HQ#sh run
Building configuration...
Current configuration : 2813 bytes
!
version 12.4
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname HQ
!
!
!
!
ip dhcp excluded-address 10.0.0.33
ip dhcp excluded-address 10.0.0.63
!
ip dhcp pool HQDHCP
network 10.0.0.32 255.255.255.224
default-router 10.0.0.33
dns-server 3.3.3.2
!
!
!
crypto isakmp policy 50
encr aes 128
authentication pre-share
group 2
!
crypto isakmp key gaga address 70.0.0.2
!
!
crypto ipsec transform-set VPN esp-aes 128 esp-sha-hmac
!
crypto map VPN_MAP 50 ipsec-isakmp
set peer 70.0.0.2
set transform-set VPN
match address IPSec
!
!
!
no ip domain-lookup
!
!
!
!
!
!
interface Loopback0
ip address 20.0.0.1 255.255.255.0
!
interface Tunnel0
ip address 192.168.2.1 255.255.255.0
tunnel source Serial0/3/0
tunnel destination 1.1.1.2
!
!
interface Tunnel1
ip address 192.168.3.1 255.255.255.0
tunnel source Serial0/3/0
tunnel destination 3.3.3.2
!
!
interface FastEthernet0/0
no ip address
duplex auto
speed auto
!
interface FastEthernet0/0.1
encapsulation dot1Q 1 native
ip address 10.0.0.65 255.255.255.224
ip nat inside
!
interface FastEthernet0/0.10
encapsulation dot1Q 10
ip address 10.0.0.1 255.255.255.224
ip nat inside
!
interface FastEthernet0/0.20
encapsulation dot1Q 20
ip address 10.0.0.33 255.255.255.224
ip nat inside
!
interface FastEthernet0/1
no ip address
duplex auto
speed auto
shutdown
!
interface Serial0/1/0
no ip address
encapsulation frame-relay
!
interface Serial0/1/0.102 point-to-point
ip address 11.0.1.1 255.255.255.0
frame-relay interface-dlci 102
!
interface Serial0/1/0.103 point-to-point
ip address 11.0.2.1 255.255.255.0
frame-relay interface-dlci 103
!
interface Serial0/1/0.104 point-to-point
ip address 11.0.3.2 255.255.255.0
frame-relay interface-dlci 104
!
interface Serial0/3/0
ip address 2.2.2.2 255.255.255.252
ip nat outside
crypto map VPN_MAP
!
interface Vlan1
no ip address
shutdown
!
router eigrp 1
passive-interface FastEthernet0/0
passive-interface FastEthernet0/0.1
passive-interface FastEthernet0/0.10
passive-interface FastEthernet0/0.20
network 192.168.2.0
network 10.0.0.0 0.0.0.255
network 192.168.3.0
no auto-summary
!
router ospf 1
log-adjacency-changes
network 11.0.1.0 0.0.0.255 area 0
network 11.0.2.0 0.0.0.255 area 0
network 10.0.0.0 0.0.0.255 area 0
!
ip nat inside source list NAT interface Serial0/3/0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 2.2.2.1
ip route 0.0.0.0 0.0.0.0 Serial0/1/0.104 2
!
!
ip access-list extended IPSec
permit ip 10.0.0.0 0.0.0.255 192.168.7.0 0.0.0.255
ip access-list extended NAT
deny ip 10.0.0.0 0.0.0.255 192.168.7.0 0.0.0.255
permit ip 10.0.0.0 0.0.0.255 any
ip access-list extended IPsec
!
!
!
!
!
line con 0
logging synchronous
line vty 0 4
login
!
!
ntp server 3.3.3.4 key 0
!
end
ერთი რაუტერის Running Config გაქვს, დაგჩა ..... ბევრი