<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[往事如风]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[一路走来,历经风雨,是非成败,转眼间。  人生几何,岁月如梭,还看明朝,会更好。]]></description>
<link>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[我的IT之路]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/7def3a5022d0686885352491.html]]></link>
        <description><![CDATA[
		
		<div><font style="background-color: #fffff0" face="FangSong_GB2312"><font size="5"><font color="#000000">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  最近网络上都在流传个人的人生经历.我的程序员之路,我的网工之路呀.看着他们写的个人经历.我也就写写我的IT之路.说说我是怎么走到现在这条路的。<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  首先要说说我的文化水平。只读了高中一年级，为什么我连高中都没有读完了？这其中的原委是这样的：我2002年初中毕业，进入了我们那儿一所比较不错的高中学校，一般上这个学校的大多数学生都能很顺利的读大学的。当时心想，算是能够跨进大学门槛了。但是天不如人愿呀。高一下学期。我就一直感觉身体不适，学习情绪也学了。终于在一次高烧３９度一夜之后，我连思想都烧的模糊了，不知道是怎么自己是怎么走到医院的，在医院住院一住就是半个月。出院之后，从此心灰意冷，很是害怕学校那个环境，怕进学校。就这样我结束了我的学习旅程。有家进行疗养，身体的和心理的。<br>
　　０４年，我１７岁。我随着一个亲戚来到苏州打工。在工地上做水电安装。在这儿一干就是两年。其中也吃了不少苦。经常要抬水管子，和重的设备，没办法，只能硬着头皮抬。肩膀红了一道又一道。人也被压伤了。所以我的个子比较低。１米７还差一点。两年中我吃了不少的苦，其实我迷茫过。失望过。后悔过　。<br>
　　谁都不知道以后的日子是怎么样的。就在０５年１０月家里打电话，就我回去去体检。说我被抽上当兵名额了。连我都不相信。我的入伍之路会是一路顺风，一个村十几个人，经过体验，政审之后。居然就我一个人比较符合。就这样。０５年１２月份进入了部队。这儿，曾经很梦寐想来的地方。我终于穿上了军装。<br>
　　说到现在好像离题了。说的是我的IT 之路，怎么一点也不和IT相关呢？<br>
　　到部队首先要新兵三个月的训练。之中吃的苦我也不多说了。可以这样说，我吃过了从未经历的苦。吃苦也不是白吃了。在新兵下连时。我被分到了我们的网络中心，从事网络管理方面的工作。同批之中，就我和另一个兄弟。我想我是很幸运的。<br>
　　从此之后，我的生活中就有了电脑。之后是去上级机关进行专业学习，说是专业学习，几个月时间人家就交了个五笔打字。其他什么依然是不会。<br>
　　回到单位后，我才真正进入了我的学习之路。记得我第一次到机房去，班长问我怎样查看网络通断，我不知道。他交了我一个ping命令。这是我学的第一个命令。所以我记得很清楚。跟着班长后面，我学了不少东西，熟悉了设备，可以自己独自值班，处理故障了。就这样，我入伍的第一年过的很充实。每天都在进步。值班闲的时候，我就买了好几本书自己看看。有计算机基础，计算机网络。通讯基础等。<br>
　　转眼进入了第二年。也就是去年了，这一年也是我学习的关键之年。由于我们这进行网络改造，但是只有我们班几个人自己做。我从做水晶头开始，到网络测试。故障排除，主要是在硬件上面。其中积累了不少经验。许多事情只有做过才知道的。后来我们这又要做网络视频监控，要架服务器。我对这个不懂。没办法，我只有学。我买了一本《网络工程师教程》，一本《服务器架设指南》两本书，学会了架iss网站。学会了用SQLserver数据库。把我们这视频监控从架摄像头到服务器架设，软件配置都学会了。这也就花了三个月的时间。渐渐的，我也成了我们班的技术骨干，许多别人不能解决的问题，我都努力研究，解决它。这样不紧解决了问题，自己更是学到了知识。在训练，工作之余。我就啃《网络工程师教程》，这本书写的理论太深，很多地方都看不懂。又找不到人。但是经过我慢慢细究，也弄懂了许多玄机。包括数据通信基础，TCP/IP，局域网和接入网知识。路由交机知识。学习了简单的交换机，路由器设置。<br>
　　我发现，我越是学习，我越发现的知识很单一。许多东西理论上是这样，但实际上又是另一个样子。而且我一个人学习，又不能和别人交流。我们那不能上网的。只能上上部队的局域网，那上面什么都没有。许多问题都没办法解决。又找不到资料。<br>
　　就这样。到了2007年的１１月份。这是一个难忘的月份。我结束了我２年的军旅生活。回到了老家。回到家我依然是什么都没有。但是我相信，我凭着我的知识，我的学习能力，我应该能够找一份工作的。从１２月我就来到了南京。我以前一个同学这，想谋份工作。来到外面，才发现我以前学的知识是多么的少。网络的知识是太多。简直是无从学起。在这儿，知道了许多业界的知识。行情。<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  今年3月份，我应聘进入了南京一家大酒店，在这里做网络管理员。负责服务器日常运行，网络维护，程控交换机维护，和其他弱电的维护。在这里我用上了以前很多自觉的知识。同时也学到了许多新的知识。<br>
现在我正常学习linux。<br>
&nbsp;&nbsp;&nbsp;&nbsp;  我相信我的道路会越走越宽的。一切都源自学习。</font><br>
</font></font></div> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/7def3a5022d0686885352491.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/%C4%AC%C8%CF%B7%D6%C0%E0">默认分类</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/7def3a5022d0686885352491.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-20  00:01</pubDate>
        <category><![CDATA[默认分类]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/7def3a5022d0686885352491.html</guid>
</item>

<item>
        <title><![CDATA[点对多点VPN实验]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/9d399c6d06ce35f342169472.html]]></link>
        <description><![CDATA[
		
		<p style="text-align: center"><img src="http://www.godupgod.com/uploaded/2008/11/200811261827190613.png" ></p>
