Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Crypt traffic between Host1 and Host2
- [Host1]-----------------[R1]---{R2_Cloud}---[R3]-----------------[Host2]
- 192.168.1.100 - 192.168.1.1 [] === crypted === [] 192.168.2.1 - 192.168.2.100
- 192.168.1.0/24 10.0.0.0/30[]10.0.0.4/30 192.168.2.0/24
- hostname Host1
- interface FastEthernet0/0
- ip address 192.168.1.100 255.255.255.0
- no shut
- line con 0
- exec-timeout 0 0
- ip route 0.0.0.0 0.0.0.0 192.168.1.1
- hostname Host2
- interface FastEthernet0/0
- ip address 192.168.2.100 255.255.255.0
- no shut
- line con 0
- exec-timeout 0 0
- ip route 0.0.0.0 0.0.0.0 192.168.2.1
- hostname R1
- policy-map shaper
- class class-default
- shape average 2000000
- interface FastEthernet0/0
- no shut
- description LAN
- ip address 192.168.1.1 255.255.255.0
- load-interval 30
- duplex auto
- speed auto
- interface FastEthernet0/1
- no shut
- description WAN
- ip address 10.0.0.2 255.255.255.252
- load-interval 30
- duplex auto
- speed auto
- service-policy output shaper
- line con 0
- exec-timeout 0 0
- ip route 0.0.0.0 0.0.0.0 FastEthernet0/1 10.0.0.1
- hostname R2
- policy-map shaper
- class class-default
- shape average 2000000
- interface FastEthernet0/0
- no shut
- description WAN_1
- ip address 10.0.0.1 255.255.255.252
- load-interval 30
- duplex auto
- speed auto
- interface FastEthernet0/1
- no shut
- description WAN_2
- ip address 10.0.0.5 255.255.255.252
- load-interval 30
- duplex auto
- speed auto
- service-policy output shaper
- line con 0
- exec-timeout 0 0
- ip route 192.168.1.0 255.255.255.0 FastEthernet0/0 10.0.0.2
- ip route 192.168.2.0 255.255.255.0 FastEthernet0/0 10.0.0.6
- hostname R3
- policy-map shaper
- class class-default
- shape average 2000000
- interface FastEthernet0/0
- no shut
- description LAN
- ip address 192.168.2.1 255.255.255.0
- load-interval 30
- duplex auto
- speed auto
- interface FastEthernet0/1
- no shut
- description WAN
- ip address 10.0.0.6 255.255.255.252
- load-interval 30
- duplex auto
- speed auto
- service-policy output shaper
- line con 0
- exec-timeout 0 0
- ip route 0.0.0.0 0.0.0.0 FastEthernet0/1 10.0.0.5
- Crypto config:
- !R1
- crypto isakmp policy 1
- authentication pre-share
- encr 3des
- group 2
- !
- crypto isakmp key 0 CISCO address 10.0.0.6
- !
- crypto isakmp invalid-spi-recovery
- crypto isakmp keepalive 30 10 periodic
- !
- crypto ipsec transform-set MyTransSet esp-3des esp-sha-hmac
- mode transport
- crypto ipsec profile MyProfile
- set transform-set MyTransSet
- !
- access-list 101 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
- !
- crypto map MyMap 10 ipsec-isakmp
- set peer 10.0.0.6
- set transform-set MyTransSet
- match address 101
- !
- interface FastEthernet0/1
- crypto map MyMap
- !R3
- crypto isakmp policy 1
- authentication pre-share
- encr 3des
- group 2
- !
- crypto isakmp key 0 CISCO address 10.0.0.2
- !
- crypto isakmp invalid-spi-recovery
- crypto isakmp keepalive 30 10 periodic
- !
- crypto ipsec transform-set MyTransSet esp-3des esp-sha-hmac
- mode transport
- crypto ipsec profile MyProfile
- set transform-set MyTransSet
- !
- access-list 101 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
- !
- crypto map MyMap 10 ipsec-isakmp
- set peer 10.0.0.2
- set transform-set MyTransSet
- match address 101
- !
- interface FastEthernet0/1
- crypto map MyMap
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement