[RT1]ping -a 192.168.40.254 172.16.40.254 //在RT1上触发主动去协商,下面协商成功截图
配置NAT:
[RT1]acl advanced 3010
[RT1-acl-ipv4-adv-3010]rule 5 deny ip source 192.168.40.0 0.0.0.255 destination 172.16.40.0 0.0.0.255
[RT1-acl-ipv4-adv-3010]rule 100 permit ip
[RT1-acl-ipv4-adv-3010]quit
[RT1]interface Serial 1/0
[RT1-Serial1/0]nat outbound 3010
RT2也是如此
RT1配置文件:
[RT1]display current-configuration
#
version 7.1.075, Alpha 7571
#
sysname RT1
#
system-working-mode standard
xbar load-single
password-recovery enable
lpu-type f-series
#
vlan 1
#
interface Serial1/0
ip address 114.20.17.18 255.255.255.0
nat outbound 3010
ipsec apply policy rt1
#
interface Serial2/0
#
interface Serial3/0
#
interface Serial4/0
#
interface NULL0
#
interface GigabitEthernet0/0
port link-mode route
combo enable copper
ip address 192.168.40.254 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
combo enable copper
#
interface GigabitEthernet0/2
port link-mode route
combo enable copper
#
interface GigabitEthernet5/0
port link-mode route
combo enable copper
#
interface GigabitEthernet5/1
port link-mode route
combo enable copper
#
interface GigabitEthernet6/0
port link-mode route
combo enable copper
#
interface GigabitEthernet6/1
port link-mode route
combo enable copper
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
user-role network-admin
#
line class tty
user-role network-operator
#
line class vty
user-role network-operator
#
line aux 0
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 63
user-role network-operator
#
ip route-static 0.0.0.0 0 114.20.17.19
ip route-static 172.16.40.0 24 114.20.17.19
#
acl basic 2000
rule 0 permit
#
acl advanced 3000
rule 5 permit ip source 192.168.40.0 0.0.0.255 destination 172.16.40.0 0.0.0.255
#
acl advanced 3010
rule 5 deny ip source 192.168.40.0 0.0.0.255 destination 172.16.40.0 0.0.0.255
rule 100 permit ip
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
ipsec transform-set rt1
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
#
ipsec policy rt1 1 isakmp
transform-set rt1
security acl 3000
local-address 114.20.17.18
remote-address 78.30.21.21
ike-profile ike1
#
ike profile ike1
keychain key1
match remote identity address 78.30.21.21 255.255.255.255
proposal 1111
#
ike proposal 1111
#
ike keychain key1
pre-shared-key address 78.30.21.21 255.255.255.255 key cipher $c$3$kPj80yy9UVgBee7hQaXB2Nn4BiSgAwpEoA==
#
return
[RT1]