²©¿Íͳ¼ÆÐÅÏ¢

51ctoÍÆ¼ö²©¿Í
Óû§Ãû£ºqÀǵÄÓÕ»ó
ÎÄÕÂÊý£º103
ÆÀÂÛÊý£º131
·ÃÎÊÁ¿£º102194
ÎÞÓDZңº1501
²©¿Í»ý·Ö£º2012
²©¿ÍµÈ¼¶£º6
×¢²áÈÕÆÚ£º2010-04-21

 

ÒªÇó£º
1.ÒªÇóʹÓÃÖ¤ÊéÑéÖ¤
2.site-to-site vpnʹÓÃSCEPÖ¤ÊéÉêÇ뷽ʽ
3.remote-vpnʹÓÃpkcs10Ö¤ÊéÉêÇ뷽ʽ
ǰÌ᣺
1.ÔÚvpn»·¾³ÖÐʵÏÖÖ¤ÊéµÄÑéÖ¤£¬±ØÐëÒªÇóʱ¼äͬ²½£¡CA·þÎñÆ÷¿ªÆôhttp server
2.ʹÓÃFTP×öΪCAÖ¤ÊéµÄ´æ·ÅµØµã£¬·ÀÖ¹´óÁ¿Ö¤ÊéÕ¼ÓÃNV
3.CAÓиöFTPÕ˺űØÐë¿ÉдµÄȨÏÞ
´î½¨£º
ÎÒÊÇʹÓÃserver U´î½¨µÄFTP·þÎñÆ÷£¬ÄÚ½¨Ò»¸öusername cisco password cisco¿ÉдµÄȨÏÞÕ˺š£
´î½¨CA
clock timezone GMT 8

clock set

ntp mster

ip domain name laoliang.com

 crypto pki server ca

 database level complete                     

 database url ftp://202.1.100.24   Ö¤Êé´æ·ÅµÄµØµã

 database username cisco password 7 094F471A1A0A   Ò»¸ö¶ÔFTP¿ÉдµÄÕ˺Å

 database archive pem                  Ñ¹Ëõ·½Ê½

 issuer-name cn=laoliang  o=nongda i=zhengzhou    CAµÄÕË»§ÐÅÏ¢

 cdp-url ftp://202.1.100.24           µõÏúÁбí

no sh
ca#SHOW crypto pki certificates              ¸ùÖ¤Êé

CA Certificate

  Status: Available

  Certificate Serial Number: 01

  Certificate Usage: Signature

  Issuer:

    cn=laoliang o\=nongda i\=zhengzhou

  Subject:

    cn=laoliang o\=nongda i\=zhengzhou

  Validity Date:

    start date: 21:09:09 GMT May 17 2011

    end   date: 21:09:09 GMT May 16 2014

  Associated Trustpoints: ca
R3´î½¨£º

crypto key generate rsa usage-keys
crypto pki trustpoint ca           ¶¨ÒåÔ¶³ÌCA

 enrollment url http://202.1.100.20:80

 serial-number

 ip-address 202.1.100.30

 subject-name cn=r3 o=nongda i=zhengzhou

 revocation-check crl none
crypto pki authen ca           »ñÈ¡CAµÄ¹«Ô¿ 
crypto pki enroll ca          °Ñ¸öÈËÐÅÏ¢¼°Æä×Ô¼ºµÄ¹«Ô¿Ìá½»¸øCA
CA:µ±r3Ìá½»ÐÅÏ¢ºó²é¿´CAµÄÇëÇó
ca#crypto pki server ca info requests

Enrollment Request Database:
Subordinate CA certificate requests:

ReqID  State      Fingerprint                      SubjectName

--------------------------------------------------------------
RA certificate requests:

ReqID  State      Fingerprint                      SubjectName

--------------------------------------------------------------
Router certificates requests:

ReqID  State      Fingerprint                      SubjectName

--------------------------------------------------------------

2      pending    A5892D5B4CDC72DF67F212A225B73D11 ipaddress=202.1.100.30+hostname=r3.laoliang.com,cn=r3 o\=nongda i\=zhengzhou

1      pending    5EB2C274199A03844B6DE6F3A2330E57 ipaddress=202.1.100.30+hostname=r3.laoliang.com,cn=r3 o\=nongda i\=zhengzhou
ca#crypto pki server ca gr    °ä·¢Ö¤Ê鏸R3

ca#crypto pki server ca grant 1

Writing 2.crt !

Writing 2.cnm !

Writing ca.ser !

ca#crypto pki server ca grant 2

Writing 3.crt !

Writing 3.cnm !

Writing ca.ser !
R4ͬÀí
ÕâÊÇÎÒÃÇÔÚFTP·þÎñÆ÷¿´ÏÂÖ¤Êé
ÕâÀï×¢ÒâÒ»µã£ºcrypto key generate rsa usage-keys ²úÉú2¶ÔÃÜÔ¿Ò»·ÝÓÃÓÚÇ©ÃûÒ»·ÝÓÃÓÚ¼ÓÃÜ£¬
r4(config)#crypto key generate rsa ?

