配置手工方式的Tunnel
[R1]acl 3000
[R1-acl-3000]rule permit ip source 192.168.100.1 0.0.0.255 destination 192.168.200.2 0.0.0.255
[R1-acl-3000]rule deny ip source any destination any
[R1-acl-3000]quit
//创建访问规则
[R1]ipsec proposal trans1
[R1-ipsec-proposal-trans1]encapsulation-mode tunnel
[R1-ipsec-proposal-trans1]transform esp-new
[R1-ipsec-proposal-trans1]esp-new authentication md5-hmac-96
[R1-ipsec-proposal-trans1]esp-new encryption-algorithm des
[R1-ipsec-proposal-trans1]quit
//创建提议,以及对提议的加密、认证方式
[R1]ipsec policy p1 100 manual
[R1-ipsec-policy-p1-100]security acl 3000
[R1-ipsec-policy-p1-100]proposal trans1
[R1-ipsec-policy-p1-100]tunnel local 192.168.13.1
[R1-ipsec-policy-p1-100]tunnel remote 192.168.23.2
[R1-ipsec-policy-p1-100]sa inbound esp spi 123456
[R1-ipsec-policy-p1-100]sa inbound esp string-key asdf
[R1-ipsec-policy-p1-100]sa outbound esp spi 654321
[R1-ipsec-policy-p1-100]sa outbound esp string-key fdsa
[R1-ipsec-policy-pl -100]quit
//创建策略,包含上述提议,该策略将应用于Tunnel中,需要注意的是Tunnel两端的路由器策略配置,R1中的tunnel local地址是R2的tunnel remote, inbound是R2的outbound。
[R1]interface e0/0
[R1-Ethernet0/0]ipsec policy p1
//在出口上应用策略
[R2]acl 3001
[R2-acl-3001]rule permit ip source 192.168.200.2 0.0.0.255 destination 192.168.100.1 0.0.0.255
[R2-acl-3001]rule deny ip source any destination any
[R2-acl-3001]quit
//创建访问规则
[R2]ipsec proposal trans2
[R2-ipsec-proposal-trans2]encapsulation-mode tunnel
[R2-ipsec-proposal-trans2]transform esp-new
[R2-ipsec-proposal-trans2]esp-new authentication md5-hmac-96
[R2-ipsec-proposal-trans2]esp-new encryption-algorithm des
[R2-ipsec-proposal-trans2]quit
//创建提议,以及对提议的加密、认证方式
[R2]ipsec policy p2 200 manual
[R2-ipsec-policy-p2-200]security acl 3001
[R2-ipsec-policy-p2-200]proposal trans2
[R2-ipsec-policy-p2-200]tunnel local 192.168.23.2
[R2-ipsec-policy-p2-200]tunnel remote 192.168.13.1
[R2-ipsec-policy-p2-200]sa inbound esp spi 654321
[R2-ipsec-policy-p2-200]sa inbound esp string-key fdsa
[R2-ipsec-policy-p2-200]sa outbound esp spi 123456
[R2-ipsec-policy-p2-200]sa outbound esp string-key asdf
[R2-ipsec-policy-p2-200]quit
[R2]interface e0/0
[R2-Ethernet0/0]ipsec policy p2