<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Ipsec с несколькими филиалами</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21176.html</link>
    <description>Здравствуйте,&lt;br&gt;настроил ipsec vpn между 2811 и 1841 по доке:&lt;br&gt;hostname R2&lt;br&gt;!&lt;br&gt;boot-start-marker&lt;br&gt;boot-end-marker&lt;br&gt;!&lt;br&gt;!&lt;br&gt;no aaa new-model&lt;br&gt;!&lt;br&gt;resource policy&lt;br&gt;!&lt;br&gt;clock timezone EST 0&lt;br&gt;ip subnet-zero&lt;br&gt;no ip domain lookup&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto isakmp policy 10&lt;br&gt; authentication pre-share&lt;br&gt;!&lt;br&gt;crypto isakmp key ciscokey address 200.1.1.1&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto ipsec transform-set myset esp-3des esp-md5-hmac &lt;br&gt;!&lt;br&gt;crypto map myvpn 10 ipsec-isakmp &lt;br&gt; set peer 200.1.1.1&lt;br&gt; set transform-set myset&lt;br&gt;&lt;br&gt;!--- Include the private-network-to-private-network traffic&lt;br&gt;!--- in the encryption process:&lt;br&gt;&lt;br&gt;match address 101&lt;br&gt;!&lt;br&gt;!&lt;br&gt;!&lt;br&gt;interface Ethernet0/0&lt;br&gt; ip address 172.16.1.1 255.255.255.0&lt;br&gt; ip nat inside&lt;br&gt; ip virtual-reassembly&lt;br&gt;!&lt;br&gt;interface Ethernet1/0&lt;br&gt; ip address 100.1.1.1 255.255.255.0&lt;br&gt; ip nat outside&lt;br&gt; ip virtual-reassembly&lt;br&gt; crypto map myvpn&lt;br&gt;!&lt;br&gt;ip classless&lt;br&gt;ip route 0.0.0.0 0.0.0.0 100.1.1.254&lt;br&gt;!&lt;br&gt;ip http server&lt;br&gt;no ip http secure-server&lt;br&gt;!&lt;br&gt;&lt;br&gt;!--- Except the private network from the NAT process:&lt;br&gt;&lt;br&gt;ip nat inside source list 175 interfa</description>

<item>
    <title>Ipsec с несколькими филиалами (walterwest7)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21176.html#3</link>
    <pubDate>Thu, 17 Jun 2010 09:55:52 GMT</pubDate>
    <description>Спасибo!&lt;br&gt;</description>
</item>

<item>
    <title>Ipsec с несколькими филиалами (karen durinyan)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21176.html#2</link>
    <pubDate>Thu, 17 Jun 2010 09:40:53 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;crypto map myvpn 10+n ipsec-isakmp &lt;br&gt;&amp;gt; set peer n.n.n.n &lt;br&gt;&amp;gt; set transform-set myset &lt;br&gt;&amp;gt;!--- Include the private-network-to-private-network traffic &lt;br&gt;&amp;gt;!--- in the encryption process: &lt;br&gt;&amp;gt;match address 10n &lt;br&gt;&amp;gt;! &lt;br&gt;&amp;gt;access-list 10x permit ip 172.16.1.0 0.0.0.255 10.x.1.0 0.0.0.255 &lt;br&gt;&amp;gt;... &lt;br&gt;&amp;gt;access-list 10n permit ip 172.16.1.0 0.0.0.255 10.n.1.0 0.0.0.255 &lt;br&gt;&lt;br&gt;and sure don&apos;t forget to exclude branch networks from the nat ACL&lt;br&gt;!&lt;br&gt;access-list 175 deny   ip 172.16.1.0 0.0.0.255 10.1.1.0 0.0.0.255&lt;br&gt;access-list 175 deny   ip 172.16.1.0 0.0.0.255 10.x.1.0 0.0.0.255&lt;br&gt;...&lt;br&gt;access-list 175 deny   ip 172.16.1.0 0.0.0.255 10.n.1.0 0.0.0.255&lt;br&gt;access-list 175 permit ip 172.16.1.0 0.0.0.255 any&lt;br&gt;&lt;br&gt;</description>
</item>

<item>
    <title>Ipsec с несколькими филиалами (karen)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21176.html#1</link>
    <pubDate>Thu, 17 Jun 2010 07:50:14 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;line con 0 &lt;br&gt;&amp;gt; exec-timeout 0 0 &lt;br&gt;&amp;gt;line aux 0 &lt;br&gt;&amp;gt;line vty 0 4 &lt;br&gt;&amp;gt; login &lt;br&gt;&amp;gt;! &lt;br&gt;&amp;gt;end &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;Тунель работает. Скажите пожалуйста, как теперь сюда добавить еще несколько тунелей с &lt;br&gt;&amp;gt;1841? &lt;br&gt;&lt;br&gt;crypto isakmp key ciscokey address x.x.x.x&lt;br&gt;...&lt;br&gt;crypto isakmp key ciscokey address n.n.n.n&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto map myvpn 10+x ipsec-isakmp &lt;br&gt; set peer x.x.x.x&lt;br&gt; set transform-set myset&lt;br&gt;!--- Include the private-network-to-private-network traffic&lt;br&gt;!--- in the encryption process:&lt;br&gt;match address 10x&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto map myvpn 10+n ipsec-isakmp &lt;br&gt; set peer n.n.n.n&lt;br&gt; set transform-set myset&lt;br&gt;!--- Include the private-network-to-private-network traffic&lt;br&gt;!--- in the encryption process:&lt;br&gt;match address 10n&lt;br&gt;!&lt;br&gt;access-list 10x permit ip 172.16.1.0 0.0.0.255 10.x.1.0 0.0.0.255&lt;br&gt;...&lt;br&gt;access-list 10n permit ip 172.16.1.0 0.0.0.255 10.n.1.0 0.0.0.255&lt;br&gt;</description>
</item>

</channel>
</rss>
