我有两个 Cisco 2921,它们使用静态加密映射运行站点到站点。一切似乎都很简单。很多人都这样做。我通常不会遇到这个问题。今天,VPN 刚刚决定它不想工作。我已经检查了两端的三重阶段 1 和阶段 2,我已经从头开始重建了两个路由器配置。我昨天跑步。什么?我觉得这只是奇怪的行为。
他们在第一阶段失败了。
其他人有这样的问题吗?
我会为后代发布我的配置:
Router-A
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key xyz address 50.xx.xx.xx
crypto ipsec transform-set VPN_SET esp-3des esp-md5-hmac
mode tunnel
crypto map S2S_VPN 1 ipsec-isakmp
description S2S VPN to Home Motors
set peer 50.xx.xx.xx
set transform-set VPN_SET
set pfs group1
match address VPN_ACL
ip access-list extended PRC_HM_VPN_ACL
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
Router-B
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key xyz address 206.xx.xx.xx
crypto ipsec transform-set S2S_SET esp-3des esp-md5-hmac
mode tunnel
crypto map S2S_VPN 1 ipsec-isakmp
description S2S VPN to Paso Robles Chevrolet
set peer 206.xx.xx.xx
set transform-set S2S_SET
set pfs group1
match address VPN_ACL
ip access-list extended VPN_ACL
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
permit ip 10.x.x.0 0.0.0.255 10.x.x.0 0.0.0.255
以及应用于具有匹配 IP 的适当外部接口的加密映射