2023年7月28日金曜日

DMVPN Cisco

 R1


Building configuration...


Current configuration : 1939 bytes

!

version 12.4

service timestamps debug datetime msec

service timestamps log datetime msec

no service password-encryption

!

hostname R1

!

boot-start-marker

boot-end-marker

!

!

no aaa new-model

memory-size iomem 5

no ip icmp rate-limit unreachable

ip cef

!

!

!

!

no ip domain lookup

!

multilink bundle-name authenticated

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

archive

 log config

  hidekeys

!

crypto isakmp policy 1

 encr 3des

 hash md5

 authentication pre-share

 group 2

crypto isakmp key cisco address 0.0.0.0 0.0.0.0

crypto isakmp keepalive 30

!

!

crypto ipsec transform-set dmvpnset esp-3des esp-md5-hmac 

!

crypto ipsec profile dmprofile

 set transform-set dmvpnset 

!

!

!

!

ip tcp synwait-time 5

!

!

!

!

interface Loopback0

 no ip address

!

interface Tunnel0

 ip address 172.31.255.1 255.255.255.0

 no ip redirects

 ip mtu 1368

 ip nhrp authentication dmcisco

 ip nhrp map multicast dynamic

 ip nhrp network-id 99

 ip nhrp holdtime 300

 ip ospf network broadcast

 tunnel source FastEthernet0/0

 tunnel mode gre multipoint

 tunnel key 10

 tunnel protection ipsec profile dmprofile

!

interface FastEthernet0/0

 ip address 64.100.1.100 255.255.255.0

 ip mtu 1454

 duplex auto

 speed auto

!

interface FastEthernet0/1

 ip address 172.16.10.1 255.255.255.0

 ip tcp adjust-mss 1328

 duplex auto

 speed auto

!

interface FastEthernet1/0

 no ip address

 shutdown

 duplex auto

 speed auto

!

interface FastEthernet2/0

 no ip address

 shutdown

 duplex auto

 speed auto

!

router ospf 1

 log-adjacency-changes

 network 172.16.0.0 0.0.0.255 area 0

 network 172.31.255.0 0.0.0.255 area 0

!

ip forward-protocol nd

ip route 0.0.0.0 0.0.0.0 FastEthernet0/0

!

!

no ip http server

no ip http secure-server

!

no cdp log mismatch duplex

!

!

!

!

!

!

control-plane

!

!

!

!

!

!

!

!

!

!

line con 0

 exec-timeout 0 0

 privilege level 15

 logging synchronous

line aux 0

 exec-timeout 0 0

 privilege level 15

 logging synchronous

line vty 0 4

 login

!

!

end


R1#

R2

ter len 0

R2#show run

Building configuration...


Current configuration : 1993 bytes

!

version 12.4

service timestamps debug datetime msec

service timestamps log datetime msec

no service password-encryption

!

hostname R2

!

boot-start-marker

boot-end-marker

!

!

no aaa new-model

memory-size iomem 5

no ip icmp rate-limit unreachable

ip cef

!

!

!

!

no ip domain lookup

!

multilink bundle-name authenticated

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

archive

 log config

  hidekeys

!

crypto isakmp policy 1

 encr 3des

 hash md5

 authentication pre-share

 group 2

crypto isakmp key cisco address 0.0.0.0 0.0.0.0

crypto isakmp keepalive 30

!

!

crypto ipsec transform-set dmvpnset esp-3des esp-md5-hmac 

!

crypto ipsec profile dmprofile

 set transform-set dmvpnset 

!

!

!

!

ip tcp synwait-time 5

!

!

!

