IPSEC VPN SITE TO SITE
wsecven, GRE
vee t6e 1928 = 1513) 094 <7 199,1682028
re eS 3 |
inh 1
1. M6
‘ra hai site, ckim bio mang LAN thuge SAIGON va VUNGTAU e6 thé
Thue hi
giao tigp duge vsi nhaw.
2. Clu hinh
chin sich pha 1). /'SAKMP- QUAN LY
Bude 1: Cau hinh chinh sich TKI
Teaknp policy 10
mp) #hash md thudttosn hash
on des /!thudt toanma hoa
2 iN 600 d6i khéa_ 36 nhém (version) Ditfio- Hollman,
hare 1! Phyong thie china thus.
Buse 2: Xac dinh théng tin key
4 peer,
wareni2s address 151.1.1.1 /oung khéa chia sé: ware) 123
pon dau xa
SAIGON (config) fezypee ieakep
Buse 3: Cin hinh chinh sich IPSec (chinh sich pha 2),
‘ing bio vé di, Thidt lip IPSec SA dua tin nhimng théng 86 cla phase 1
+ chon giao thre ESP de doing gor dl
ip 182.168.1.0 0.0,0,258 192.168.2.0
1 ip local - branch 1 WVip local - branch 4
Tiss 100 perm:
1/10- QUAN LY, cho m6i Peer
gered.
1.1.1 (tunnel ?) port outedich <=> dau xa
ransforn-set MYSET
88 100 khéc nhau cho mbi Peer, didu kign
ap HYMAP
Cée bude Kim trong ty én VUN
TAU
ee utng Carscamerinterface Loopback0
ip address
2.0
0.0.0.255
192.168.1.0 0.0.0,.255
ee utng CarscamerSau khi két ndi VPN duc
Trang thai isakmp sa
1002 ° ACTIVE
fpkts encaps
fpkts decaps: 9, Hpkts decrypt: 9, Epkts veril
= a
inbound ep saz st dung che 963 at
spi: 0x7507C194 (1963442580) Bag |
ee utng Carscameroutbound esp sas: A st dung
spi: Ox1ALGGDES (437677544) =>Tuona
Is-hmac
inbound cia peer
lite
outbound ah
outhoun
Ame: 00:01:
vrf: (none)
1,1,1/500 2
onnid:1001 iifetime:23:56:13
FLOW: permit ip 192.168.1.0/255.255.255.0 192.168.2.0/255.255.255.0
wong dic
ceypto map
nts dected @ drop
pkts enc'ed 9 drop
(KB/Sec) 4569737/3493
(K8/Sec)_ 4559737/3493
$6 long két ndi dirge mo ( 1 IKE va 2 IPSec):
v4 Crypto Toa
ast ate
det stat: mi-id slot status
s2-1.1150.1.2.1 11no stare 10010 ACTIVE (deleted)
Trong qua trinh cf hinh, e6 thé ding eau Ktnh debug crypto isakmp dé
iem tra tien trinh
ee utng Carscamer