<p>基本配置：</p>
<blockquote>
<p><strong>Hub Router</strong></p>
<p>hostname Hub<br>
! <br>
crypto isakmp policy 1<br>
  authentication pre-share<br>
crypto isakmp key cisco47 address 0.0.0.0  //0.0.0.0指定对端可为任意<br>
!<br>
crypto ipsec transform-set trans2 esp-des esp-md5-hmac<br>
  mode transport<br>
! <br>
crypto map vpnmap1 local-address Ethernet0 <br>
crypto map vpnmap1 10 ipsec-isakmp <br>
  set peer 172.16.1.1 <br>
  set transform-set trans2 <br>
  match address 101 <br>
crypto map vpnmap1 20 ipsec-isakmp <br>
  set peer 172.16.2.1 <br>
  set transform-set trans2 <br>
  match address 102 <br>
. . . <br>
crypto map vpnmap1 &lt;10*n&gt; ipsec-isakmp <br>
  set peer 172.16.&lt;n&gt;.1 <br>
  set transform-set trans2 <br>
  match address &lt;n+100&gt; <br>
! <br>
interface Tunnel1 <br>
  bandwidth 1000 <br>
  ip address 10.0.0.1 255.255.255.252 <br>
  ip mtu 1400 <br>
  delay 1000 <br>
  tunnel source Ethernet0 <br>
  tunnel destination 172.16.1.1 <br>
! <br>
interface Tunnel2<br>
  bandwidth 1000 <br>
  ip address 10.0.0.5 255.255.255.252 <br>
  ip mtu 1400 <br>
  delay 1000 <br>
  tunnel source Ethernet0 <br>
  tunnel destination 172.16.2.1 <br>
! <br>
. . . <br>
! <br>
interface Tunnel&lt;n&gt; <br>
  bandwidth 1000 <br>
  ip address 10.0.0.&lt;4n-3&gt; 255.255.255.252 <br>
  ip mtu 1400 <br>
  delay 1000 <br>
  tunnel source Ethernet0 <br>
  tunnel destination 172.16.&lt;n&gt;.1 <br>
! <br>
interface Ethernet0 <br>
  ip address 172.17.0.1 255.255.255.0 <br>
  crypto map vpnmap1 <br>
! <br>
interface Ethernet1 <br>
  ip address 192.168.0.1 255.255.255.0 <br>
! <br>
router eigrp 1 <br>
  network 10.0.0.0 0.0.0.255 <br>
  network 192.168.0.0 0.0.0.255 <br>
  no auto-summary <br>
! <br>
access-list 101 permit gre host 172.17.0.1 host 172.16.1.1 <br>
access-list 102 permit gre host 172.17.0.1 host 172.16.2.1 <br>
... <br>
access-list &lt;n+100&gt; permit gre host 172.17.0.1 host 172.16.&lt;n&gt;.1</p>
<p><strong>Spoke1 Router </strong></p>
<p>hostname Spoke1 <br>
! <br>
crypto isakmp policy 1 <br>
  authentication pre-share <br>
crypto isakmp key cisco47 address 0.0.0.0 <br>
! <br>
crypto ipsec transform-set trans2 esp-des esp-md5-hmac <br>
  mode transport <br>
! <br>
crypto map vpnmap1 local-address Ethernet0 <br>
crypto map vpnmap1 10 ipsec-isakmp <br>
  set peer 172.17.0.1 <br>
  set transform-set trans2 <br>
  match address 101 <br>
! <br>
interface Tunnel0 <br>
  bandwidth 1000 <br>
  ip address 10.0.0.2 255.255.255.252 <br>
  ip mtu 1400 <br>
  delay 1000 <br>
  tunnel source Ethernet0 <br>
  tunnel destination 172.17.0.1 <br>
! <br>
interface Ethernet0 <br>
  ip address 172.16.1.1 255.255.255.252<br>
  crypto map vpnmap1 <br>
! <br>
interface Ethernet1 <br>
  ip address 192.168.1.1 255.255.255.0 <br>
! <br>
router eigrp 1 <br>
  network 10.0.0.0 0.0.0.255 <br>
  network 192.168.1.0 0.0.0.255 <br>
  no auto-summary <br>
! <br>
access-list 101 permit gre host 172.16.1.1 host 172.17.0.1</p>
</blockquote>
<p>注意：在Cisco IOS 12.2(13)T 前crypto map vpnmap必须同时映射到物理接口和所有的隧道端口上，而在Cisco IOS 12.2(13)T 之后只要映射到物理接口上就可以了</p> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/9d399c6d06ce35f342169472.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/cisco%D1%A7%CF%B0">cisco学习</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/9d399c6d06ce35f342169472.html#comment">查看评论</a>]]></description>