  general-keys  Generate a general purpose RSA key pair for signing and

                encryption

  usage-keys    Generate separate RSA key pairs for signing and encryption

  <cr>
 

ÅäÖúúóR4µÄshow runÐÅÏ¢
r4#show run

Building configuration...
Current configuration : 5306 bytes

 Last configuration change at 14:29:08 UTC Tue May 17 2011

version 12.4

service timestamps debug datetime msec

service timestamps log datetime msec

no service password-encryption

hostname r4

boot-start-marker

boot-end-marker

no aaa new-model

memory-size iomem 5

ip cef

no ip domain lookup

ip domain name laoliang.com

crypto pki trustpoint ca

 enrollment url http://202.1.100.20:80

 serial-number

 subject-name cn=r4 ou=nongda i=zhengzhou

 revocation-check crl none

crypto pki certificate chain ca

 certificate 05

  30820212 3082017B A0030201 02020105 300D0609 2A864886 F70D0101 04050030

  29312730 25060355 0403131E 6C616F6C 69616E67 20206F3D 6E6F6E67 64612069

  3D7A6865 6E677A68 6F75301E 170D3131 30353137 31333138 34305A17 0D313230

  35313631 33313834 305A3043 3121301F 06035504 03131872 34206F75 3D6E6F6E

  67646120 693D7A68 656E677A 686F7531 1E301C06 092A8648 86F70D01 0902160F

  72342E6C 616F6C69 616E672E 636F6D30 5C300D06 092A8648 86F70D01 01010500

  034B0030 48024100 C3A11EC2 DFB7A349 F8E09D68 28E57490 7A6883DD EB434574

  520C366B 09AB41D7 F1BE7363 52F88593 85AB63E3 D1F66F6D 67205B20 F19454BA

  077885D6 A2D50E59 02030100 01A37430 72302306 03551D1F 041C301A 3018A016

  A0148612 6674703A 2F2F3230 322E312E 3130302E 3234300B 0603551D 0F040403

  02052030 1F060355 1D230418 30168014 366F45DC 405B228E EBE72399 C6893FFD

  13899A38 301D0603 551D0E04 16041457 35CF6AFD 0DA86962 CD7C8A34 7D287E79

  ADDF4E30 0D06092A 864886F7 0D010104 05000381 810062A2 EDBF3263 76B0E6BF

  B63B8FE6 5F04556D 23691944 EBB8641E A5A02892 0C31B336 EF7B0A6F FFC92430

  F16F71DB 1DE49F83 C34EA5C5 4E425C62 1D12BAD8 A4CF9198 EC84F72E FC15D2B8

  FD7B4FBA B9A3BEF3 F3A7A237 D9DEA9FB C2FFD5F1 24827EB8 2180F9C9 923E07C2

  6CC34DE2 0B1DD9F1 9EE63306 2825D038 00909D74 56E7

  quit

 certificate 04

  30820212 3082017B A0030201 02020104 300D0609 2A864886 F70D0101 04050030

  29312730 25060355 0403131E 6C616F6C 69616E67 20206F3D 6E6F6E67 64612069

  3D7A6865 6E677A68 6F75301E 170D3131 30353137 31333138 33355A17 0D313230

  35313631 33313833 355A3043 3121301F 06035504 03131872 34206F75 3D6E6F6E

  67646120 693D7A68 656E677A 686F7531 1E301C06 092A8648 86F70D01 0902160F

  72342E6C 616F6C69 616E672E 636F6D30 5C300D06 092A8648 86F70D01 01010500

  034B0030 48024100 BCFAD0A9 191FAD30 2B1B51E8 260EFD40 39F68D68 11B78909

  B56ACC30 236988E3 E5E9B21E 0C3F904E C7A447E9 D683EB85 3E8DFA99 5CF9C41A

  22618115 0150B9F3 02030100 01A37430 72302306 03551D1F 041C301A 3018A016

  A0148612 6674703A 2F2F3230 322E312E 3130302E 3234300B 0603551D 0F040403

  02078030 1F060355 1D230418 30168014 366F45DC 405B228E EBE72399 C6893FFD

  13899A38 301D0603 551D0E04 16041445 0AA4084B 09BFAEC3 0272C638 C7DE747C

  A47B6930 0D06092A 864886F7 0D010104 05000381 8100922E 7289C55B 50716AA0

  0A165B75 4A38A293 9C8E3C75 AA2117CA 39C29EC3 2BD9AE62 38447BE7 9D65E4D5

  5DAD74C0 8D9F8F73 841883A7 57CEF4FB 5DD41093 B89EB20A 55F10C33 BB159D3F

  9DC9F5FB 8048E70A 9D885C03 0A1E306E 324B5F6B 52B46D5A E286192B 7EF9B89A

  45C9E51C 89071CD4 C68D694B 5977C001 9B868E22 3124

  quit

 certificate ca 01

  3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 04050030

  29312730 25060355 0403131E 6C616F6C 69616E67 20206F3D 6E6F6E67 64612069

  3D7A6865 6E677A68 6F75301E 170D3131 30353137 31333039 30395A17 0D313430

  35313631 33303930 395A3029 31273025 06035504 03131E6C 616F6C69 616E6720

  206F3D6E 6F6E6764 6120693D 7A68656E 677A686F 7530819F 300D0609 2A864886

  F70D0101 01050003 818D0030 81890281 8100BD5F 93A6D7F9 A53B2F54 CE3C2F03

  C40C158B BF43BB17 B5821732 57DAF284 9BB239F6 89349A84 C343EF58 B6D3A4E7

  894A2553 24DD2DE4 3CA5FEE4 6A6E73F3 CF10660F 07BF4130 E4912CC2 AFB3E9A8

  0F84C75D 35907E2F F3416EAE 9C5FB761 7EAA25C0 93A4EA00 592FB485 F15E0E62

  EB132B32 8173DB92 AC008FA9 11489414 07150203 010001A3 63306130 0F060355

  1D130101 FF040530 030101FF 300E0603 551D0F01 01FF0404 03020186 301F0603

  551D2304 18301680 14366F45 DC405B22 8EEBE723 99C6893F FD13899A 38301D06

  03551D0E 04160414 366F45DC 405B228E EBE72399 C6893FFD 13899A38 300D0609

  2A864886 F70D0101 04050003 81810053 18A811BB 0BDABF83 6D528194 B5E107DE

  EE518F07 C70E1FE6 DFE0FBA2 6E87BB91 4D56FC8A 7AFA91AD 275BF120 DAEBCE6B

  87A51EFD ECA0677E 8844F915 A499A8C3 71F7F9C6 CE3089DF 67221387 516D1B51

  35DA49D3 23E32858 06709738 8C753D33 D2C2CFFF 8E9B962C C0EBB1AA 96663F20

  8B442A05 2FBF5E2B 0E9F63DC 024590

  quit


crypto isakmp policy 10

crypto ipsec transform-set vpn esp-des esp-md5-hmac

crypto map mymap 65000 ipsec-isakmp

 set peer 202.1.100.30

 set transform-set vpn

 match address vpn

interface Loopback0

 ip address 4.4.4.4 255.255.255.255

interface Ethernet0/0

 ip address 202.1.100.40 255.255.255.0

 full-duplex

 crypto map mymap

ip http server

no ip http secure-server

ip route 3.3.3.3 255.255.255.255 202.1.100.30

ip access-list extended vpn

 permit ip host 4.4.4.4 host 3.3.3.3
ÔÚR3ÉÏ¿ªÆôdebug cry isa


r3#debug  cry isa

Crypto ISAKMP debugging is on

r3#ping 4.4.4.4 sou

r3#ping 4.4.4.4 source 3.3.3.3 re

r3#ping 4.4.4.4 source 3.3.3.3 repeat 100
Type escape sequence to abort.

Sending 100, 100-byte ICMP Echos to 4.4.4.4, timeout is 2 seconds:

Packet sent with a source address of 3.3.3.3
May 17 13:28:32.811: ISAKMP: received ke message (1/1)

May 17 13:28:32.815: ISAKMP:(0:0:N/A:0): SA request profile is (NULL)

May 17 13:28:32.815: ISAKMP: Created a peer struct for 202.1.100.40, peer port 500

May 17 13:28:32.815: ISAKMP: New peer created peer = 0x6457345C peer_handle = 0x80000002

May 17 13:28:32.819: ISAKMP: Locking peer struct 0x6457345C, IKE refcount 1 for isakmp_initiator

May 17 13:28:32.819: ISAKMP: local port 500, remote port 500

May 17 13:28:32.819: ISAKMP: set new node 0 to QM_IDLE     

May 17 13:28:32.819: insert sa successfully sa = 64572D70

May 17 13:28:32.823: ISAKMP:(0:0:N/A:0):Can not start Aggressive mode, trying Main mode.

May 17 13:28:32.823: ISAKMP:(0:0:N/A:0):No pre-shared key with 202.1.100.40!

