{"id":980,"date":"2021-10-11T20:59:02","date_gmt":"2021-10-12T03:59:02","guid":{"rendered":"https:\/\/www.xh86.me\/?p=980"},"modified":"2021-10-11T20:59:02","modified_gmt":"2021-10-12T03:59:02","slug":"cisco%e9%85%8d%e7%bd%aevpn-ipsec","status":"publish","type":"post","link":"https:\/\/www.xh86.me\/?p=980","title":{"rendered":"Cisco\u914d\u7f6eVPN IPSec"},"content":{"rendered":"<h1 id=\"\u5b9e\u9a8c\u62d3\u6251\">\u5b9e\u9a8c\u62d3\u6251<\/h1>\n<p><a class=\"fancybox fancybox.image\" href=\"https:\/\/i.loli.net\/2019\/03\/28\/5c9c3006a1ccd.png\" rel=\"group\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/i.loli.net\/2019\/03\/28\/5c9c3006a1ccd.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/i.loli.net\/2019\/03\/28\/5c9c3006a1ccd.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"00.png\" \/><\/div><\/a><\/p>\n<h1 id=\"\u914d\u7f6e\u8fd0\u8425\u5546\u7f51\u7edc\">\u914d\u7f6e\u8fd0\u8425\u5546\u7f51\u7edc<\/h1>\n<p>\u5728\u914d\u7f6eVPN\u4e4b\u524d\uff0c\u9996\u5148\u8981\u4fdd\u8bc1\u6a21\u62df\u7684\u8fd0\u8425\u5546\u7f51\u7edc\u662f\u53ef\u4ee5\u6b63\u5e38\u901a\u4fe1\u7684\uff0c\u8fd9\u91cc\u6211\u914d\u7f6e\u7684\u662fOSPF\uff0c\u9700\u8981\u6ce8\u610f\u7684\u662f\u4e24\u8fb9\u7684\u8def\u7531\u5668\u4e0d\u8981\u628a\u5185\u7f51\u7f51\u6bb5\u4e5f\u7ed9\u5ba3\u544a\u51fa\u53bb\u4e86\uff0c\u5982\u679c\u662f\u8fd9\u6837\u90a3VPN\u4e5f\u5c31\u6ca1\u6709\u5b58\u5728\u7684\u610f\u4e49\u4e86\u3002<br \/>\n\u9996\u5148\u662f\u5de6\u8fb9\u7684R1\uff1a<\/p>\n<pre><code>Router(config)#int f0\/0\r\nRouter(config-if)#ip add 202.1.1.1 255.255.255.0\r\nRouter(config-if)#no shut\r\nRouter(config-if)#exit\r\nRouter(config)#router ospf 1\r\nRouter(config-router)#net 202.1.1.0 0.0.0.255 area 0\r\n<\/code><\/pre>\n<p>\u4e2d\u95f4\u7684R0\uff1a<\/p>\n<pre><code>Router(config)#int f0\/0\r\nRouter(config-if)#ip add 202.1.1.254 255.255.255.0\r\nRouter(config-if)#no shut\r\nRouter(config)#int f0\/1\r\nRouter(config-if)#ip add 210.1.1.254 255.255.255.0\r\nRouter(config-if)#no shut\r\nRouter(config-if)#exit\r\nRouter(config)#router ospf 1\r\nRouter(config-router)#net 202.1.1.0 0.0.0.255 area 0\r\nRouter(config-router)#net 210.1.1.0 0.0.0.255 area 0\r\n<\/code><\/pre>\n<p>\u53f3\u8fb9\u7684R2\uff1a<\/p>\n<pre><code>Router(config)#int f0\/0\r\nRouter(config-if)#ip add 210.1.1.1 255.255.255.0\r\nRouter(config-if)#no shut\r\nRouter(config-if)#exit\r\nRouter(config)#router ospf 1\r\nRouter(config-router)#net 210.1.1.0 0.0.0.255 area 0\r\n<\/code><\/pre>\n<p>\u7b49\u5f85\u6536\u655b\u5b8c\u6210\u9a8c\u8bc1\u7f51\u7edc\u662f\u5426\u53ef\u4ee5\u6b63\u5e38\u901a\u4fe1\u3002<\/p>\n<h1 id=\"\u914d\u7f6e\u5185\u7f51\">\u914d\u7f6e\u5185\u7f51<\/h1>\n<p>\u5185\u7f51\u8fc7\u4e8e\u7b80\u5355\u8fd9\u91cc\u4e0d\u518d\u8d58\u8ff0\uff0c\u6211\u7684\u5de6\u8fb9\u7684\u533a\u57df1\u7684\u7f51\u6bb5\u662f10.0.1.0\/24\uff0c\u53f3\u8fb9\u7684\u533a\u57df2\u662f10.0.2.0\/24\uff0c\u7f51\u5173\u5219\u5206\u522b\u4e3a1.1\u548c2.1\u3002<\/p>\n<h1 id=\"\u914d\u7f6eIPSec-site-to-site\">\u914d\u7f6eIPSec(site to site)<\/h1>\n<p>R1:<\/p>\n<pre><code>Router(config)#crypto isakmp enable #\u542f\u7528IKE,\u9ed8\u8ba4\u5373\u4e3a\u542f\u52a8\r\nRouter(config)#crypto