设为首页收藏本站language→→ 语言切换

鸿鹄论坛

 找回密码
 论坛注册

QQ登录

先注册再绑定QQ

查看: 1730|回复: 2
收起左侧

IPSec 在 跨网段时有没有需要特别的配置为何我的配置不通

[复制链接]
发表于 2013-1-9 10:18:47 | 显示全部楼层 |阅读模式
捕获.PNG
使用的鼎杰的模拟器   
RT2 与 rt3 中间跑IPSec  r1 和 r4 的e0/1/0 模拟内网   
使用内外地址ping  网络中除了对端内网的所有地址都没有问题
所有的ip 都是 启动的rip v2 协议  
为何 内外互相ping 不通啊    各位大神求解啊



r3的配置

version 5.20, Alpha 1011
#
sysname wai
#
password-control login-attempt 3 exceed lock-time 120
#
undo voice vlan mac-address 00e0-bb00-0000
#
ipsec cpu-backup enable
#
undo cryptoengine enable
#
domain default enable system
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
ike proposal 10
#
ike peer wode
pre-shared-key cipher XgybmeVxnUk=
remote-address 1.1.34.3
#
ipsec proposal nide
esp authentication-algorithm sha1
#
ipsec policy tade 10 isakmp
security acl 3003
ike-peer wode
proposal nide
#
interface Ethernet0/1/0
port link-mode route
#
interface Serial0/2/0
link-protocol ppp
ip address 1.1.34.4 255.255.255.0
#
interface Serial0/2/1
link-protocol ppp
#               
interface Serial0/2/2
link-protocol ppp
ip address 1.1.45.4 255.255.255.0
#
interface Serial0/2/3
link-protocol ppp
#
interface NULL0
#
interface Ethernet0/4/0
port link-mode bridge
#
interface Ethernet0/4/1
port link-mode bridge
#
interface Ethernet0/4/2
port link-mode bridge
#
interface Ethernet0/4/3
port link-mode bridge
#
interface Ethernet0/4/4
port link-mode bridge
#
interface Ethernet0/4/5
port link-mode bridge
#
interface Ethernet0/4/6
port link-mode bridge
#
interface Ethernet0/4/7
port link-mode bridge
#
interface Tunnel1
ip address 1.1.1.2 255.255.255.0
source 1.1.34.4
destination 1.1.34.3
keepalive 10 3
#
rip 1
undo summary
version 2
network 1.0.0.0
#
ip route-static 10.2.2.0 255.255.255.0 Tunnel1 preference 55
#               
load xml-configuration
#
user-interface con 0
user-interface vty 0 4
#
return

r2 的配置


version 5.20, Alpha 1011
#
sysname wqi
#
password-control login-attempt 3 exceed lock-time 120
#
undo voice vlan mac-address 00e0-bb00-0000
#
ipsec cpu-backup enable
#
undo cryptoengine enable
#
domain default enable system
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
ike proposal 10
#
ike peer wode
pre-shared-key cipher XgybmeVxnUk=
remote-address 1.1.34.4
#
ipsec proposal nide
esp authentication-algorithm sha1
#
ipsec policy tade 10 isakmp
security acl 3003
ike-peer wode
proposal nide
#
acl number 3003
rule 0 permit ip source 10.1.1.0 0.0.0.255 destination 10.2.2.0 0.0.0.255
#
interface Ethernet0/1/0
port link-mode route
#
interface Serial0/2/0
link-protocol ppp
ip address 1.1.23.3 255.255.255.0
#               
interface Serial0/2/1
link-protocol ppp
#
interface Serial0/2/2
link-protocol ppp
ip address 1.1.34.3 255.255.255.0
#
interface NULL0
#
interface Ethernet0/4/0
port link-mode bridge
#
interface Ethernet0/4/1
port link-mode bridge
#
interface Ethernet0/4/2
port link-mode bridge
#
interface Ethernet0/4/3
port link-mode bridge
#
interface Ethernet0/4/4
port link-mode bridge
#
interface Ethernet0/4/5
port link-mode bridge
#
interface Ethernet0/4/6
port link-mode bridge
#
interface Ethernet0/4/7
port link-mode bridge
#
interface Tunnel1
ip address 1.1.1.1 255.255.255.0
source 1.1.34.3
destination 1.1.34.4
keepalive 10 3
#
rip 1
undo summary
version 2
network 1.0.0.0
#
ip route-static 10.1.1.0 255.255.255.0 Tunnel1
#               
load xml-configuration
#
user-interface con 0
user-interface vty 0 4



                               
登录/注册后可看大图
该贴已经同步到 zpiaomiao的微博
发表于 2013-1-9 10:42:31 | 显示全部楼层
R3上没有ACL看到,另外你IPsec没调用接口

你想实现的是gre over ipsec,那么你感兴趣流量就不因该这么定义 因该定义接口的gre地址,你这样只能实现L2L的,调用到接口 可以ping通了
沙发 2013-1-9 10:42:31 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-1-9 10:43:35 | 显示全部楼层
不错不错,支持顶个
板凳 2013-1-9 10:43:35 回复 收起回复
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-1-24 18:04 , Processed in 0.058848 second(s), 12 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表