!

interface Tunnel0

 ip address 172.31.255.2 255.255.255.0

 no ip redirects

 ip mtu 1368

 ip nhrp authentication dmcisco

 ip nhrp map multicast 64.100.1.100

 ip nhrp map 172.31.255.1 64.100.1.100

 ip nhrp network-id 99

 ip nhrp holdtime 300

 ip nhrp nhs 172.31.255.1

 ip ospf network broadcast

 ip ospf priority 0

 tunnel source FastEthernet0/0

 tunnel mode gre multipoint

 tunnel key 10

 tunnel protection ipsec profile dmprofile

!

interface FastEthernet0/0

 ip address 64.100.1.101 255.255.255.0

 ip mtu 1454

 duplex auto

 speed auto

!

interface FastEthernet0/1

 ip address 172.16.11.1 255.255.255.0

 ip tcp adjust-mss 1328

 duplex auto

 speed auto

!

interface FastEthernet1/0

 no ip address

 shutdown

 duplex auto

 speed auto

!

interface FastEthernet2/0

 no ip address

 shutdown

 duplex auto

 speed auto

!

router ospf 1

 log-adjacency-changes

 network 172.16.11.0 0.0.0.255 area 0

 network 172.31.255.0 0.0.0.255 area 0

!

ip forward-protocol nd

ip route 0.0.0.0 0.0.0.0 FastEthernet0/0

!

!

no ip http server

no ip http secure-server

!

no cdp log mismatch duplex

!

!

!

!

!

!

control-plane

!

!

!

!

!

!

!

!

!

!

line con 0

 exec-timeout 0 0

 privilege level 15

 logging synchronous

line aux 0

 exec-timeout 0 0

 privilege level 15

 logging synchronous

line vty 0 4

 login

!

!

end


R2#



R3

ter len 0

R3#show run

Building configuration...


Current configuration : 1993 bytes

!

version 12.4

service timestamps debug datetime msec

service timestamps log datetime msec

no service password-encryption

!

hostname R3

!

boot-start-marker

boot-end-marker

!

!

no aaa new-model

memory-size iomem 5

no ip icmp rate-limit unreachable

ip cef

!

!

!

!

no ip domain lookup

!

multilink bundle-name authenticated

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

!

archive

 log config

  hidekeys

!

crypto isakmp policy 1

 encr 3des

 hash md5

 authentication pre-share

 group 2

crypto isakmp key cisco address 0.0.0.0 0.0.0.0

crypto isakmp keepalive 30

!

!

crypto ipsec transform-set dmvpnset esp-3des esp-md5-hmac 

!

crypto ipsec profile dmprofile

 set transform-set dmvpnset 

!

!

!

!

ip tcp synwait-time 5

!

!

!

!

interface Tunnel0

 ip address 172.31.255.3 255.255.255.0

 no ip redirects

 ip mtu 1368

 ip nhrp authentication dmcisco

 ip nhrp map multicast 64.100.1.100

 ip nhrp map 172.31.255.1 64.100.1.100

 ip nhrp network-id 99

 ip nhrp holdtime 300

 ip nhrp nhs 172.31.255.1

 ip ospf network broadcast

 ip ospf priority 0

 tunnel source FastEthernet0/0

 tunnel mode gre multipoint

 tunnel key 10

 tunnel protection ipsec profile dmprofile

!

interface FastEthernet0/0

 ip address 64.100.1.102 255.255.255.0

 ip mtu 1454

 duplex auto

 speed auto

!

interface FastEthernet0/1

 ip address 172.16.12.1 255.255.255.0

 ip tcp adjust-mss 1328

 duplex auto

 speed auto

!

interface FastEthernet1/0

 no ip address

 shutdown

 duplex auto

 speed auto

!

interface FastEthernet2/0

 no ip address

 shutdown

 duplex auto

 speed auto

!

router ospf 1

 log-adjacency-changes

 network 172.16.12.0 0.0.0.255 area 0

 network 172.31.255.0 0.0.0.255 area 0

!

ip forward-protocol nd

ip route 0.0.0.0 0.0.0.0 FastEthernet0/0

!

!

no ip http server

no ip http secure-server

!

no cdp log mismatch duplex

!

!

!

!

!

!

control-plane

!

!

!

!

!

!

!

!

!

!

line con 0

 exec-timeout 0 0

 privilege level 15

 logging synchronous

line aux 0

 exec-timeout 0 0

 privilege level 15

 logging synchronous

line vty 0 4

 login

!

!

end


R3#wr

Building configuration...

[OK]

R3#



0 件のコメント:

GoogleAD