May 17 13:28:32.823: ISAKMP:(0:0:N/A:0): constructed NAT-T vendor-07 ID

May 17 13:28:32.827: ISAKMP:(0:0:N/A:0): constructed NAT-T vendor-03 ID

May 17 13:28:32.827: ISAKMP:(0:0:N/A:0): constructed NAT-T vendor-02 ID

May 17 13:28:32.827: ISAKMP:(0:0:N/A:0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM

May 17 13:28:32.827: ISAKMP:(0:0:N/A:0):Old State = IKE_READY  New State = IKE_I_MM1
May 17 13:28:32.831: ISAKMP:(0:0:N/A:0): beginning Main Mode exchange

May 17 13:28:32.831: ISAKMP:(0:0:N/A:0): sending packet to 202.1.100.40 my_port 500 peer_port 500 (I) MM_NO_STATE

May 17 13:28:33.263: ISAKMP (0:0): received packet from 202.1.100.40 dport 500 sport 500 Global (I) MM_NO_STATE

May 17 13:28:33.275: ISAKMP:(0:0:N/A:0):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH

May 17 13:28:33.275: ISAKMP:(0:0:N/A:0):Old State = IKE_I_MM1  New State = IKE_I_MM2
May 17 13:28:33.279: ISAKMP:(0:0:N/A:0): processing SA pay.load. message ID = 0

May 17 13:28:33.283: ISAKMP:(0:0:N/A:0): processing vendor id payload

May 17 13:28:33.283: ISAKMP:(0:0:N/A:0): vendor ID seems Unity/DPD but major 245 mismatch

May 17 13:28:33.283: ISAKMP (0:0): vendor ID is NAT-T v7

May 17 13:28:33.283: ISAKMP : Scanning profiles for xauth ...

May 17 13:28:33.283: ISAKMP:(0:0:N/A:0):Checking ISAKMP transform 1 against priority 10 policy

May 17 13:28:33.287: ISAKMP:      encryption DES-CBC

May 17 13:28:33.287: ISAKMP:      hash SHA

May 17 13:28:33.287: ISAKMP:      default group 1

May 17 13:28:33.287: ISAKMP:      auth RSA sig

May 17 13:28:33.287: ISAKMP:      life type in seconds

May 17 13:28:33.287: ISAKMP:      life duration (VPI) of  0x0 0x1 0x51 0x80

May 17 13:28:33.291: ISAKMP:(0:0:N/A:0):atts are acceptable. Next payload is 0

May 17 13:28:33.343: ISAKMP:(0:1:SW:1): processing vendor id payload

May 17 13:28:33.343: ISAKMP:(0:1:SW:1): vendor ID seems Unity/DPD but major 245 mismatch

May 17 13:28:33.343: ISAKMP (0:134217729): vendor ID is NAT-T v7

May 17 13:28:33.343: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE

May 17 13:28:33.343: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM2  New State = IKE_I_MM2
May 17 13:28:33.343: ISAKMP (0:134217729): constructing CERT_REQ for issuer cn=laoliang o\=nongda i\=zhengzhou

May 17 13:28:33.343: ISAKMP:(0:1:SW:1): sending packet to 202.1.100.40 my_port 500 peer_port 500 (I) MM_SA_SETUP

May 17 13:28:33.343: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE

May 17 13:28:33.343: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM2  New State = IKE_I_MM3
May 17 13:28:33.587: ISAKMP (0:134217729): received packet from 202.1.100.40 dport 500 sport 500 Global (I) MM_SA_SETUP

May 17 13:28:33.591: ISAKMP:(0:1:SW:1):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH

May 17 13:28:33.595: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM3  New State = IKE_I_MM4
May 17 13:28:33.595: ISAKMP:(0:1:SW:1): processing KE payload. message ID = 0

May 17 13:28:.33.659: ISAKMP:(0:1:SW:1): processing NONCE payload. message ID = 0

May 17 13:28:33.663: ISAKMP:(0:1:SW:1):SKEYID state generated

May 17 13:28:33.667: ISAKMP:(0:1:SW:1): processing CERT_REQ payload. message ID = 0

May 17 13:28:33.667: ISAKMP:(0:1:SW:1): peer wants a CT_X509_SIGNATURE cert

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): peer want cert issued by

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): Choosing trustpoint ca as issuer

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): processing vendor id payload

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): vendor ID is Unity

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): processing vendor id payload

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): vendor ID is DPD

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): processing vendor id payload

May 17 13:28:33.671: ISAKMP:(0:1:SW:1): speaking to another IOS box!

May 17 13:28:33.671: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE

May 17 13:28:33.671: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM4  New State = IKE_I_MM4
May 17 13:28:33.671: ISAKMP:(0:1:SW:1):Send initial contact

May 17 13:28:33.715: ISAKMP:(0:1:SW:1):SA is doing RSA signature authentication using id type ID_IPV4_ADDR

May 17 13:28:33.715: ISAKMP (0:134217729): ID payload

        next-payload : 6

        type         : 1

        address      : 202.1.100.30

        protocol     : 17

        port         : 500

        length       : 12

May 17 13:28:33.715: ISAKMP:(0:1:SW:1):Total payload length: 12

May 17 13:28:33.715: ISAKMP (0:134217729): constructing CERT payload for ipaddress=202.1.100.30+hostname=r3.laoliang.com,cn=r3 o\=nongda i\=zhengzhou

May 17 13:28:33.715: ISAKMP:(0:1:SW:1): using the ca trustpoint's keypair to sign

May 17 13:28:33.831: ISAKMP:(0:1:SW:1): sending packet to 202.1.100.40 my_port 500 peer_port 500 (I) MM_KEY_EXCH

May 17 13:28:33.831: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE

May 17 13:28:33.831: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM4  New State = IKE_I_MM5

.

May 17 13:28:38.140: ISAKMP (0:134217729): received packet from 202.1.100.40 dport 500 sport 500 Global (I) MM_KEY_EXCH

May 17 13:28:38.148: ISAKMP:(0:1:SW:1): processing ID payload. message ID = 0

May 17 13:28:38.148: ISAKMP (0:134217729): ID payload

        next-payload : 6

        type         : 2

        FQDN name    : r4.laoliang.com

        protocol     : 17

        port         : 500

        length       : 23

May 17 13:28:38.148: ISAKMP:(0:1:SW:1):: peer matches *none* of the profiles

May 17 13:28:38.152: ISAKMP:(0:1:SW:1): processing CERT payload. message ID = 0

May 17 13:28:38.152: ISAKMP:(0:1:SW:1): processing a CT_X509_SIGNATURE cert

May 17 13:28:38.188: ISAKMP:(0:1:SW:1): peer's pubkey isn't cached.

May 17 13:28:41.016: ISAKMP:(0:1:SW:1): Unable to get DN from certificate!

May 17 13:28:41.020: ISAKMP:(0:1:SW:1): Cert presented by peer contains no OU field.

May 17 13:28:41.024: ISAKMP (134217729): adding peer's pubkey to cache

May 17 13:28:41.024: ISAKMP:(0:1:SW:1): processing SIG payload. message ID = 0

May 17 13:28:41.048: ISAKMP:(0:1:SW:1):SA authentication status:

        authenticated

May 17 13:28:41.048: ISAKMP:(0:1:SW:1):SA has been authenticated with 202.1.100.40

May 17 13:28:41.048: ISAKMP: Trying to insert a peer 202.1.100.30/202.1.100.40/500/,  and inserted successfully 6457345C.

