Вы находитесь на странице: 1из 3

PC-A (192.168.1.3 255.255.255.0 192.168.1.

1)
PC-C (192.168.3.3 255.255.255.0 192.168.3.1)

R1
ena
conf t
host R1
int g0/1
ip add 192.168.1.1 255.255.255.0
no shut
ex
int s0/0/0
ex
no ip domain-lookup
int s0/0/0
clock rate 64000
ip add 10.1.1.1 255.255.255.252
no shut
ex
router ospf 101
network 192.168.1.0 0.0.0.255 area 0
network 10.1.1.0 0.0.0.3 area 0
ex
security passwords min-length 10
ip domain-name ccnasecurity.com
crypto key generate rsa
1024
username admin01 algorithm-type scrypt secret admin01pass
do wr
license boot module c1900 technology-package securityk9
do wr
reload
ena
conf t
crypto isakmp enable
crypto isakmp policy 10
?
crypto isakmp policy 10
hash sha
authentication pre-share
group 1
lifetime 3600
encryption aes 256
end
show crypto isakmp policy
conf t
crypto isakmp key cisco123 address 10.2.2.1
crypto ipsec transform-set 50 esp-aes 256 esp-sha-hmac
exit
conf t
crypto ipsec security-association lifetime seconds 1800
access-list 101 permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
crypto map CMAP 10 ipsec-isakmp
match address 101
set peer 10.2.2.1
set pfs group1
set transform-set 50
set security-association lifetime seconds 900
exit
interface S0/0/0
crypto map CMAP
end
conf t

R2
conf t
host R2
no ip domain-lookup
int s0/0/0
ip add 10.1.1.2 255.255.255.252
no shut
ex
int s0/0/1
no clock rate 64000
no ip add 10.2.2.2 255.255.255.252
no shut
ex
router ospf 101
network 10.1.1.0 0.0.0.3 area 0
network 10.2.2.0 0.0.0.3 area 0
ex
do
wr
license boot module c1900 technology-package securityk9
y
reload

R3
ena
conf t
no ip domain-lookup
host R3
int g0/1
ip add 192.168.3.1 255.255.255.0
no shut
int s0/0/1
ip add 10.2.2.1 255.255.255.252
no shut
ex
router ospf 101
network 192.168.3.0 0.0.0.255 area 0
network 10.2.2.0 0.0.0.3 area 0
ex
security passwords min-length 10
ip domain-name ccnasecurity.com
crypto key generate rsa
1024
username admin01 algorithm-type scrypt secret admin01pass
do wr
license boot module c1900 technology-package securityk9
do wr
do reload
ena
conf t
crypto isakmp enable
crypto isakmp policy 10
hash sha
authentication pre-share
group 1
lifetime 3600
encryption aes 256
end
conf t
crypto isakmp key cisco123 address 10.1.1.1
crypto ipsec transform-set 50 esp-aes 256 esp-sha-hmac
exit
conf t
crypto ipsec security-association lifetime seconds 1800
access-list 101 permit ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
crypto map CMAP 10 ipsec-isakmp
match address 101
set peer 10.1.1.1
set pfs group1
set transform-set 50
set security-association lifetime seconds 900
exit
interface S0/0/1
crypto map CMAP
end
conf t

Вам также может понравиться