博威---云架构决胜云计算

 找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 1971|回复: 2

l2tp/ipsec remote access vpn on pix 7.2

[复制链接]
发表于 2007-5-4 15:53:46 | 显示全部楼层 |阅读模式
l2tp/ipsec remote access vpn on pix 7.2 [/td]
PIX Version 7.2(1)
!
interface Ethernet0
nameif outside
security-level 0
ip address 58.135.192.7 255.255.255.192
!
interface Ethernet1
nameif inside
security-level 100
ip address 10.0.0.254 255.255.255.0
!
access-list nonat permit ip 10.0.0.0 255.255.255.0 10.10.10.0 255.255.255.0
ip local pool l2tpoipsec 10.0.0.10-10.0.0.20 mask 255.255.255.0
route outside 0.0.0.0 0.0.0.0 58.135.192.62 1
nat (inside) 0 access-list nonat  //这个命令很重要,或者直接no nat-control
group-policy l2tpoipsec internal
group-policy l2tpoipsec attributes
dns-server value 202.106.116.1
vpn-tunnel-protocol IPSec l2tp-ipsec  //必须要加IPsec,只有l2tp-ipsec的话是拨不通的
default-domain value cisco.com
address-pools value l2tpoipsec
username l2tpoipsec password diVqlLvH/KThxao5xxZ8XA== nt-encrypted  //在password后面加个mschap,这个也是必须的
crypto ipsec transform-set l2tpoipsec esp-3des esp-md5-hmac  //就用3des吧和md5,windows不支持aes,而且据我查的那个sha1好像是40位的,可能和pix的sha加密位数不一样
crypto ipsec transform-set l2tpoipsec mode transport  //必须加,l2tp协议所定
crypto dynamic-map dyn 10 set transform-set l2tpoipsec
crypto map l2tpoipsec 10 ipsec-isakmp dynamic dyn
crypto map l2tpoipsec interface outside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des  //和windows端是匹配的
hash md5
group 2
lifetime 86400
tunnel-group DefaultRAGroup general-attributes  //这个很重要,一定要使用DefaultRAGroup,因为l2tp是不支持group的
default-group-policy l2tpoipsec
tunnel-group DefaultRAGroup ipsec-attributes
pre-shared-key *
tunnel-group DefaultRAGroup ppp-attributes
authentication ms-chap-v2

发表于 2008-2-26 12:46:52 | 显示全部楼层
什么玩意啊!
 楼主| 发表于 2008-2-26 12:54:34 | 显示全部楼层
要是高手话,就不用看了。晕晕
您需要登录后才可以回帖 登录 | 注册

本版积分规则

小黑屋|手机版|Archiver|boway Inc. ( 冀ICP备10011147号 )

GMT+8, 2024-11-24 11:56 , Processed in 0.086779 second(s), 16 queries .

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回复 返回顶部 返回列表