May 17 13:28:41.052: ISAKMP:(0:1:SW:1):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH

May 17 13:28:41.052: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM5  New State = IKE_I_MM6
May 17 13:28:41.052: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE

May 17 13:28:41.056: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM6  New State = IKE_I_MM6
May 17 13:28:41.060: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE

May 17 13:28:41.060: ISAKMP:(0:1:SW:1):Old State = IKE_I_MM6  New State = IKE_P1_COMPLETE
May 17 13:28:41.064: ISAKMP:(0:1:SW:1):beginning Quick Mode exchange, M-ID of 1880679587

May 17 13:28:41.080: ISAKMP:(0:1:SW:1): sending packet to 202.1.100.40 my_port 500 peer_port 500 (I) QM_IDLE     

May 17 13:28:41.084: ISAKMP:(0:1:SW:1):Node 1880679587, Input = IKE_MESG_INTERNAL, IKE_INIT_QM

May 17 13:28:41.084: ISAKMP:(0:1:SW:1):Old State = IKE_QM_READY  New State = IKE_QM_I_QM1

May 17 13:28:41.084: ISAKMP:(0:1:SW:1):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE

May 17 13:28:41.088: ISAKMP:(0:1:SW:1):Old State = IKE_P1_COMPLETE  New State = IKE_P1_COMPLETE
May 17 13:28:41.516: ISAKMP (0:134217729): received packet from 202.1.100.40 dport 500 sport 500 Global (I) QM_IDLE     

May 17 13:28:41.520: ISAKMP:(0:1:SW:1): processing HASH payload. message ID = 1880679587

May 17 13:28:41.520: ISAKMP:(0:1:SW:1): processing SA payload. message ID.!! = 1880679587

May 17 13:28:41.520: ISAKMP:(0:1:SW:1):Checking IPSec proposal 1

May 17 13:28:41.524: ISAKMP: transform 1, ESP_DES

May 17 13:28:41.524: ISAKMP:   attributes in transform:

May 17 13:28:41.524: ISAKMP:      encaps is 1 (Tunnel)

May 17 13:28:41.524: ISAKMP:      SA life type in seconds

May 17 13:28:41.524: ISAKMP:      SA life duration (basic) of 3600

May 17 13:28:41.524: ISAKMP:      SA life type in kilobytes

May 17 13:28:41.524: ISAKMP:      SA life duration (VPI) of  0x0 0x46 0x50 0x0

May 17 13:28:41.528: ISAKMP:      authenticator is HMAC-MD5

May 17 13:28:41.528: ISAKMP:(0:1:SW:1):atts are acceptable.

May 17 13:28:41.532: ISAKMP:(0:1:SW:1): processing NONCE payload. message ID = 1880679587

May 17 13:28:41.532: ISAKMP:(0:1:SW:1): processing ID payload. message ID = 1880679587

May 17 13:28:41.532: ISAKMP:(0:1:SW:1): processing ID payload. message ID = 1880679587

May 17 13:28:41.540: ISAKMP: Locking peer struct 0x6457345C, IPSEC refcount 1 for for stuff_ke

!!!!!May 17 13:28:41.544: ISAKMP:(0:1:SW:1): Creating IPSec SAs

May 17 13:28:41.544:         inbound SA from 202.1.100.40 to 202.1.100.30 (f/i)  0/ 0

        (proxy 4.4.4.4 to 3.3.3.3)

May 17 13:28:41.544:         has spi 0x3F85BFA4 and conn_id 0 and flags 2

May 17 13:28:41.544:         lifetime of 3600 seconds

May 17 13:28:41.544:         lifetime of 4608000 kilobytes

May 17 13:28:41.548:         has client flags 0x0

May 17 13:28:41.548:         outbound SA from 202.1.100.30 to 202.1.100.40 (f/i) 0/0

        (proxy 3.3.3.3 to 4.4.4.4)

May 17 13:28:41.548:         has spi 244258562 and conn_id 0 and flags A

May 17 13:28:41.548:         lifetime of 3600 seconds

May 17 13:28:41.548:         lifetime of 4608000 kilobytes

May 17 13:28:41.552:         has client flags 0x0

May 17 13:28:41.552: ISAKMP:(0:1:SW:1): sending packet to 202.1.100.40 my_port 500 peer_port 500 (I) QM_IDLE     

May 17 13:28:41.556: ISAKMP:(0:1:SW:1):deleting node 1880679587 error FALSE reason "No Error"

Ma!!!!!!y 17 13:28:41.556: ISAKMP:(0:1:SW:1):Node 1880679587, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH

May 17 13:28:41.556: ISAKMP:(0:1:SW:1):Old State = IKE_QM_I_QM1  New State = IKE_QM_PHASE2_COMPLETE

May 17 13:28:41.560: ISAKMP: Locking peer struct 0x6457345C, IPSEC refcount 2 for from create_transforms

May 17 13:28:41.564: ISAKMP: Unlocking IPSEC struct 0x6457345C from create_transforms, count 1!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Success rate is 95 percent (95/100), round-trip min/avg/max = 60/167/272 ms
¶þ£º¹ØÓÚvpn client Ö¤ÊéÉêÇë
µã»÷enroll

department Ãû×Ö±ØÐë¸øipsecgroup¶¨ÒåµÄÃû×ÖÒ»ÖÂ
 ÔÚ51cto¿ª²©ÓжÎʱ¼äÁË£¬Õâ¶ÎÈÕ×ÓдÁËµã¹ØÓÚciscoµÄÎÄÕ¡£½ñÌìÓÐÈË˵ÎÒµÄÎÄÕÂдµÄÁ¬ÊµÑ鱨¸æ¶¼²»Ë㣬¹ÒÁËÕÅͼ£¬ÏÂÃæ¾ÍÊÇÌùÃüÁî¡£
Õâ¾ÍÈÃÎÒÏëÆð¹ØÓÚÑ§Ï°ÍøÂçµÄ·½·¨£¬ÎÒÃǵ½µ×¸ÃÔõÑùÀûÓÃ51ctoÕâ¸öƽ̨ѧµ½ÎÒ..
 
 