isakmp policy 1 #\u5b9a\u4e49IKE\u5b89\u5168\u7b56\u7565\u96c61\r\nRouter(config-isakmp)#authentication pre-share #IKE\u9a8c\u8bc1\u65b9\u5f0f\u80c3\u9884\u5171\u4eab\u5bc6\u94a5\r\nRouter(config-isakmp)#encryption 3des #IKE\u52a0\u5bc6\u65b9\u5f0f\u4e3a3des\r\nRouter(config-isakmp)#group 1 #IKE\u4f7f\u7528Diffie-Hellman\u7ec41\r\nRouter(config-isakmp)#hash md5 #IKE\u7684Hash\u9a8c\u8bc1\u4e3aMD5\r\nRouter(config-isakmp)#exit\r\nRouter(config)#crypto isakmp key cyne address 210.1.1.1 #\u4e24\u7aef\u7684KEY\u5fc5\u987b\u4e00\u81f4\uff0c210.1.1.1\u662f\u5bf9\u7aef\u7684\u516c\u7f51\u5730\u5740\r\nRouter(config)#crypto ipsec transform-set lab ah-md5-hmac esp-3des #\u5b9a\u4e49VPN\u4f7f\u7528IPSec\u7b56\u7565\u96c6\uff0clab\u4e3a\u7b56\u7565\u96c6\u540d\u79f0\r\nRouter(config)#access-list 100 permit ip 10.0.1.0 0.0.0.255 10.0.2.0 0.0.0.255 #\u5b9a\u4e49\u5728R1\u4e0a\u9700\u8981\u52a0\u5bc6\u7684\u6d41\u91cf\r\nRouter(config)#crypto map test 110 ipsec-isakmp #\u5b9a\u4e49\u52a0\u5bc6\u56fe\r\nRouter(config-crypto-map)#match address 100 #\u5728\u52a0\u5bc6\u56fe\u4e2d\u58f0\u660e\u52a0\u5bc6\u6d41\u91cf\u5217\u8868\r\nRouter(config-crypto-map)#set peer 210.1.1.1 #\u5bf9\u7aef\u516c\u7f51ip\r\nRouter(config-crypto-map)#set transform-set lab #\u5728\u52a0\u5bc6\u56fe\u4e2d\u8c03\u7528IPSec\u7684\u7b56\u7565\u96c6lab\r\nRouter(config-crypto-map)#exit\r\nRouter(config)#int f0\/0\r\nRouter(config-if)#crypto map test #\u5c06\u52a0\u5bc6\u56fe\u5e94\u7528\u5230\u6b64\u7aef\u53e3\r\nRouter(config-if)#exit \r\nRouter(config)#ip route 10.0.2.0 255.255.255.0 f0\/0 #\u6307\u5b9aVPN\u7684\u9759\u6001\u8def\u7531\r\n<\/code><\/pre>\n<p>R2:<\/p>\n<pre><code>Router(config)#crypto isakmp enable\r\nRouter(config)#crypto isakmp policy 1\r\nRouter(config-isakmp)#authentication pre-share \r\nRouter(config-isakmp)#encryption 3des\r\nRouter(config-isakmp)#group 1\r\nRouter(config-isakmp)#hash md5\r\nRouter(config-isakmp)#exit\r\nRouter(config)#crypto isakmp key cyne address 202.1.1.1 #\u4e24\u7aef\u7684KEY\u5fc5\u987b\u4e00\u81f4\uff0c202.1.1.1\u662f\u5bf9\u7aef\u7684\u516c\u7f51\u5730\u5740\r\nRouter(config)#crypto ipsec transform-set lab ah-md5-hmac esp-3des\r\nRouter(config)#access-list 100 permit ip 10.0.2.0 0.0.0.255 10.0.1.0 0.0.0.255\r\nRouter(config)#crypto map test 110 ipsec-isakmp \r\nRouter(config-crypto-map)#match address 100 \r\nRouter(config-crypto-map)#set peer 202.1.1.1 #\u5bf9\u7aef\u516c\u7f51ip\r\nRouter(config-crypto-map)#set transform-set lab\r\nRouter(config-crypto-map)#exit\r\nRouter(config)#int f0\/0\r\nRouter(config-if)#crypto map test\r\nRouter(config-if)#exit \r\nRouter(config)#ip route 10.0.1.0 255.255.255.0 f0\/0\r\n<\/code><\/pre>\n<h1 id=\"\u9a8c\u8bc1\u7ed3\u679c\">\u9a8c\u8bc1\u7ed3\u679c<\/h1>\n<p>\u4f7f\u7528\u533a\u57df1\u5185\u7684PC ping \u533a\u57df2\u4e2d\u7684PC\uff0c\u53d1\u73b0\u5df2\u7ecf\u53ef\u4ee5\u901a\u4fe1\uff1a<br \/>\n<a class=\"fancybox fancybox.image\" href=\"https:\/\/i.loli.net\/2019\/03\/28\/5c9c3cfee86a3.png\" rel=\"group\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/i.loli.net\/2019\/03\/28\/5c9c3cfee86a3.