亚洲激情专区-91九色丨porny丨老师-久久久久久久女国产乱让韩-国产精品午夜小视频观看

溫馨提示×

溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊×
其他方式登錄
點擊 登錄注冊 即表示同意《億速云用戶服務條款》

ISAKMP Profile技術應用

發布時間:2020-08-02 02:15:09 來源:網絡 閱讀:2332 作者:超哥2018 欄目:安全技術

ISAKMP Profile技術應用






ISAKMP Profile技術是IKE協商的一種新型配置方式。它主要的作用是映射我們第一階段ISAKMP參數到第

二階段IPSec隧道,可以實現一個設備和多個站點建立多個隧道。還可以很好的消除不同×××之間的影

響,讓第一階段策略和第二階段策略關聯的更加緊密。并且ISAKMP Profile普遍在EZ×××和VRF-ware 

IPSec ×××配置里邊被采用。


Site1

crypto keyring ccie 

  pre-shared-key address 61.128.1.1 key cisco

!

crypto isakmp policy 100

 encr 3des

 authentication pre-share

 group 2

crypto isakmp profile isaprof

   keyring ccie

   match identity address 61.128.1.1 255.255.255.255 

!

!

crypto ipsec transform-set myset esp-3des esp-sha-hmac 

!

crypto map ccie 10 ipsec-isakmp 

 set peer 61.128.1.1

 set transform-set myset 

 set isakmp-profile isaprof

 match address ***

!

interface Loopback0

 ip address 1.1.1.1 255.255.255.0

!

interface FastEthernet0/0

 ip address 202.100.1.1 255.255.255.0

 crypto map ccie

!      

ip route 0.0.0.0 0.0.0.0 202.100.1.10

!

ip access-list extended ***

 permit ip 1.1.1.0 0.0.0.255 2.2.2.0 0.0.0.255


Internet

interface FastEthernet0/0

 ip address 202.100.1.10 255.255.255.0

!

interface FastEthernet0/1

 ip address 61.128.1.10 255.255.255.0


end


Site2:

crypto keyring ccie 

  pre-shared-key address 202.100.1.1 key cisco

!

crypto isakmp policy 100

 encr 3des

 authentication pre-share

 group 2

crypto isakmp profile isaprof

   keyring ccie

   match identity address 202.100.1.1 255.255.255.255 

!

!

crypto ipsec transform-set myset esp-3des esp-sha-hmac 

!

crypto map ccie 10 ipsec-isakmp 

 set peer 202.100.1.1

 set transform-set myset 

 set isakmp-profile isaprof

 match address ***

!


interface Loopback0

 ip address 2.2.2.2 255.255.255.0

!

interface FastEthernet0/0

 ip address 61.128.1.1 255.255.255.0

 crypto map ccie

!     

ip forward-protocol nd

ip route 0.0.0.0 0.0.0.0 61.128.1.10

!

ip access-list extended ***

 permit ip 2.2.2.0 0.0.0.255 1.1.1.0 0.0.0.255

!

測試

Site1#ping 2.2.2.2 source lo0               


Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:

Packet sent with a source address of 1.1.1.1 

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 104/133/148 ms


Site1#show crypto ipsec sa


interface: FastEthernet0/0

    Crypto map tag: ccie, local addr 202.100.1.1


   protected vrf: (none)

   local  ident (addr/mask/prot/port): (1.1.1.0/255.255.255.0/0/0)

   remote ident (addr/mask/prot/port): (2.2.2.0/255.255.255.0/0/0)

   current_peer 61.128.1.1 port 500

     PERMIT, flags={origin_is_acl,}

    #pkts encaps: 9, #pkts encrypt: 9, #pkts digest: 9

    #pkts decaps: 9, #pkts decrypt: 9, #pkts verify: 9

    #pkts compressed: 0, #pkts decompressed: 0

    #pkts not compressed: 0, #pkts compr. failed: 0

    #pkts not decompressed: 0, #pkts decompress failed: 0

    #send errors 1, #recv errors 0


     local crypto endpt.: 202.100.1.1, remote crypto endpt.: 61.128.1.1

     path mtu 1500, ip mtu 1500, ip mtu idb FastEthernet0/0

     current outbound spi: 0x96AB8F14(2527825684)


     inbound esp sas:

      spi: 0xF41D2511(4095550737)

        transform: esp-3des esp-sha-hmac ,

        in use settings ={Tunnel, }

        conn id: 1, flow_id: SW:1, crypto map: ccie

        sa timing: remaining key lifetime (k/sec): (4566332/2033)

        IV size: 8 bytes

        replay detection support: Y

        Status: ACTIVE


     inbound ah sas:


     inbound pcp sas:


     outbound esp sas:

      spi: 0x96AB8F14(2527825684)

        transform: esp-3des esp-sha-hmac ,

        in use settings ={Tunnel, }

        conn id: 2, flow_id: SW:2, crypto map: ccie

        sa timing: remaining key lifetime (k/sec): (4566332/2031)

        IV size: 8 bytes

        replay detection support: Y

        Status: ACTIVE


     outbound ah sas:


     outbound pcp sas:


Site1#show crypto session 

Crypto session current status


Interface: FastEthernet0/0

Profile: isaprof

Session status: UP-ACTIVE     

Peer: 61.128.1.1 port 500 

  IKE SA: local 202.100.1.1/500 remote 61.128.1.1/500 Active 

  IPSEC FLOW: permit ip 1.1.1.0/255.255.255.0 2.2.2.0/255.255.255.0 

        Active SAs: 2, origin: crypto map


向AI問一下細節

免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。

AI

台山市| 都江堰市| 正定县| 湘潭市| 临沧市| 成都市| 水富县| 泌阳县| 鄱阳县| 广宗县| 遵义市| 鄂伦春自治旗| 东至县| 张家口市| 湄潭县| 西吉县| 泰安市| 桑日县| 克拉玛依市| 垦利县| 大关县| 左贡县| 广南县| 高陵县| 巴中市| 南溪县| 云阳县| 临澧县| 长垣县| 方正县| 大同市| 加查县| 高唐县| 宁蒗| 大关县| 原阳县| 宜春市| 准格尔旗| 新源县| 什邡市| 和龙市|