GRE Over IPsec
GRE Over IPsec
u
u
R3的公网接口为f0/1.
Tunnel模式
u
crypto isakmp policy 10 crypto
isakmp key cisco address 3.3.3.3 255.255.255.0 crypto isakmp key cisco address 23.23.23.2 255.255.255.0 ! crypto ipsec transform-set VPNSET esp-3des esp-md5-hmac ! crypto map VPNMAP 10 ipsec-isakmp ! interface Loopback0 ! interface Loopback100 ! interface Tunnel0 ! interface FastEthernet0/0 crypto map
VPNMAP ! router eigrp 100 ! ip route 0.0.0.0 0.0.0.0 12.12.12.2 ! ip access-list extended VPN |
u
u
当172.16.1.1 ping 172.16.2.1时,首先查找路由表,现下一跳路由是192.168.1.2,本地的出口为Tunnel0口。Tunnel口用GRE封装,源为IP为12.12.12.1,目的IP为23.23.23.2。再查找23.23.23.2的路由,发现出口为f0/0,把数据包由f0/0发出。由于f0/0加密了,所以再次封装ESP。在由物理口查找路由,源为12.12.12.1,目的为23.23.23.2,从f0/0出去。 封装格式tunnel模式: |
Transparent模式
R1配置,该方法配置可以配置两种模式
crypto isakmp policy 10 crypto isakmp key cisco address 3.3.3.3 255.255.255.0 crypto isakmp key cisco address 23.23.23.2 255.255.255.0 ! crypto ipsec transform-set VPNSET esp-3des esp-md5-hmac ! crypto
ipsec profile GREPRO ! interface Loopback0 ! interface Loopback100 ! interface Tunnel0 ! interface FastEthernet0/0 ! router eigrp 100 ! ip route 0.0.0.0 0.0.0.0 12.12.12.2 ! |
u
Transparent模式 |