Cisco ASA Iikev1

crypto ipsec ikev1 transform-set bjidc esp-des esp-md5-hmac        w

 

crypto ipsec security-association pmtu-aging infinite
crypto dynamic-map dyn1 1 set ikev1 transform-set ccc
crypto dynamic-map dyn1 1 set reverse-route
crypto dynamic-map lpmap 10 set ikev1 transform-set lpset
crypto dynamic-map lpmap 10 set reverse-route
crypto map mymap 1 ipsec-isakmp dynamic dyn1
crypto map lpmap 10 ipsec-isakmp dynamic lpmap
crypto map lpmap interface outside

 

crypto ikev1 enable outside

 

crypto ikev1 policy 1
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 43200
crypto ikev1 policy 10
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 86400

group-policy aaa internal
group-policy aaa attributes
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value vpn
 address-pools value ciscovpn
group-policy lp-policy internal
group-policy lp-policy attributes
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value Split

 

 
tunnel-group vpn type remote-access
tunnel-group vpn general-attributes
 address-pool ciscovpn-----------
 authentication-server-group aaa
tunnel-group vpn ipsec-attributes
 ikev1 pre-shared-key *****

------------------------------------------------------
tunnel-group lpgroup type remote-access
tunnel-group lpgroup ipsec-attributes
 ikev1 pre-shared-key *****

 

posted @   博雅塔之客  阅读(149)  评论(0编辑  收藏  举报
相关博文:
阅读排行:
· Manus爆火,是硬核还是营销?
· 终于写完轮子一部分:tcp代理 了,记录一下
· 震惊!C++程序真的从main开始吗?99%的程序员都答错了
· 别再用vector<bool>了!Google高级工程师:这可能是STL最大的设计失误
· 单元测试从入门到精通
点击右上角即可分享
微信分享提示