        <pubDate>2009-04-25  18:21</pubDate>
        <category><![CDATA[cisco学习]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/9d399c6d06ce35f342169472.html</guid>
</item>

<item>
        <title><![CDATA[IPSEC vpn 冗余方法：HSRP+IPsec vpn]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/0dead1cfde3c1f35f9dc61b8.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<div forimg="1">
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/242938259e82414335a80fca.jpg"></p>
<p>简要说明：</p>
<p>R6-----10.0.0.0----R1-----10.1.1.0----R2----10.2.2.0--fa0/1--R3--fa0/0</p>
<p> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr>  <wbr></wbr>--fa0/1-R4--fa0/0---10.3.3.0----R5</p>
<p> <wbr></wbr></p>
<p>先上配置</p>
<p>R3：</p>
<p>IPSEC VPN:</p>
<p>crypto isakmp policy 10 <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr>//定义isakmp 策略<br>
 <wbr></wbr>encr aes<br>
 <wbr></wbr>authentication pre-share<br>
 <wbr></wbr>group 2<br>
 <wbr></wbr>lifetime 180<br>
crypto isakmp key cisco address 10.1.1.1 <wbr></wbr> //预共享密钥。ip地址为R1的s1/1端口IP地址<br>
crypto isakmp aggressive-mode disable <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> //取消积极模式<br>
!<br>
!<br>
crypto ipsec transform-set set1 esp-aes esp-sha-hmac<br>
!<br>
crypto map to_R1 10 ipsec-isakmp<br>
 <wbr></wbr>set peer 10.1.1.1<br>
 <wbr></wbr>set transform-set set1<br>
 <wbr></wbr>match address 110</p>
<p> <wbr></wbr></p>
<p><strong>HSRP:</strong></p>
<p>interface FastEthernet0/0 <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> //内部接口配置，为R5当网关<br>
 <wbr></wbr>ip address 10.3.3.3 255.255.255.0<br>
 <wbr></wbr>duplex auto<br>
 <wbr></wbr>speed auto<br>
 <wbr></wbr>standby 0 track FastEthernet0/1 <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> //全是HSRP<br>
 <wbr></wbr>standby 10 ip 10.3.3.1<br>
 <wbr></wbr>standby 10 priority 105<br>
 <wbr></wbr>standby 10 preempt<br>
 <wbr></wbr>standby 10 name R5gateway<br>
!<br>
interface FastEthernet0/1 <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> //出接口配置，为ＶＰＮ做冗余<br>
 <wbr></wbr>ip address 10.2.2.3 255.255.255.0<br>
 <wbr></wbr>duplex auto<br>
 <wbr></wbr>speed auto<br>
 <wbr></wbr>standby 10 ip 10.2.2.1<br>
 <wbr></wbr>standby 10 priority 105<br>
 <wbr></wbr>standby 10 preempt<br>
 <wbr></wbr>standby 10 name vpn　　　　　　　　　　　//名字很重要。下面需要。必须定义<br>
 <wbr></wbr>standby 10 track FastEthernet0/0<br>
<strong> <wbr></wbr>crypto map to_R1 redundancy vpn</strong> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> //这个很重要，必须指定关键字redundancy才能调用</p>
<p> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> HSRP，后面的名字为上文定义的 <wbr></wbr> name <wbr></wbr>: vpn。如果忽略</p>
<p> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> 的话，变无法建立VPN了。因为上面crypto map 里面指定</p>
<p> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr>的PEER地址为HSRP定义的虚IP地址</p>
<p>R4配置同上</p>
<p>R1配置为普通的IPSEC vpn配置一样 <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr></p>
<p> <wbr></wbr></p>
<p>虽然这个提供了线路冗余，但是连接为<strong>无状态VPN冗余</strong> <wbr></wbr>，在切换时，存在一段时间的丢包现象。上丢包图： <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr></p>
<p>!!!!!!!!!!!!!......................................!!!!!!!!!!!!! <wbr></wbr> <wbr></wbr> <wbr></wbr> <wbr></wbr></p>
<p> <wbr></wbr></p>
<p>这是R6 ping R5 的结果，其中我shutdown掉R3的FA0/0或者FA0/1接口，就会出现线路切换。中间一段时间丢包。丢包原因是因为R4接替后需要重新和R1协商SA（安全会话），而在协商过程中牵扯到ACK问题（设置了提交位)，故在协商期间所有数据均丢弃.</p>
