface FastEthernet0/0
ip address dhcp
interface FastEthernet1/0
ip address 192.168.1.254 255.255.255.0
ip route 0.0.0.0 0.0.0.0 13.1.1.1
R4配置:
interface FastEthernet0/0
ip address 172.16.1.1 255.255.255.0
ip route 0.0.0.0 0.0.0.0 172.16.1.254
R5配置:
interface FastEthernet0/0
ip address 192.168.1.1 255.255.255.0
ip route 0.0.0.0 0.0.0.0 192.168.1.254
3、配置Dynamic p2p GRE over IPsec
3.1、配置GRE
R2配置:
interface Tunnel2
ip address 1.1.1.1 255.255.255.0
tunnel source 12.1.1.2
tunnel destination 3.3.3.3
ip route 3.3.3.3 255.255.255.255 12.1.1.1
這條路由必須配置,這是配置規(guī)則要求的
R3配置:
interface Tunnel3
ip address 1.1.1.2 255.255.255.0
tunnel source Loopback0
tunnel destination 12.1.1.2
3.2、R2配置Dynamic LAN-to-LAN ×××(相對(duì)普通的Dynamic LAN-to-LAN ×××多了一條指令)
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0
crypto ipsec transform-set ccie esp-3des esp-sha-hmac
crypto dynamic-map dymap 1
set transform-set ccie
crypto map mymap 1 ipsec-isakmp dynamic dymap (經(jīng)測試,這條指令可以不寫)
crypto map mymap local-address FastEthernet0/0
interface FastEthernet0/0
crypto map mymap
3.3、R3配置LAN-to-LAN ×××(與普通LAN-to-LAN ×××的ACL不同,多了一條指令)
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp key cisco123 address 12.1.1.2
crypto ipsec transform-set ccie esp-3des esp-sha-hmac
access-list 100 permit gre 3.3.3.0 0.0.0.255 12.1.1.0 0.0.0.255
crypto map mymap 1 ipsec-isakmp
set peer 12.1.1.2
set transform-set ccie
match address 100
crypto map mymap local-address FastEthernet0/0(經(jīng)測試,這條指令可以不寫)
interface FastEthernet0/0
crypto map mymap
3.4、配置動(dòng)態(tài)路由協(xié)議(此時(shí)私網(wǎng)流量走的都是隧道。)
R2配置:
router ospf 1
network 1.1.1.0 0.0.0.255 area 0
network 172.16.1.0 0.0.0.255 area 0
R3配置:
router ospf 1
network 1.1.1.0 0.0.0.255 area 0
network 192.168.1.0 0.0.0.255 area 0
4、NAT對(duì)Dynamic p2p GRE over IPsec的影響與NAT對(duì)Static p2p GRE over IPsec的影響一樣
另外有需要云服務(wù)器可以了解下創(chuàng)新互聯(lián)scvps.cn,海內(nèi)外云服務(wù)器15元起步,三天無理由+7*72小時(shí)售后在線,公司持有idc許可證,提供“云服務(wù)器、裸金屬服務(wù)器、高防服務(wù)器、香港服務(wù)器、美國服務(wù)器、虛擬主機(jī)、免備案服務(wù)器”等云主機(jī)租用服務(wù)以及企業(yè)上云的綜合解決方案,具有“安全穩(wěn)定、簡單易用、服務(wù)可用性高、性價(jià)比高”等特點(diǎn)與優(yōu)勢,專為企業(yè)上云打造定制,能夠滿足用戶豐富、多元化的應(yīng)用場景需求。