Cau Hinh Ip Tinh Cho Cac Cong Router

  • View
    87

  • Download
    3

Embed Size (px)

Text of Cau Hinh Ip Tinh Cho Cac Cong Router

1.C u hnh a ch ip cho cc c ng trn router 2. nh tun b ng OSPF 3.S d ng SDM c u hnh VPN cho Cisco router -Ti n hnh ci t SDM cho router EZVPN , m i ng i c th tham kh o t i y http://www.ttgtc.com/forum/showthread.php?t=11 login -By gi trn PC ta truy c p vo Web https://172.16.2.1 vo giao di n Web c a Router. Ta nh p username v password c ab c2 ch ng th c,sau khi ch ng th c thnh cng ta c giao di n c a SDM nh sau :

-Vo Edit > Preferences ch n Preview commands before delivering to router c th xem tr c l nh SDM s p chu n xu ng router c u

hnh

-Lm theo cc b c sau c u hnh EZVPN router tr thnh VPN server Ch n Configure > VPN > Easy VPN Server >Launch Easy VPN Server Wizard.

AAA ph i c enable trn VPN server,AAA l vi t t t c a Authentication (xc th c ), Accounting (c p quy n ),Accounting ( tnh c c ,log) .Ch n Yes ti p t c

Ch n Next t i Easy VPN Server Wizard.

Ch n interface m Cisco VPN client s k t n i VPN server,trong tr ng h p ny l S0/1/0

Ch n Next ch n Add

c u hnh Internet Key Exchange (IKE) Policy ,c th t o Policy m i

Click Next ch n transform set m c nh,ho c t o transform set m i .Trong tr ng h p ny chng ta ch n transform set m c nh

T i Ch n Local t i Group Authorization and Group Policy Lookup

Chon Local t i User Authentication

Add User Credenticals > thm user c tn l vpnuser c m t kh u la vpnuser v i privileage l 1 ch ng th c khi client vpn vo router

Nh n Next

Nh n Add nh p m i 1 Tunnel Group tn l vpn v i pre-share key l 123456 v pool ip thu c l p m ng c a PCVPN t 172.16.2.240 n 172.16.2.250

SDM s bo trng l p m ng v i PCVPN > OK

Ta c th xem l i ton b c u hnh t i y > Finish

Sau SDM s

y l nh xu ng router

4.Ci t ph n m m Cisco VPN Ki m tra a ch IP trn my VPN client

Sau t

my client th

ping

n VPN server

Ci t ph n m m Cisco VPN client v t o k t n i b ng cch ch n Connection Entries > New

n VPN server

Nh p thng tin v nh

sau :

Ch n k t n i VPN v a m i kh i t o ch n Connect

EZVPN server s yu c u ch ng th c ta s d ng vpnuser v m t kh u l vpnuser t o b c 1 ch ng th c :

Sauk khi ch ng th c thnh cng vpn client s c c p pht 1 a ch ip n m trong kho ng t 172.16.2.240 172.16.2.250 m ta c u hnh trn

T

vpn client th

ping

n cc m ng LAN

DN v HCM

Ki m tra l i b ng route t nh ct

nh tuy n trn EZVPN server ta s th y c 1 ng thm vo b ng nh tuy n

EZVPN#show ip route Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is 172.16.6.2 to network 0.0.0.0 172.16.0.0/16 is variably subnetted, 7 subnets, 2 masks S 172.16.2.240/32 [1/0] via 172.16.7.2 C 172.16.4.0/24 is directly connected, Serial0/2/1 C 172.16.5.0/24 is directly connected, Serial0/1/1 C 172.16.6.0/24 is directly connected, Serial0/1/0 O 172.16.1.0/24 [110/782] via 172.16.4.2, 00:31:23, Serial0/2/1 C 172.16.2.0/24 is directly connected, FastEthernet0/1 O 172.16.3.0/24 [110/782] via 172.16.5.2, 00:31:23, Serial0/1/1 S* 0.0.0.0/0 [1/0] via 172.16.6.2 Nh chng ta th y ,EZVPN s t ng t o ra 1 static route n 172.16.2.240 ,ip c a vpn client ,gip cho vpn cleint c th truy c p n ti nguyn c a cc m ng LAN bn trong router N,HCM