</div>
</div> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/0dead1cfde3c1f35f9dc61b8.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/cisco%D1%A7%CF%B0">cisco学习</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/0dead1cfde3c1f35f9dc61b8.html#comment">查看评论</a>]]></description>
        <pubDate>2009-04-23  09:16</pubDate>
        <category><![CDATA[cisco学习]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/0dead1cfde3c1f35f9dc61b8.html</guid>
</item>

<item>
        <title><![CDATA[配置Cisco IOS EASY VPN Server和Cisco VPN Client]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/766071a294434fa5caefd0fc.html]]></link>
        <description><![CDATA[
		
		<h4 class="c_tx"> </h4>
<div class="real_blog" style="text-indent: 2em; line-height: 26px; height: auto! important">
<table class="FCK__ShowTableBorders" style="table-layout: fixed; width: 100%; position: relative" cellspacing="0" cellpadding="0">
    <tbody>
        <tr>
            <td style="word-wrap: break-word" valign="top">
            <div><img style="display: none" height="1" width="1" src="http://qzone.qq.com/ac/b.gif">
            <div align="center"> </div>
            <img style="display: none" height="1" width="1" src="http://qzone.qq.com/ac/b.gif">
            <div style="font-size: 16px"><center><strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3"><wbr></wbr><wbr></wbr></font><wbr></wbr></strong><wbr></wbr></center><wbr></wbr><strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">
            <div forimg="1">
            <p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/dbe7482416f2ba224d088d03.jpg"></p>
            <p> </p>
            </div>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 试验说明；R1为SKY公司的网关，其F1/0接口连接互联网，用户现在出差在外，通过拨号连接到互联网上，现在希望实现用户通过internet拨号进入SKY公司的R1路由器上，拨号使用easy vpn，并能连接到SKY公司的内网，192.168.0.0/24 网段</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">实验要求；</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">1，</font><wbr></wbr></strong><wbr></wbr><strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">通过cisco vpn client 拨上R1，需要ping通R1的网关的地址，</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">2，VPN拨入成功之后，可以ping通 192.168.0.2，能访问内网服务器上的共享资源</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">实验过程：<br>
            第一步&nbsp;&nbsp;  R1预配置</font><wbr></wbr></strong><wbr></wbr><br>
            R1(config)#<em><wbr></wbr><strong><wbr></wbr>int f0/0<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>ip add 192.168.0.1 255.255.255.0<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>no sh<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>int e1/0<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>ip add 192.168.1.200 255.255.255.0<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>no sh<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>end<br>
            </strong><wbr></wbr></em><wbr></wbr>R1#<em><wbr></wbr><strong><wbr></wbr>ping 192.168.1.101<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  在本实验中PC机的IP地址是192.168.1.101<br>
            </font><wbr></wbr>Type escape sequence to abort.<br>
            Sending 5, 100-byte ICMP Echos to 192.168.1.101, timeout is 2 seconds:<br>
            .!!!!<br>
            Success rate is 80 percent (4/5), round-trip min/avg/max = 8/50/168 ms<br>
