quit
!
crypto isakmp policy 1
authentication rsa-encr
no crypto isakmp ccm
!
!
crypto ipsec transform-set vpnn esp-3des esp-sha-hmac
!
crypto map vpn-map 10 ipsec-isakmp
set peer 10.1.1.2
set transform-set vpnn
match address 100
!
!
!
!
interface Loopback0
ip address 172.25.2.1 255.255.255.0
!
interface FastEthernet0/0
ip address 10.1.1.1 255.255.255.0
speed 100
full-duplex
crypto map vpn-map
ip route 0.0.0.0 0.0.0.0 10.1.1.2
!
!
!
access-list 100 permit ip 172.25.2.0 0.0.0.255 172.25.1.0 0.0.0.255
-----------------------------------------------------------------------
r4#sh cry ips sa
interface: FastEthernet0/0
Crypto map tag: vpn-map, local addr 10.1.1.1
protected vrf: (none)
local ident (addr/mask/prot/port): (172.25.2.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (172.25.1.0/255.255.255.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 11, #pkts encrypt: 11, #pkts digest: 11
#pkts decaps: 11, #pkts decrypt: 11, #pkts verify: 11
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0
#pkts not decompressed: 0, #pkts decompress failed: 0
#send errors 10, #recv errors 0
local crypto endpt.: 10.1.1.1, remote crypto endpt.: 10.1.1.2
path mtu 1500, ip mtu 1500
current outbound spi: 0x45397004(1161392132)
inbound esp sas:
spi: 0x58964BA2(1486244770)
transform: esp-3des esp-sha-hmac ,
in use settings ={Tunnel, }
conn id: 2002, flow_id: SW:2, crypto map: vpn-map
sa timing: remaining key lifetime (k/sec): (4605507/3384)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0x45397004(1161392132)
transform: esp-3des esp-sha-hmac ,
in use settings ={Tunnel, }
conn id: 2001, flow_id: SW:1, crypto map: vpn-map
sa timing: remaining key lifetime (k/sec): (4605507/3382)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
outbound ah sas:
outbound pcp sas:
r4#
------------------------------------------------------------------------------
r4#
r4#
r4#sh cry key my rsa
% Key pair was generated at: 17:52:13 beijing Mar 1 2002
Key name: r4.r4.com
Usage: General Purpose Key
Key is not exportable.
Key Data:
305C300D 06092A86 4886F70D 01010105 00034B00 30480241 00C3167F C00AA729
4D772DC8 017CACE2 A4A524D8 CEA19ED5 53DE98C2 092B75FE 2437ABE0 86B5577F
B5CF417E 5736A996 1320328E ADF1E0C2 F77AF269 DD263B90 23020301 0001
% Key pair was generated at: 17:52:14 beijing Mar 1 2002
Key name: r4.r4.com.server
Usage: Encryption Key
Key is not exportable.
Key Data:
307C300D 06092A86 4886F70D 01010105 00036B00 30680261 00B7718B 6D20FBFD
5A1E30A8 434D4ACE C746ABDE 7E542FC5 55479D7F 10A60446 E96B67E2 A641849A
F6501D93 83BDDF75 263EF818 AEA12D6E 020BC67B 089F29EF E385C1D1 639F17CE
B23BE340 6EA3DFBF A0C5CD96 FA01CB50 ECDEEB2E 985807A6 C7020301 0001
文章整理:西部数码--专业提供域名注册、虚拟主机服务
http://www.west263.com
以上信息与文章正文是不可分割的一部分,如果您要转载本文章,请保留以上信息,谢谢!