ÎÒÃÇÏÈ×öÏÂÅäÖãº
R1:interface Serial1/0

 ip address 13.1.1.1 255.255.255.0

 serial restart-delay 0      

interface Serial1/1

 ip address 14.1.1.1 255.255.255.0

 serial restart-delay 0

interface Serial1/2

 ip address 15.1.1.1 255.255.255.0

 serial restart-delay 0

interface Loopback0

 ip address 1.1.1.1 255.255.255.0

router ospf 10

 router-id 1.1.1.1

 log-adjacency-changes

 network 1.1.1.0 0.0.0.255 area 0

 network 13.1.1.0 0.0.0.255 area 0

router bgp 1

 no synchronization

 bgp router-id 1.1.1.1

 bgp log-neighbor-changes

 neighbor liang peer-group

 neighbor liang remote-as 2

 neighbor liang ebgp-multihop 255

 neighbor liang update-source Loopback0

 neighbor 3.3.3.3 remote-as 1

 neighbor 3.3.3.3 update-source Loopback0

 neighbor 3.3.3.3 next-hop-self

 neighbor 4.4.4.4 peer-group liang

 neighbor 5.5.5.5 peer-group liang

 no auto-summary

ip route 4.4.4.4 255.255.255.255 14.1.1.4

ip route 5.5.5.5 255.255.255.255 15.1.1.5

R2:
interface Loopback0

 ip address 2.2.2.2 255.255.255.0
interface Serial1/0

 ip address 24.1.1.2 255.255.255.0

 serial restart-delay 0       

interface Serial1/1

 ip address 23.1.1.2 255.255.255.0

 serial restart-delay 0

interface Serial1/2

 no ip address

 shutdown

 serial restart-delay 0

inteface Serial1/3

 ip address 25.1.1.2 255.255.255.0

 serial restart-delay 0

router ospf 10

 router-id 2.2.2.2

 log-adjacency-changes

 network 2.2.2.0 0.0.0.255 area 0

 network 23.1.1.0 0.0.0.255 area 0

router bgp 1

 no synchronization

 bgp router-id 2.2.2.2

 bgp log-neighbor-changes

 neighbor liang peer-group     ÎªÁ˼ò»¯ÅäÖÃÎÒÃÇÓÃpeer-group

 neighbor liang remote-as 2

 neighbor liang ebgp-multihop 255

 neighbor liang update-source Loopback0

 neighbor 3.3.3.3 remote-as 1

 neighbor 3.3.3.3 update-source Loopback0

 neighbor 3.3.3.3 next-hop-self

 neighbor 4.4.4.4 peer-group liang

 neighbor 5.5.5.5 peer-group liang

 no auto-summary

ip route 4.4.4.4 255.255.255.255 24.1.1.4

ip route 5.5.5.5 255.255.255.255 25.1.1.5
R3:
interface Loopback0

 ip address 3.3.3.3 255.255.255.0

interface Serial1/0

 ip address 13.1.1.3 255.255.255.0

 serial restart-delay 0      

interface Serial1/1

 ip address 23.1.1.3 255.255.255.0

 serial restart-delay 0

router ospf 10

 router-id 3.3.3.3

 log-adjacency-changes

 network 3.3.3.0 0.0.0.255 area 0

 network 13.1.1.0 0.0.0.255 area 0

 network 23.1.1.0 0.0.0.255 area 0

router bgp 1

 no synchronization

 bgp router-id 3.3.3.3

 bgp log-neighbor-changes

 neighbor 1.1.1.1 remote-as 1

 neighbor 1.1.1.1 update-source Loopback0

 neighbor 2.2.2.2 remote-as 1

 neighbor 2.2.2.2 update-source Loopback0

 no auto-summary
ÆäËûµÄÅäÖö¼²î²»¶à²»ÔÚÌù³öÀ´ÁË
ÎÒÃÇ¿´ÏÂBGP±í
R1#show ip bgp

BGP table version is 3, local router ID is 1.1.1.1

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

*  6.6.6.0/24       4.4.4.4                                0 2 i

*>                  5.5.5.5                                0 2 i

*  8.8.8.0/24       5.5.5.5                                0 2 i

*>                  4.4.4.4                                0 2 i
R2#show ip bgp

BGP table version is 3, local router ID is 2.2.2.2

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

*  6.6.6.0/24       4.4.4.4                                0 2 i

*>                  5.5.5.5                                0 2 i

*  8.8.8.0/24       5.5.5.5                                0 2 i

*>                  4.4.4.4                                0 2 i
R3#   show ip bgp

BGP table version is 9, local router ID is 3.3.3.3

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

* i6.6.6.0/24       2.2.2.2                  0    100      0 2 i

*>i                 1.1.1.1                  0    100      0 2 i

* i8.8.8.0/24       2.2.2.2                  0    100      0 2 i

*>i                 1.1.1.1                  0    100      0 2 i
·¢ÏÖR3µ½6.6.6.0ºÍ8.8.8.0 ÏÂÒ»Ìø¶¼ÊÇR1
ÎÒÃǵÄÒªÇóÊÇR3·ÃÎÊ6.6.6.0/24 ×ßR1 R4 ·ÃÎÊ8.8.8.0/24×ßR2 R5
µÚÒ»ÖÖ·½Ê½ÎÒÃÇÔÚR1 R2µÄout·½Ïò×ö

R1
access-list 1 permit 6.6.6.0

access-list 2 permit 8.8.8.0

route-map to-r3 permit 10

 match ip address 1

 set local-preference 400

route-map to-r3 permit 20

 match ip address 2

 set local-preference 300

route-map to-r3 permit 30

R1(config)#router bgp 1

R1(config-router)#neighbor 3.3.3.3 route-map to-r3
R2


access-list 1 permit 6.6.6.0

access-list 2 permit 8.8.8.0

route-map to-r3 permit 10

 match ip address 1

 set local-preference 300

route-map to-r3 permit 20

 match ip address 2

 set local-preference 400

R2(config)#router bgp 1

R2(config-router)#neighbor 3.3.3.3 route-map to-r3 out
ÎÒÃÇÐèÒªµÄR3ÉÏÈíÇåÏÂ
R3#clear ip bgp * soft

R3#   show ip bgp    

BGP table version is 12, local router ID is 3.3.3.3

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

* i6.6.6.0/24       2.2.2.2                  0    300      0 2 i

*>i                 1.1.1.1                  0    400      0 2 i

*>i8.8.8.0/24       2.2.2.2                  0    400      0 2 i

* i                 1.1.1.1                  0    300      0 2 i

 
·¢ÏÖµÚÒ»ÌøÈ·Êµ±äÁË£¬µ«ÎÒÃÇ¿´ÏÂR2 R1µÄBGP±í
R1#show ip bgp

BGP table version is 3, local router ID is 1.1.1.1

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight Path

* 6.6.6.0/24 4.4.4.4 0 2 i

*> 5.5.5.5 0 2 i

* 8.8.8.0/24 5.5.5.5 0 2 i

*> 4.4.4.4 0 2 i
R2#show ip bgp   Ö±½Ó×ßR4ÁË »¹²»ÊÇÎÒÃÇÏëÒªµÄÒªÇó

BGP table version is 3, local router ID is 2.2.2.2

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight Path

* 6.6.6.0/24 4.4.4.4         0 2 i       

*> 5.5.5.5 0 2 i

* 8.8.8.0/24 5.5.5.5 0 2 i

*> 4.4.4.4 0 2 i
ÎÒÃÇÖ»ÊÇ¿ØÖÆÁËR3µ½R1R2µÄѡ·
ÎÒÃÇÔÚR3 R4µÄin·½Ïò×ö

R1
access-list 1 permit 6.6.6.0

route-map liang permit 10

 match ip address 1

 set local-preference 500

route-map liang permit 20

neighbor 4.4.4.4 route-map liang in
R2
access-list 1 permit 8.8.8.0

route-map liang permit 10

 match ip address 1

 set local-preference 500

route-map liang permit 20

neighbor 5.5.5.5 route-map liang in
ÈíÇåÒ»ÏÂÔÚR1 R2  R3
R1#show ip bgp

BGP table version is 4, local router ID is 1.1.1.1

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

*> 6.6.6.0/24       4.4.4.4                       500      0 2 i

*                   5.5.5.5                                0 2 i

*  8.8.8.0/24       5.5.5.5                                0 2 i

*>                  4.4.4.4                                0 2 i
R2#show ip bgp

BGP table version is 4, local router ID is 2.2.2.2

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

*  6.6.6.0/24       4.4.4.4                                0 2 i

*>                  5.5.5.5                                0 2 i

*> 8.8.8.0/24       5.5.5.5                       500      0 2 i

*                   4.4.4.4                                0 2 i
R3#   show ip bgp

BGP table version is 17, local router ID is 3.3.3.3

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete
   Network          Next Hop            Metric LocPrf Weight Path

