linux初探

首页

应用服务器

Linux技巧

中文文档

Linux初级

服务器源代码

命令详解

Linux技术应用

Linux安全应用

Linux业界新闻

UniX技术文章

Linux编程与内核

Linux数据库

Linux服务器

Linux安装指导

Linux论坛

首页>>Linux安全应用>>文章正文

两个点的VPN配置实例


一个两个点的VPN配置,Router Cisco 2610XM.
  
  version 12.2
  service timestamps debug datetime localtime
  service timestamps log datetime localtime
  no service password-encryption
  !
  hostname Router
  !
  no logging buffered
  enable secret 5 $1$gxXJ$xJJKhbeYZS4PTDrZNG8nJ0
  !
  ip subnet-zero
  !
  !
  no ip domain-lookup
  !
  ip audit notify log
  ip audit po max-events 100
  !
  crypto isakmp policy 1
  encr 3des
  hash md5
  authentication pre-share
  group 2
  crypto isakmp key kc#14C11320/yhm-guiyang address 202.232.88.132
  crypto isakmp key kc#14C11320/beijing-guiyang address 218.247.171.165
  crypto isakmp keepalive 10
  !
  !
  crypto ipsec transform-set RTPSET esp-3des esp-md5-hmac
  !
  crypto map RTP 10 ipsec-isakmp
  set peer 202.232.88.132
  set transform-set RTPSET
  match address 100
  crypto map RTP 20 ipsec-isakmp
  set peer 218.247.171.165
  set transform-set RTPSET
  match address 102
  !
   fax interface-type fax-mail
  mta receive maximum-recipients 0
  !
  !
  !
  interface FastEthernet0/0
  ip address xxx.xxx.46.2 255.255.255.224
  ip access-group 101 in
  ip nat outside
  duplex auto
  speed auto
  crypto map RTP
  !
  interface FastEthernet0/1
  ip address 10.78.10.1 255.255.248.0 secondary
  ip address 10.78.9.1 255.255.248.0
  ip nat inside
  duplex auto
  speed auto
  !
  ip nat pool internet 61.243.46.3 61.243.46.3 netmask 255.255.255.224
  ip nat inside source route-map nonat pool internet overload
  ip classless
  ip route 0.0.0.0 0.0.0.0 FastEthernet0/0
  no ip http server
  ip pim bidir-enable
  !
  !
  logging trap debugging
  access-list 10 permit any
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.18.0.0 0.0.255.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.11.8.0 0.0.7.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.11.72.0 0.0.7.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.13.16.0 0.0.7.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.32.8.0 0.0.7.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.32.16.0 0.0.7.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.32.40.0 0.0.7.255
  access-list 100 permit ip 10.78.0.0 0.0.255.255 10.33.16.0 0.0.7.255
  access-list 101 deny 53 any any
  access-list 101 deny 55 any any
  access-list 101 deny 77 any any
  access-list 101 deny pim any any
  access-list 101 permit udp 10.18.100.0 0.0.0.255 any eq snmp
  access-list 101 deny udp any any eq snmp
  access-list 101 permit tcp 10.0.0.0 0.255.255.255 any eq telnet
  access-list 101 permit tcp 202.232.88.128 0.0.0.63 any eq telnet
  access-list 101 deny tcp any any eq telnet
  access-list 101 permit ip any any
  access-list 101 permit esp any any
  access-list 102 permit ip 10.78.0.0 0.0.255.255 10.79.8.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.18.0.0 0.0.255.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.11.8.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.11.72.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.13.16.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.32.8.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.32.16.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.32.40.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.33.16.0 0.0.7.255
  access-list 110 deny ip 10.78.0.0 0.0.255.255 10.79.8.0 0.0.7.255
  access-list 110 permit ip 10.78.0.0 0.0.255.255 any
  !
  route-map nonat permit 10
  match ip address 110
  !
  snmp-server community public RO
  call rsvp-sync
  !
  !
  mgcp profile default
  !
  mgcp profile defaullogin
  !
  dial-peer cor custom
  !
  !
  !
  !
  banner motd C
  S/N:JMX0636L32C
  
  !
  line con 0
  line aux 0
  password
  login
  modem InOut
  modem autoconfigure type default
  transport input all
  stopbits 1
  speed 115200
  flowcontrol hardware
  line vty 0 4
  password
  login
  !
  !
  end
原文出处:http://blog.chinaunix.net/u/5591/showart_243878.html
Linux联盟收集整理

相关文章

·Ubuntu Linux:Bind双重域名配置
·Sendmail配置终极指南
·通过监控Linux下进程来保证系统安全
·tar.gz文件的安装
·架设基于Linux(2.6.14内核)的服务器集群
·怎样保护Linux系统下的Apache网站
·巧妙运用前后台任务让Linux系统加速
·用OpenVPN构建安全VPN
·OpenVPN使用User/Pass验证登录

热门文章

·利用135端口漏洞入侵个人电脑
·网吧频繁掉线(ARP)与解决方
·新手学堂:防火墙在网络中的
·害怕受网络攻击 英国公民干脆
·知己知彼:IEXPLORE命令行参
·保护个人隐私 隐藏在图片背后
·顶尖网络高手写的alexa作弊完
·国庆期间有45万余台计算机感
·病毒门诊:清除猖狂的Sxs.ex
·电脑用户须知 忘记分级审查密

Copyright@2005 www.linuxGoo.com All Right Reserved