(outside) 1 172.17.63.210 !--- 去路由器的流量不做地址转换 nat (inside) 0 access-list nonat nat (inside) 1 10.1.1.0 255.255.255.0 0 0 conduit permit icmp any any route outside 0.0.0.0 0.0.0.0 172.17.63.209 1 !--- IPSec 策略: sysopt connection permit-ipsec crypto ipsec transform-set avalanche esp-des esp-md5-hmac crypto ipsec security-association lifetime seconds 3600 crypto map forsberg 21 ipsec-isakmp crypto map forsberg 21 match address ipsec <页码:[1] [2] [3] [4] [5] [6] 第2页、共6页 |