IPSec-VPN專(zhuān)題七:DMVPN-核心冗余架構(gòu)_第1頁(yè)
IPSec-VPN專(zhuān)題七:DMVPN-核心冗余架構(gòu)_第2頁(yè)
IPSec-VPN專(zhuān)題七:DMVPN-核心冗余架構(gòu)_第3頁(yè)
全文預(yù)覽已結(jié)束

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

DMVPN中使用多個(gè)NHS服務(wù)器,實(shí)現(xiàn)冗余:

1:R1/R2/R3/R4:直接配置路由可達(dá):?jiǎn)⒂肙SPF協(xié)議:

2:R1/R2/R3/R4:配置GRETunnel:(支持組播)

3:R1/R2/R3/R4:配置NHRP:

==>R1的配置:(主NHS)

interfaceTunnel0

ipaddress172.16.1.1255.255.255.0

noipredirects

ipnhrpnetwork-id10

ipnhrpmapmulticastdynamic

:從NHRP的注冊(cè)消息中指定組播發(fā)送的目的地址

tunnelsourceFastEthernet0/0

tunnelmodegremultipoint

tunnelkey123

end

==>R2的配置:(備份NHS)

interfaceTunnel0

ipaddress172.16.1.2255.255.255.0

ipnhrpmapmulticastdynamic

ipnhrpnetwork-id10

ipnhrpmap172.16.1.1202.101.1.1

:指定主NHS服務(wù)器,如果自己NHRP失敗,可以向172.16.1.1咨詢

ipnhrpnhs172.16.1.1

delay1000

tunnelsourceFastEthernet0/0

tunnelmodegremultipoint

tunnelkey123

end

==>Branch1的配置:

interfaceTunnel0

ipaddress172.16.1.3255.255.255.0

noipredirects

ipnhrpmap172.16.1.1202.101.1.1

ipnhrpmap172.16.1.2202.101.1.5

ipnhrpmapmulticast202.101.1.1

ipnhrpmapmulticast202.101.1.4

ipnhrpnetwork-id10

ipnhrpnhs172.16.1.1

:優(yōu)先級(jí)由Internet路由來(lái)決定:

ipnhrpnhs172.16.1.2

tunnelsourceFastEthernet0/0

tunnelmodegremultipoint

tunnelkey123

end

==>Branch2的配置:

interfaceTunnel0

ipaddress172.16.1.4255.255.255.0

noipredirects

ipnhrpmap172.16.1.1202.101.1.1

ipnhrpmap172.16.1.2202.101.1.5

ipnhrpmapmulticast202.101.1.1

ipnhrpmapmulticast202.101.1.4

ipnhrpnetwork-id10

ipnhrpnhs172.16.1.1

ipnhrpnhs172.16.1.2

tunnelsourceFastEthernet0/0

tunnelmodegremultipoint

tunnelkey123

end

4:R1/R2/R3/R4:在內(nèi)部網(wǎng)絡(luò)中啟用EIGRP協(xié)議:

==>根據(jù)EIGRP協(xié)議,在接口配置Feature:

interfaceTunnel0

noipnext-hop-selfeigrp90

noipsplit-horizoneigrp90

==>此時(shí)查看Branch1/2的路由:

Branch1#showiprouteeigrp

4.0.0.0/32issubnetted,1subnets

D

4.4.4.4[90/285084416]via172.16.1.4,00:00:01,Tunnel0

[90/285084416]via172.16.1.4,00:00:01,Tunnel0

D

192.168.1.0/24[90/284702976]via172.16.1.2,00:00:01,Tunnel0

[90/284702976]via172.16.1.1,00:00:01,Tunnel0

Branch2#showiprouteeigrp

3.0.0.0/32issubnetted,1subnets

D

3.3.3.3[90/285084416]via172.16.1.3,00:00:13,Tunnel0

[90/285084416]via172.16.1.3,00:00:13,Tunnel0

D

192.168.1.0/24[90/284702976]via172.16.1.2,00:02:47,Tunnel0

[90/284702976]via172.16.1.1,00:02:47,Tunnel0

5:R1/R2/R3/R4:配置IPSecVPN:

cryptoisakmppolicy10

authenticationpre-share

encrydes

group2

hashmd5

cryptoisakmpkeydmvpnaddress0.0.0.00.0.0.0

cryptoipsectransform-setDMVPNesp-desesp-md5-hmac

cryptoipsecprofiledmvpn-profile

settransform-setDMVPN

!

intt0

tunnelprotectionipsecprofiledmvpn-profile

6:測(cè)試:

R3pingR4:

Branch1#ping4.4.4.4soulo0

!!!!!

Branch1#showipnhrp

172.16.1.1/32via172.16.1.1,Tunnel0created00:19:34,neverexpire

Type:static,Flags:authoritativeused

NBMAaddress:202.101.1.1

172.16.1.2/32via172.16.1.2,Tunnel0created00:19:34,neverexpire

Type:static,Flags:authoritativeused

NBMAaddress:202.101.1.5

172.16.1.4/32via172.16.1.4,Tunnel0created00:01:24,expire01:47:52

Type:dynamic,Flags:router

NBMAaddress:1.1.45.4

Branch1#showcryptoengineconnactive

IDInterface

IP-Address

State

Algorithm

Encrypt

Decrypt

10FastEthernet0/0

1.1.35.3

set

HMAC_MD5+DES_56_CB

0

0

11Tunnel0

172.16.1.3

set

HMAC_MD5+DES_56_CB

0

0

2001Tunnel0

1.1.35.3

set

DES+MD5

0

0

2002Tunnel0

1.1.35.3

set

DES+MD5

33

0

2003FastEthernet0/0

1.1.35.3

set

DES+MD5

0

3

2004Tunnel0

1.1.35.3

set

DES+MD5

4

0

2005Tunnel0

1.1.35.3

set

DES+MD5

0

28

2006Tunnel0

1.1.35.3

set

DES

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

最新文檔

評(píng)論

0/150

提交評(píng)論