* i6.6.6.0/24       2.2.2.2                  0    100      0 2 i

*>i                 1.1.1.1                  0    500      0 2 i

*>i8.8.8.0/24       2.2.2.2                  0    500      0 2 i

* i                 1.1.1.1                  0    100      0 2 i
ÎÒÃǵÄÄ¿µÄ´ïµ½ÁË£¡
×ܽ᣺
loacl preference ÓÐÈýÖÖ²»Í¬µÄ·½·¨½øÐÐÅäÖÃ

1.ͨ¹ýIGP·ÓÉÒýÈëBGPÊǹØÁªroute-map

2.Õë¶ÔIBGP peer Ó¦ÓÃin and out ·½Ïò½øÐÐÅäÖ㬶ԴÓpeerÊÕµ½»òÕßͨ¹ýµÄ¸øpeerµÄËùÓлò²¿·Ö½øÐÐÉèÖÃ

3.Õë¶ÔEBGP peer Ó¦ÓÃin ·½ÏòµÄroute-mapÕë¶Ôpeer½ÓÊܵ½µÄËùÓлò²¿·Ö·ÓɽøÐÐÉèÖÃ[/img]..
DMVPNµÄÓŵ㣺
1.ÖÐÐÄ·Óɲ»ÐèҪΪÿ¸ö·ÖÖ§Õ¾µãµ¥¶À½¨Á¢Ò»¸ögreËíµÀºÍcrypto map ÌõÄ¿£¬¼ò»¯ipsecÅäÖÃ
2.ÖÐÐÄÕ¾µã²»ÐèÒªÖªµÀ·ÖÖ§Õ¾µãµÄϸ½Ú£¬¼´Ê¹Ôö¼Ó·ÖÖ§Õ¾µã£¬ÖÐÐÄÕ¾µãÒ²²»ÐèÒª¶îÍâµÄÅäÖÃ
3.·ÖÖ§Õ¾µã¿ÉÒÔ¶¯..
ÔÚʵ¼ÊÍøÂçÔËÓÃÖÐÎÒÃÇʱ³£ÅÜGRE+IPSECÀ´ÊµÏÖÎÒÃÇÖÐÐĵ½·ÖÖ§µÄÔ¶³Ì·ÃÎʻػ°£¬ÕâÑùÒÔÀ´ÈÝÒ×ÅäÖ㬶øÀ´¿ÉÓÃÐԸߣ¬ÎÒÃÇÖªµÀL2LÎÞÂÛÊÇÁ´Â·±¸·Ý»¹ÊÇÉ豸±¸·Ý£¬¶¼²»ÊÇ״̬±¸·Ý£¬µ±Ò»¸öµã¶Ïµôºó£¬Óþ­¹ý¼¸Ê®ÃëÉõÖÁ1·Ö¶àÖÖ..
ÔÚʵ¼Ê¹¤³ÌÖÐÎÒÃǾ­³£×övpnÀ´ÊµÏÖÔ¶³Ì·ÃÎʵݲȫ£¬¼ÙÈçÏÖÔÚÒ»¹«Ë¾ÓµÓÐһ̨·ÓÉÆ÷À´ÊµÏÖL2Lvpn£¬±£Ö¤·Ö²¿Á¬½Ó×ܲ¿µÄÊý¾Ý°²È«¡£µ«Ëæ×ÅÒµÎñµÄÀ©´ó£¬Ò»Ð©³ö²îÔ±¹¤Í¬ÑùÒª·ÃÎÊ×ܲ¿ÄÚ²¿µÄÊý¾Ý£¬À´±£Ö¤ÈÕ³£¹¤×÷µÄ½øÐУ¬¸Ã..
˵ÆðÉí·ÝÈÏÖ¤ÎÒÃǾͻáÏëÆðAAA £¬AAA´ú±íAuthentication¡¢Authorization¡¢Accounting£¬ÒâΪÈÏÖ¤¡¢ÊÚȨ¡¢¼ÇÕÊ£¬ÆäÖ÷ҪĿµÄÊǹÜÀíÄÄЩÓû§¿ÉÒÔ·ÃÎÊ·þÎñÆ÷£¬¾ßÓзÃÎÊȨµÄÓû§¿ÉÒԵõ½ÄÄЩ·þÎñ£¬ÈçºÎ¶ÔÕýÔÚʹÓÃÍøÂç×Ê..

 1 .ÐéÏßΪ2²ãÏß·trunkʵÏßΪ3²ãÁ´Â·
2. ÓÐ3¸övlan   ds1Ϊvlan1 vlan2µÄ¸úÍøÇÅ  ds2Ϊvlan3µÄ¸úÍøÇÅ
3. ÔÚswÏÂpc1ÊôÓÚvlan1£¬sw4ÏÂpc4ÊôÓÚvlan3
4. »ã¾Û²ãÏòÉÏÊÇ´¿´âµÄ3²ãÁ´Â·
5. ÄÇÕâ¸öÍøÂçÓм¸¸ö×ÓÍø£¿
×ܹ²ÓÐ11¸ö×ÓÍø£¬Ã¿¸öʵÏßΪ1¸ö×ÓÍø¼ÓÉÏ3¸övlan
6. ÄÇôpc1µÄÍø¹ØÖ¸ÏòÄÄÀ
 Ds1µÄsvi¿ÚÌṩ3²ãµ½2²ãµÄÏνӠ  Ϊʲô²»Ö±Ïòcs1,ÒòΪds1ºÍcs1Ö®¼äµÄÁ´Â·Îª3²ã£¬pc1²»ÖªµÀËüÃÇÖ®¼äµÄ×ÓÍø
Ö¸Ïò±¾µØvlan µÄip
7. Ϊʲôds1ºÍds2Á½¸öÈý²ã½»»»»úÖ®¼äµÄÁ´Â·Îª2²ã²»ÊÇ3²ã£¿


