实施的技术:×××、隧道、ospf
 
解决问题:总部和分部之间通过Internet来实现运行相同的路由协议
 
拓扑结构
构建企业内联网_职场
 
 
各个路由器的命令如下:
R1命令:
r1>en
r1#config t
r1(config)#interface f0/0
r1(config-if)#ip add 192.168.1.1 255.255.255.0
r1(config-if)#no shutdown
r1(config-if)#int s1/0
r1(config-if)#ip add 100.100.100.1 255.255.255.0
r1(config-if)#no shutdown
r1(config-if)#exit
r1(config)#ip route 0.0.0.0 0.0.0.0 s1/0
r1(config)#crypto isakmp enable
r1(config)#crypto isakmp policy 1
r1(config-isakmp)#authentication pre-share
r1(config-isakmp)#encryption 3des
r1(config-isakmp)#group 2
r1(config-isakmp)#hash sha
r1(config-isakmp)#exit
r1(config)#crypto isakmp key 123 address 100.100.102.2
r1(config)#access-list 101 permit icmp 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
r1(config)#access-list 101 permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
r1(config)#crypto ipsec transform-set aaa ah-md5-hmac esp-3des
r1(cfg-crypto-trans)#exit
r1(config)#crypto map ccc 1 ipsec-isakmp
r1(config-crypto-map)#match address 101
r1(config-crypto-map)#set peer 100.100.102.2
r1(config-crypto-map)#set transform-set aaa
r1(config-crypto-map)#exit
r1(config)#int s1/0
r1(config-if)#crypto map ccc
r1(config-if)exit
r1(config)#crypto isakmp policy 2
r1(config-isakmp)#authentication pre-share
r1(config-isakmp)#encryption des
r1(config-isakmp)#hash md5
r1(config-isakmp)#group 1
r1(config-isakmp)#exit
r1(config)#crypto isakmp key 456 address 100.100.101.2
r1(config)#access-list 102 permit icmp 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
r1(config)#access-list 102 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
r1(config)#crypto ipsec transform-set bbb ah-sha-hmac esp-des
r1(cfg-crypto-trans)#exit
r1(config)#crypto map ccc 2 ipsec-isakmp
r1(config-crypto-map)#match address 102
r1(config-crypto-map)#set transform-set bbb
r1(config-crypto-map)#set peer 100.100.101.2
r1(config-crypto-map)#exit
r1(config)#exit
r1#(config)interface Tunnel0
r1(config-if)ip address 2.2.2.1 255.255.255.0
r1(config-if)tunnel source s1/0
r1(config-if)tunnel destination 100.100.102.2
r1(config-if)exit
r1#(config)interface Tunnel1
r1(config-if)ip address 3.3.3.1 255.255.255.0
r1(config-if)tunnel source s1/0
r1(config-if)tunnel destination 100.100.101.2
r1(config-if)exit
r1(config)router ospf 1
r1(config-router)network 192.168.1.0 0.0.0.255 area 0
r1(config-router)network 2.2.2.0 0.0.0.255 area 2
r1(config-router)network 3.3.3.0 0.0.0.255 area 1
r1(config-routre)default-information originate
r1(config-router)exit
r1(config)exit
r1#wr
R2路由器命令
r2>en
r2#conf t
r2(config)#interface s0/0
r2(config-if)#ip add 100.100.100.2 255.255.255.0
r2(config-if)#no shutdown
r2(config-if)#int s0/1
r2(config-if)#ip add 100.100.101.1 255.255.255.0
r2(config-if)#no shutdown
r2(config-if)#int s0/2
r2(config-if)#ip add 100.100.102.1 255.255.255.0
r2(config-if)#no shutdown
r2(config-if)#exit
r2(config)exit
r2#wr
R3路由器命令
r3>en
r3#conf t
r3(config)#interface f0/0
r3(config-if)#ip add 192.168.2.1 255.255.255.0
r3(config-if)#no shutdown
r3(config-if)#int s1/0
r3(config-if)#ip add 100.100.101.2 255.255.255.0
r3(config-if)#no shutdown
r3(config-if)#exit
r3(config)#ip route 0.0.0.0 0.0.0.0 s1/0
r3(config)#crypto isakmp enable
r3(config)#crypto isakmp policy 2
r3(config-isakmp)#authentication pre-share
r3(config-isakmp)#hash md5
r3(config-isakmp)#group 1
r3(config-isakmp)#exit
r3(config)#crypto isakmp key 456 address 100.100.100.1
r3(config)#access-list 102 permit icmp 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
r3(config)#access-list 102 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
r3(config)#crypto ipsec transform-set bbb ah-sha-hmac esp-des
r3(cfg-crypto-trans)#exit
r3(config)#crypto map ccc 2 ipsec-isakmp
r3(config-crypto-map)#match address 102
r3(config-crypto-map)#set peer 100.100.100.1
r3(config-crypto-map)#set transform-set bbb
r3(config-crypto-map)#exit
r3(config)#interface s1/0
r3(config-if)#crypto map ccc
r3(config-if)exit
r3(config)interface Tunnel 1
r3(config-if)ip address 3.3.3.2 255.255.255.0
r3(config-if)tunnel source s1/0
r3(config-if)tunnel destination 100.100.100.1
r3(config-if)exit
r3(config)router ospf 1
r3(config-router)network 192.168.3.0 0.0.0.255 area 1
r3(config-router)network 3.3.3.0 0.0.0.255 area 1
r3(config-routre)default-information originate
r3(config-router)exit
r3(config)exit
r3#wr
R4路由器命令
r4>en
r4#conf t
r4(config)#int f0/0
r4(config-if)#ip add 192.168.3.1 255.255.255.0
r4(config-if)#no shutdown
r4(config-if)#int s1/0
r4(config-if)#ip add 100.100.102.2 255.255.255.0
r4(config-if)#no shutdown
r4(config-if)#exit
r4(config)#ip route 0.0.0.0 0.0.0.0 s1/0
r4(config)#cry isakmp enable
r4(config)#crypto isakmp policy 1
r4(config-isakmp)#authentication pre-share
r4(config-isakmp)#encryption 3des
r4(config-isakmp)#group 2
r4(config-isakmp)#hash sha
r4(config-isakmp)#exit
r4(config)#crypto isakmp key 123 address 100.100.100.1
r4(config)#access-list 101 permit icmp 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
r4(config)#access-list 101 permit ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
r4(config)#crypto ipsec transform-set aaa ah-md5-hmac esp-3des
r4(cfg-crypto-trans)#exit
r4(config)#crypto map ccc 1 ipsec-isakmp
r4(config-crypto-map)#match Address 100.100.100.1
r4(config-crypto-map)#match address 101
r4(config-crypto-map)#set peer 100.100.100.1
r4(config-crypto-map)#set transform-set aaa
r4(config-crypto-map)#exit
r4(config)#int s1/0
r4(config-if)#crypto map ccc
r4(config-if)#exit
r4#(config)interface Tunnel1
r4(config-if)ip address 3.3.3.2 255.255.255.0
r4(config-if)tunnel source s1/0
r4(config-if)tunnel destination 100.100.100.1
r4(config-if)exit
r4(config)router ospf 1
r4(config-router)network 192.168.3.0 0.0.0.255 area 2
r4(config-router)network 2.2.2.0 0.0.0.255 area 2
r4(config-routre)default-information originate
r4(config-router)exit
r4(config)exit
r4#wr
 
通过以上配置就可以在R1、R3、R4上看见全部内部网络的路由信息
 
里面有什么地方看不懂的
留言!!!