            R1#<br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第二步&nbsp;&nbsp;  配置认证策略</font><wbr></wbr></strong><wbr></wbr><br>
            R1#<strong><wbr></wbr><em><wbr></wbr>conf t<br>
            </em><wbr></wbr></strong><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>aaa new-model<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  激活AAA<br>
            </font><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>aaa authorization network vpn-client-user local<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置对远程接入IPSec连接的授权，组名为vpn-client-user</font><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第三步&nbsp;&nbsp;  定义用户的组策略</font><wbr></wbr></strong><wbr></wbr><br>
            R1(config)#<em><wbr></wbr><strong><wbr></wbr>ip local pool VPNDHCP 192.168.0.100 192.168.0.150<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置一个内部地址池，用于分配IP地址到远程接入的VPN客户端，在本实验中地址池的起始地址为192.168.0.100，终止的IP地址为192.168.0.150，在后面的组策略中会引用改地址池<br>
            </font><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto isakmp client configuration group vpn-client-user</strong><wbr></wbr></em><wbr></wbr><br>
            <font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置远程接入组，组名为vpn-client-user，此组名与aaa authorization network命令中的名称一致<br>
            </font><wbr></wbr>R1(config-isakmp-group)#<em><wbr></wbr><strong><wbr></wbr>key norvel.com.cn<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置IKE阶段1使用预共享密钥，密钥为norvel.com.cn</font><wbr></wbr><br>
            R1(config-isakmp-group)#<em><wbr></wbr><strong><wbr></wbr>pool VPNDHCP<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff3300" size="3">//&nbsp;&nbsp;  配置在客户端连接的Easy VPN client所分配的IP地址池</font><wbr></wbr><br>
            R1(config-isakmp-group)#<em><wbr></wbr><strong><wbr></wbr>dns 221.11.1.67<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  给客户端分配DNS地址<br>
            </font><wbr></wbr>R1(config-isakmp-group)#<em><wbr></wbr><strong><wbr></wbr>domain norvel.com.cn<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置分配给客户端的DNS域名<br>
            </font><wbr></wbr>R1(config-isakmp-group)#<em><wbr></wbr><strong><wbr></wbr>exit<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config)#<br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第四步&nbsp;&nbsp;  配置IKE阶段1策略</font><wbr></wbr></strong><wbr></wbr><br>
            R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto isakmp policy 10<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-isakmp)#<em><wbr></wbr><strong><wbr></wbr>authentication pre-share<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-isakmp)#<em><wbr></wbr><strong><wbr></wbr>encryption 3des<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-isakmp)#<em><wbr></wbr><strong><wbr></wbr>group 2<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-isakmp)#<em><wbr></wbr><strong><wbr></wbr>hash sha<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-isakmp)#<em><wbr></wbr><strong><wbr></wbr>exit<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>end<br>
            </strong><wbr></wbr></em><wbr></wbr>R1#<em><wbr></wbr><strong><wbr></wbr>show crypto isakmp policy</strong><wbr></wbr></em><wbr></wbr><br>
            Global IKE policy<br>
