Cisco ASA Iikev1

crypto ipsec ikev1 transform-set bjidc esp-des esp-md5-hmac        w

 

crypto ipsec security-association pmtu-aging infinite
crypto dynamic-map dyn1 1 set ikev1 transform-set ccc
crypto dynamic-map dyn1 1 set reverse-route
crypto dynamic-map lpmap 10 set ikev1 transform-set lpset
crypto dynamic-map lpmap 10 set reverse-route
crypto map mymap 1 ipsec-isakmp dynamic dyn1
crypto map lpmap 10 ipsec-isakmp dynamic lpmap
crypto map lpmap interface outside

 

crypto ikev1 enable outside

 

crypto ikev1 policy 1
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 43200
crypto ikev1 policy 10
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 86400

group-policy aaa internal
group-policy aaa attributes
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value vpn
 address-pools value ciscovpn
group-policy lp-policy internal
group-policy lp-policy attributes
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value Split

 

 
tunnel-group vpn type remote-access
tunnel-group vpn general-attributes
 address-pool ciscovpn-----------
 authentication-server-group aaa
tunnel-group vpn ipsec-attributes
 ikev1 pre-shared-key *****

------------------------------------------------------
tunnel-group lpgroup type remote-access
tunnel-group lpgroup ipsec-attributes
 ikev1 pre-shared-key *****

 

posted @ 2022-07-11 14:32  博雅塔之客  阅读(138)  评论(0编辑  收藏  举报