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/i.loli.net\/2019\/03\/28\/5c9c3cfee86a3.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"01.png\" \/><\/div><\/a><\/p>\n<h1 id=\"NAT-IPSec-VPN\">NAT + IPSec VPN<\/h1>\n<p>NAT\u548cIPSec\u5b58\u5728\u4e00\u4e9b\u4e0d\u517c\u5bb9\u7684\u60c5\u51b5\uff0c\u6bd4\u5982NAT\u66f4\u6539\u4e86IP\u5934\u90e8\u4e2d\u7684\u6e90\u5730\u5740\u548c\u76ee\u7684\u5730\u5740\uff0c\u6821\u9a8c\u548c\u4f1a\u88ab\u91cd\u65b0\u8ba1\u7b97\u5e76\u4fee\u6539\uff0c\u6240\u4ee5\u5bfc\u81f4\u88ab\u5bf9\u7aefIPSec\u4e22\u5f03\u7b49\u7b49\u3002<\/p>\n<p>\u90a3\u5982\u679c\u914d\u7f6e\u4e86NAT\u4e4b\u540e\u5e94\u8be5\u5982\u4f55\u8ba9IPSec\u6b63\u5e38\u5de5\u4f5c\u5462\uff1f\u4eca\u5929\u5728\u6572\u5b9e\u9a8c\u7684\u65f6\u5019\u601d\u8003\u4e86\u5f88\u4e45\uff0c\u6700\u540e\u627e\u5230\u4e86\u901a\u8fc7\u66f4\u6539ACL\u4e5f\u5c31\u662f\u66f4\u6539IPSec\u7684\u201c\u611f\u5174\u8da3\u201d\u6d41\u91cf\u6765\u89e3\u51b3\uff0c\u7b80\u5355\u62d3\u6251\u5982\u4e0b\uff1a<br \/>\n<a class=\"fancybox fancybox.image\" href=\"https:\/\/i.loli.net\/2019\/06\/25\/5d121572efee411287.png\" rel=\"group\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/i.loli.net\/2019\/06\/25\/5d121572efee411287.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/i.loli.net\/2019\/06\/25\/5d121572efee411287.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"21.png\" \/><\/div><\/a><br \/>\n\u4e24\u7aef\u516c\u7f51\u63a5\u5165\u8def\u7531\u5668\u7684ACL\u8fdb\u884c\u5982\u4e0b\u914d\u7f6e\uff1a<\/p>\n<pre><code>R1#sh access-lists 100\r\nExtended IP access list 100\r\n    permit ip 172.16.5.0 0.0.0.255 172.16.2.0 0.0.0.255\r\n    permit ip 172.16.2.0 0.0.0.255 218.18.1.0 0.0.0.3\r\n    permit ip 218.18.1.0 0.0.0.3 172.16.2.0 0.0.0.255\r\n<\/code><\/pre>\n<pre><code>R2#sh access-lists 100\r\nExtended IP access list 100\r\n    permit ip 172.16.2.0 0.0.0.255 172.16.5.0 0.0.0.255\r\n    permit ip host 218.18.1.2 172.16.2.0 0.0.0.255\r\n    permit ip 172.16.2.0 0.0.0.255 218.18.1.0 0.0.0.3\r\n<\/code><\/pre>\n<p>\u4e0a\u8ff0ACL\u7684\u4f5c\u7528\u4e5f\u5c31\u662f\u628aNAT\u4e4b\u540e\u7684\u516c\u7f51IP\u5730\u5740\u52a0\u5165\u5230IPSec\u7684\u611f\u5174\u8da3\u6d41\u91cf\u4e2d\u3002\u5f53\u7136\uff0c\u8fd9\u4e5f\u53ea\u662f\u6211\u5728\u5b9e\u9a8c\u4e2d\u81ea\u5df1\u6478\u7d22\u7684\u89e3\u51b3\u65b9\u6cd5\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5b9e\u9a8c\u62d3\u6251 \u914d\u7f6e\u8fd0\u8425\u5546\u7f51\u7edc \u5728\u914d\u7f6eVPN\u4e4b\u524d\uff0c\u9996\u5148\u8981\u4fdd\u8bc1\u6a21\u62df\u7684\u8fd0\u8425\u5546\u7f51\u7edc\u662f\u53ef\u4ee5\u6b63\u5e38\u901a\u4fe1\u7684\uff0c\u8fd9\u91cc\u6211\u914d\u7f6e\u7684\u662fOSPF [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-980","post","type-post","status-publish","format-standard","hentry","category-cisco"],"_links":{"self":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=980"}],"version-history":[{"count":1,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/980\/revisions"}],"predecessor-version":[{"id":981,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/980\/revisions\/981"}],"wp:attachment":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}