¼ÓÈëswaºÍswbÖ®¼äµÄÁ´Â·Îª3²ã  swaÊôÓÚvlan2 swbÊôÓÚvlan3£¬ÏÖÔÚsw1ÊôÓÚvlan2£¬sw1µÄÊý¾ÝÖ±½Óͨ¹ýswaÉÏÃæµÄÁ´Â·½øÐд«Ê䣬¼ÓÈësw1ÊôÓÚvlan3ÔÚswbºÍsw1Ö®¼äµÄÁ´Â·downÁË£¬ÄÇôswb»¹ÈÏΪ֮¼äΪvlan3µÄ¸úÍøÇÅsw1ÉϵÄÊý¾Ý´«Êä²»µ½swbÖ»ºÃ´ÓswaµÄÉÏÃæ½øÐд«Ê䣬ÕâÑùswaÉÏÃæµÄÁ´Â·Á÷Á¿¾Í»á¶àЩÉõÖÁÓµÈû¶øswbÉÏÃæÁ´Â·µÄÁ÷Á¿¾Í»áºÜÉÙ´ï²»µ½¸ºÔؾùºâµÄЧ¹û£¬¼ÙÈçswaswbÖ®¼äµÄÁ´Â·Îª2²ãµÄÔÚsw1ºÍswbÖ®¼äµÄÁ´Â·downµôÖ®ºó£¬Í¨¹ýÊÕÁ²sw1ÉϵÄÊý¾Ý¾Í»áͨ¹ýswaµ½´ïswb£¬ÔÙͨ¹ýswbÏòÉÏ´«Êä
ËùÒÔÎÒÃÇÒªÇóΪ2²ãµÄÆðtrunk
¼ÙÈçÁ½¸ö3²ã½»»»»ú±»3²ã½Ó¿Ú¸ô¿ª£¬ÊôÓÚ±¾µØvlan£¬Ã¿¸ö½»»»»úÏÂÓÐÒ»¸ö×ÓÍø£¬Á½¸ö¾ÍÓÐÁ½¸ö×ÓÍø
8. VlanÖ®¼ä·ÓÉÔõô×ö£¿3¸övlanÖ®¼äͨÐÅÔõô×ö£¿
ÎÒÃÇÔÚds1ºÍds2Ö®¼äÆðSVI
ÎÒÃÇÔÚds1Æôvlan1ºÍvlan2 µÄsvi£¬ÔÚds2ÉÏÆôvlan3µÄÍø¹Ø
¼ÙÈçds1downÁËÔõô°ì£¿ÔÚds1ÉÏÆô3¸ösvi£¬ÄÇôpcÉϵÄÍø¹ØÉèÄǸö£¿
ÎÒÃÇÒ»°ãÔÚds1ºÍds2ÉÏÆôÓÃhrsp£¬ÆôÓÃÒ»¸öÐéÄâµÄip×öpcÍø¹Ø
9. ÎÒÃÇÒ»°ãÔÚ·À»ðǽÉÏ×önatºÍĬÈÏ·ÓÉÖ¸ÏòͨÐÅÉÌ£¬
10.Ds1ºÍcs1Ö®¼äÔõôͨÐÅ£¿
ÎÒÃÇ×ö·ÓÉЭÒéÈçospf×öÇøÓò¼ä·ÓÉ£¬¿ÉÒÔÔÚ·À»ðǽÉÏ×öĬÈÏ·ÓÉip default network  ´«¸øºËÐIJ㽻»»»ú£¬»ã¾Û²ãѧϰºËÐIJ㣬ÄÇôÔÚds1ÆôÓÃospfÐèÒªÆôÓü¸¸önetwork£¬5¸ö  ÉÏÃæ2¸ö×ÓÍø3¸övlan  trunkûÓÐ×ÓÍø²»ÓÃͨ¸æÒ²¾ÍÊÇ˵2²ãµØÖ·²»ÓÃͨ¸æ
 
²¹³ä£º
 
vlanºÅÊǶàÉÙipµØÖ·Ò²Ö»Îª¶àÉÙ£¬·½±ãÒÔºóÅÅ´í£¬vlan2  2.0
 
·ÓÉ×öpcÖ¸¶¨ip ¼ÓĬÈÏ·ÓÉ
 
Èý²ã½Ó¿ÚûÓбØÒª×ötrunk  trunkÊÇ2²ãµÄЭÒéÓÃÔÚÁ½¸ö2²ã½»»»»úÖ®¼ä
ÅжϹ㲥Óò¿´¿´Óм¸¸öÍø¶Î£¬ÔÚ3²ã½»»»»úÖ®¼ävtp¾ÍûÓÐÒâÒåÁË£¬vtp²»»áÓ°ÏìvlanµÄ´«ËÍÖ»»áÓ°Ïìvlan´«Êä¸øË­
[/img]..
 ÎÒÃÇÔÚ×ö·ÓÉÖØÐ·ֲ¼µÄµÄʱºò£¬Ê±³£ÓÉÓÚAD¾àÀëµÄ²»Í¬µ¼Ö·ÓɳöÏÖ»·Â·»òÕßµ¼Ö²»ÕýÈ·µÄ·ÓÉ£¬ÄÇÕâÆªÎÄÕÂÎҾͺúÃ˵ÏÂÕâ¸öÎÊÌ⣬ÈçͼËùʾ£º

ÎÒÃÇÏȰ´Õý³£µÄ·ÖÅä·½·¨×öÏ¿´¿´ÎÊÌâÔÚÄÄ
ÎÒÃÇÏÖÔÚr3  r4 ÉÏÖØÐ·ÖÅä ÃüÁîÈçÏÂ


r3(config)#router rip
r3(config-router)#reis
r3(config-router)#redis
r3(config-router)#redistribute ospf 1 me
r3(config-router)#redistribute ospf 1 metric 2
r3(config-router)#redistribute ospf 1 metric 2 su
r3(config-router)#redistribute ospf 1 metric 2 subnets

r3(config-router)#redistribute rip metric 100 sub
r3(config-router)#redistribute rip metric 100 subnets metric-ty 2

r4(config)#router rip
r4(config-router)#redis
r4(config-router)#redistribute ospf 1 me
r4(config-router)#redistribute ospf 1 metric ?
  <0-16>       Default metric
  transparent  Transparently redistribute metric

r4(config-router)#redistribute rip metric 100 me 
r4(config-router)#redistribute rip metric 100 metric-type 2 sub

 
r4#show ip route



Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area 
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route
 
Gateway of last resort is not set
 
O    192.168.4.0/24 [110/74] via 192.168.3.1, 00:02:04, Serial0/0
O    192.168.5.0/24 [110/138] via 192.168.3.1, 00:02:04, Serial0/0
O E2 192.168.6.0/24 [110/100] via 192.168.3.1, 00:02:04, Serial0/0
O E2 192.168.1.0/24 [110/100] via 192.168.3.1, 00:02:04, Serial0/0
C    192.168.2.0/24 is directly connected, Ethernet1/0
C    192.168.3.0/24 is directly connected, Serial0/0

ÎÒÃÇ¿´ÏÂr4µÄ·ÓÉ±í·¢ÏÖͨÍù0.6Íø¶ÎÏÅÒ»ÌøÊÇ192.168.3.1 Ìøµ½r1ÉÏÃæÈ¥ÁË£¬Õâ²¢²»ÊÇ×î¼Ñ·ÓÉ£¬ÎªÊ²Ã´»á·¢ÉúÕâÑùµÄÎÊÌâ?ÊǹÜÀí¾àÀëÈǵûö£¬ÎÒÃÇÖªµÀospf¹ÜÀí¾àÀëÊÇ90¡£¶øripÊÇ120£¬ËùÒÔ·ÓÉ»áÓÅÏÈÑ¡ÓÃospf·ÓÉÌõÄ¿£¬Õâ¾Í¸øÎÒÃÇÒ»¸ö¾¯Ê¾:ÔÚ¶àµã·ÓÉÖØÐ·ÖÅäʱ¹ÜÀí¾àÀë»áµ¼Ö·Ç×î¼Ñ·¾¶µÄÑ¡Ôñ£¬Â·ÓÉ»·Â·ºÍºÚ¶´¡£
ÄÇÎÒÃǸÃÕ¦Ñù×öÄÇ£¬ÓÐÁ½ÖÖ·½·¨Ò»ÊÇÔËÓÃÖØ·¢²¼ÁÐ±í¿ØÖÆÂ·ÓɸüÐÂ
·¨¶þ£ºÓÃdistance¿ØÖƹÜÀí¾àÀë 
ÎÒÃÇÏÈ¿´µÚÒ»ÖÖ·½·¨
ÎÒÃÇÔÚr3 r4 ×öÈçÏÂÅäÖÃ
r3 £ºr3(config-router)#redistribute rip metric 100  sub
r3(config-router)#net
r3(config-router)#network 192.168.3.0 0.0.0.255 a 0
r3(config-router)#dis
r3(config-router)#distri
r3(config-router)#distribute-list 1 in
r3(config-router)#router rip
r3(config-router)#redtri
r3(config-router)#redis 
r3(config-router)#redistribute ospf 1 me
r3(config-router)#redistribute ospf 1 metric 2
r3(config-router)#net
r3(config-router)#network 192.168.6.0
r3(config-router)#distri
r3(config-router)#distribute-list 2 in
r3(config-router)#ip cl
r3(config-router)#ip cl
r3(config)#acc
r3(config)#access-list 1 per
r3(config)#access-list 1 permit 192.168.4.0
r3(config)#access-list 1 permit 192.168.3.0
r4;r4(config)#router rip 
r4(config-router)#redis
r4(config-router)#redistribute ospf 1 me
r4(config-router)#redistribute ospf 1 metric 2
r4(config-router)#net
r4(config-router)#network 192.168.2.0 0.0.0.
                                      ^
% Invalid input detected at '^' marker.
 
