设为首页收藏本站language 语言切换
查看: 2449|回复: 0
收起左侧

[求助] vrf -aware ipsec vpn问题请教

[复制链接]
发表于 2014-1-14 20:40:50 | 显示全部楼层 |阅读模式
本帖最后由 jin544642965 于 2014-1-14 20:54 编辑

测试top如下:


其中ASR1上模拟vpn路由器,ASR2模拟企业路由器对接vpn;使用互联网段为 10.255.0.0/28
在ASR上开启lo0接口,配置到一个vrf中,为VIP3112;
ASR也开启lo0接口,进行模拟感兴趣流测试;

目前测试结果如下:
当ASR 1 lo0接口上划分到VIP3112时,ipsec vpn建立成功;但感兴趣流数据ping不通,发现只有site发起端数据包加密封装过去后对端site能够解密,但是没有回包;

当ASR 1 lo0 接口重新划到全局后,ipsec vpn建立成功;感兴趣流数据ping通;


配置如下:
ASR1006-1#
      
ip vrf VIP3112
rd 112:1
route-target export 112:1
route-target import 112:1

crypto keyring vpn3112  
  pre-shared-key address 10.255.0.4 key cisco
crypto isakmp policy 1
hash md5
authentication pre-share
crypto isakmp keepalive 20
crypto isakmp profile vpn3112
   vrf VIP3112
   keyring vpn3112
   match identity address 10.255.0.4 255.255.255.255
crypto ipsec transform-set zuoyb esp-des esp-md5-hmac
mode tunnel
crypto map zuoyb 10 ipsec-isakmp
set peer 10.255.0.4
set transform-set zuoyb
set isakmp-profile vpn3112
match address 112
interface Loopback0
ip vrf forwarding VIP3112
ip address 10.100.241.100 255.255.255.0
interface TenGigabitEthernet1/2/0
ip address 10.255.0.1 255.255.255.240
cdp enable
crypto map zuoyb
ip route 0.0.0.0 0.0.0.0 10.255.0.4 100 name test-vpn
ip route vrf VIP3112 0.0.0.0 0.0.0.0 10.255.0.4 global
access-list 112 permit ip 10.100.241.0 0.0.0.255 192.168.1.0 0.0.0.255

------------------------------------------------------------------------------------------
ASR1006-2#

crypto isakmp policy 1
hash md5
authentication pre-share
group 2
crypto isakmp keepalive 20
crypto isakmp profile vip3112
   keyring vip3112
   match identity address 10.255.0.1 255.255.255.255
crypto ipsec transform-set zuoyb esp-des esp-md5-hmac
mode tunnel
crypto map zuoyb 10 ipsec-isakmp
set peer 10.255.0.1
set transform-set zuoyb
match address 112
interface Loopback0
ip address 192.168.1.100 255.255.255.0
interface TenGigabitEthernet1/2/0
ip address 10.255.0.4 255.255.255.240
cdp enable
crypto map zuoyb
ip route 0.0.0.0 0.0.0.0 10.255.0.1
ip route 192.168.1.0 255.255.255.0 10.110.10.253
access-list 112 permit ip 192.168.1.0 0.0.0.255 10.100.241.0 0.0.0.255

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?论坛注册

x
您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2026-6-26 03:32 , Processed in 0.057284 second(s), 10 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表