Codice: Seleziona tutto
crypto isakmp enable OUTSIDE
access-list INSIDE_NAT0 line 1 extended permit ip 172.26.65.0 255.255.255.0 192.168.0.0 255.255.255.0
access-list OUTSIDE_20_cryptomap line 1 extended permit ip 172.26.65.0 255.255.255.0 192.168.0.0 255.255.255.0
tunnel-group 1.1.1.1 type ipsec-l2l
tunnel-group 1.1.1.1 ipsec-attributes
pre-shared-key l2l10xhtw%
isakmp keepalive threshold 10 retry 2
crypto isakmp policy 10 authen pre-share
crypto isakmp policy 10 encrypt 3des
crypto isakmp policy 10 hash md5
crypto isakmp policy 10 group 2
crypto isakmp policy 10 lifetime 86400
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map OUTSIDE_map 20 match address OUTSIDE_20_cryptomap
crypto map OUTSIDE_map 20 set pfs group2
crypto map OUTSIDE_map 20 set peer 1.1.1.1
crypto map OUTSIDE_map 20 set transform-set ESP-3DES-MD5
crypto map OUTSIDE_map interface OUTSIDE
nat (INSIDE) 0 access-list INSIDE_NAT0 tcp 0 0 udp 0