r4(config-router)#network 192.168.2.0 0.0.0.255 
                                      ^
% Invalid input detected at '^' marker.
 
r4(config-router)#network 192.168.2.0           
r4(config-router)#distri
r4(config-router)#distribute-list 1 in
r4(config-router)#router ospf 1
r4(config-router)#red
r4(config-router)#redistribute rip me
r4(config-router)#redistribute rip metric 100 sub
r4(config-router)#net
r4(config-router)#network 192.168.3.0 0.0.0.255 a 0
r4(config-router)#distri
r4(config-router)#distribute-list 2 in
r4(config-router)#ip cl
r4(config)#acc
r4(config)#access-list 1 per 192.168.1.0 
r4(config)#acc
r4(config)#access-list 1 per 192.168.6.0
r4(config)#acc
r4(config)#access-list 2 per 192.166.4.0
r4(config)#access-list 2 per 192.168.4.0
r4(config)#access-list 2 per 192.168.5.0
ÎÒÃÇÔÚshowÏÂ

r4#show ip ro
r4#show ip route 
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area 
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route
 
Gateway of last resort is not set
 
O    192.168.4.0/24 [110/74] via 192.168.3.1, 00:00:21, Serial0/0
O    192.168.5.0/24 [110/138] via 192.168.3.1, 00:00:21, Serial0/0
R    192.168.6.0/24 [120/1] via 192.168.2.5, 00:00:11, Ethernet1/0
R    192.168.1.0/24 [120/1] via 192.168.2.5, 00:00:11, Ethernet1/0
C    192.168.2.0/24 is directly connected, Ethernet1/0
C    192.168.3.0/24 is directly connected, Serial0/0
·¢ÏÖ192.168.6.0 ÏÅÒ»ÌøÎª192.168.2.5 ÁË  ³É¹¦
·¨2£ºÓÃdistance¸Ä±ä¹ÜÀí¾àÀë
 

r3(config)#router ospf 1
r3(config-router)#red
r3(config-router)#redistribute rip me
r3(config-router)#redistribute rip metric 100 sub
r3(config-router)#net
r3(config-router)#network 192.168.5.0 0.0.0.255 a 0
r3(config-router)#dis
r3(config-router)#distan
r3(config-router)#distance 130
r3(config-router)#distan
r3(config-router)#distance 110 0.0.0.0 255.255.255.0 1
r3(config-router)#rout
r3(config-router)#router rip
r3(config-router)#redis
r3(config-router)#redistribute ospf 1 me
r3(config-router)#redistribute ospf 1 metric 2 
r3(config-router)#net
r3(config-router)#network 192.168.6.0
r3(config-router)#dis
r3(config-router)#distan
r3(config-router)#distance 130
r3(config-router)#distan
r3(config-router)#distance 120 192.168.6.3 2

r3(config)#access-list 1 per 192.168.4.0
r3(config)#access-list 1 per 192.168.5.0
r3(config)#access-list 2 per 192.168.6.0 
r3(config)#access-list 2 per 192.168.1.0 

r4(config-router)#redistribute rip me
r4(config-router)#redistribute rip metric 100 sub
r4(config-router)#net
r4(config-router)#network 192.168.3.0 0.0.0.255 a 0
r4(config-router)#distan
r4(config-router)#distance 130
r4(config-router)#distance 110 0.0.0.0 255.255.255.255 1
r4(config-router)#router rip
r4(config-router)#red
r4(config-router)#redistribute ospf 1 me
r4(config-router)#redistribute ospf 1 metric 2 
r4(config-router)#net
r4(config-router)#network 192.168.2.0
r4(config-router)#dis
r4(config-router)#distan
r4(config-router)#distance 130
r4(config-router)#distan
r4(config-router)#distance 120 192.168.2.4 2
% Incomplete command.
 
r4(config-router)#distance 120 192.168.2.4  0.0.0.255 2
r4(config-router)#ip cl
r4(config)#ac 
r4(config)#access-list 1 per 192.168.4.0
r4(config)#access-list 1 per 192.168.5.0
r4(config)#access-list 2 per 192.168.1.0
r4(config)#access-list 2 per 192.168.6.0

r4#show ip ro
r4#show ip route 
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area 
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route
 
Gateway of last resort is not set
 
O    192.168.4.0/24 [110/74] via 192.168.3.1, 00:00:21, Serial0/0
O    192.168.5.0/24 [110/138] via 192.168.3.1, 00:00:21, Serial0/0
R    192.168.6.0/24 [120/1] via 192.168.2.5, 00:00:11, Ethernet1/0
R    192.168.1.0/24 [120/1] via 192.168.2.5, 00:00:11, Ethernet1/0
C    192.168.2.0/24 is directly connected, Ethernet1/0
C    192.168.3.0/24 is directly connected, Serial0/0
³É¹¦£¡

 


 




 [/img]..
²ßÂÔ·ÓÉÊÇÒ»ÖֱȻùÓÚÄ¿±êÍøÂç½øÐзÓɸü¼ÓÁé»îµÄÊý¾Ý°ü·ÓÉת·¢»úÖÆ¡£Ó¦ÓÃÁ˲ߠ ²ßÂÔ·ÓÉ£¬Â·ÓÉÆ÷½«Í¨¹ý·ÓÉͼ¾ö¶¨ÈçºÎ¶ÔÐèҪ·ÓɵÄÊý¾Ý°ü½øÐд¦Àí£¬Â·ÓÉͼ¾ö¶¨ÁËÒ»¸öÊý¾Ý°üµÄÏÂÒ»Ìø×ª·¢Â·ÓÉÆ÷¡£
 &n..
 <<   1   2   3   4   5   >>   Ò³Êý ( 1/11 )

¹«¸æ

×î½üѧÁ˲»ÉÙ¶«Î÷ace wlan waas µÈµÈ£¬Óлú»áºÃºÃ·ÖÏí¸ø´ó¼Ò£¡ÄãÒªÄã¸ÒÈÃÎÒ×ö£¬ÎÒ¾ÍÄÜ×öµÄ×îºÃ