You are on page 1of 2

punto a punto asa1 config)#access-list LAN1-to-LAN2 extended permit ip 192.168.1.0 255.255.255.0 19 2.168.2.0 255.255.255.

0 (config)#access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168. 2.0 255.255.255.0 (config)#nat (inside) 0 access-list NONAT (config)# isakmp policy 10 (config-isakmp-policy)# encryption aes (config-isakmp-policy)# hash sha (config-isakmp-policy)# authentication pre-share (config-isakmp-policy)# group 2 (config-isakmp-policy)# lifetime 3600 (config)# isakmp enable outside (config)# isakmp identity address (config)# tunnel-group 200.200.200.1 type ipsec-l2l (config)# tunnel-group 200.200.200.1 ipsec-attributes (config-tunnel-ipsec)# pre-shared-key somestrongkey (config)# crypto ipsec transform-set ASA1TS esp-aes-192 esp-sha-hmac (config)# crypto map ASA1VPN 10 match address LAN1-to-LAN2 (config)# crypto map ASA1VPN 10 set peer 200.200.200.1 (config)# crypto map ASA1VPN 10 set transform-set ASA1TS (config)# crypto map ASA1VPN 10 set security-association lifetime seconds 36000 (config)# crypto map ASA1VPN interface outside --------------------------------------------------------------------asa2 config)#access-list LAN2-to-LAN1 extended permit ip 192.168.2.0 255.255.255.0 19 2.168.1.0 255.255.255.0 (config)#access-list NONAT extended permit ip 192.168.2.0 255.255.255.0 192.168. 1.0 255.255.255.0 (config)#nat (inside) 0 access-list NONAT (config)# isakmp policy 10 (config-isakmp-policy)# encryption aes (config-isakmp-policy)# hash sha (config-isakmp-policy)# authentication pre-share (config-isakmp-policy)# group 2 (config-isakmp-policy)# lifetime 3600 (config)# isakmp enable outside (config)# isakmp identity address (config)# tunnel-group 100.100.100.1 type ipsec-l2l (config)# tunnel-group 100.100.100.1 ipsec-attributes (config-tunnel-ipsec)# pre-shared-key somestrongkey (config)# (config)# (config)# (config)# (config)# (config)# crypto crypto crypto crypto crypto crypto ipsec transform-set ASA2TS esp-aes-192 esp-sha-hmac map ASA2VPN 10 match address LAN2-to-LAN1 map ASA2VPN 10 set peer 100.100.100.1 map ASA2VPN 10 set transform-set ASA2TS map ASA2VPN 10 set security-association lifetime seconds 36000 map ASA2VPN interface outside

para realizar pruebas ,...... show crypto isakmp sa

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------accesso remoto asa1 config)# ip local pool VPNPOOL 192.168.20.1-192.168.20.254 config)# vpn-addr-assign local config)# access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168. 20.0 255.255.255.0 ASA-config)# nat (inside) 0 access-list NONAT config)# group-policy config)# group-policy config-group-policy)# config-group-policy)# config-group-policy)# company-vpn-policy internal company-vpn-policy attributes vpn-idle-timeout 30 dns-server value 192.168.1.5 wins-server value 192.168.1.6

config)# username user password 1234 config)# isakmp policy config-isakmp-policy)# config-isakmp-policy)# config-isakmp-policy)# config-isakmp-policy)# config)# isakmp enable 20 encryption 3des hash sha authentication pre-share group 2 ASA-1(config-isakmp-policy)# lifetime 3600 outside

config)# tunnel-group vpnclient type remote-access config)# tunnel-group vpnclient general-attributes config-tunnel-general)# address-pool VPNPOOL config-tunnel-general)# default-group-policy company-vpn-policy config)# tunnel-group vpnclient ipsec-attributes config-tunnel-ipsec)# pre-shared-key groupkey123

You might also like