            Protection suite of priority 10<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  encryption algorithm:&nbsp;&nbsp;  Three key triple DES<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  hash algorithm:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  Secure Hash Standard<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  authentication method:&nbsp;&nbsp;  Pre-Shared Key<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  Diffie-Hellman group:&nbsp;&nbsp;  #2 (1024 bit)<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  lifetime:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  86400 seconds, no volume limit<br>
            Default protection suite<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  encryption algorithm:&nbsp;&nbsp;  DES - Data Encryption Standard (56 bit keys).<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  hash algorithm:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  Secure Hash Standard<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  authentication method:&nbsp;&nbsp;  Rivest-Shamir-Adleman Signature<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  Diffie-Hellman group:&nbsp;&nbsp;  #1 (768 bit)<br>
            &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  lifetime:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  86400 seconds, no volume limit<br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第五步&nbsp;&nbsp;  配置动态加密映射<br>
            </font><wbr></wbr></strong><wbr></wbr>R1#conf t<br>
            R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto ipsec transform-set R1 esp-sha-hmac esp-3des<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff3300" size="3">//&nbsp;&nbsp;  配置名为R1的转换集</font><wbr></wbr><br>
            R1(cfg-crypto-trans)#<em><wbr></wbr><strong><wbr></wbr>exit<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto dynamic-map dyvpn 10<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff3300" size="3">//&nbsp;&nbsp;  配置名为dyvpn的动态加密映射</font><wbr></wbr><br>
            R1(config-crypto-map)#<em><wbr></wbr><strong><wbr></wbr>set transform-set R1</strong><wbr></wbr></em><wbr></wbr><br>
            R1(config-crypto-map)#<font style="line-height: 1.5em" color="#ff0000" size="3"><strong><wbr></wbr>reverse-route&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </strong><wbr></wbr></font><wbr></wbr><br>
            <font style="line-height: 1.5em" size="3"><font style="line-height: 1.5em" color="#ff3300" size="3">//&nbsp;&nbsp;</font><wbr></wbr>Reverse-route 生成的两条路由,不配置这条命令，是无法ping内网的设备192.168.0.2</font><wbr></wbr><br>
            R1(config-crypto-map)#<em><wbr></wbr><strong><wbr></wbr>exit</strong><wbr></wbr></em><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第六步&nbsp;&nbsp;  配置静态加密映射</font><wbr></wbr></strong><wbr></wbr><br>
            R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto map dyvpn isakmp authorization list vpn-client-user<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  指定应该为远程接入VPN连接执行的授权，这里的vpn-client-user名称必须与aaa authorization network命令中的相同<br>
            </font><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto map dyvpn client configuration address respond</strong><wbr></wbr></em><wbr></wbr><br>
            <font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置允许路由器将信息分配给远程接入客户端，respond参数使路由器等待客户端提示发送这些信息，然后路由器使用策略信息来回应<br>
            </font><wbr></wbr>R1(config)#<em><wbr></wbr><strong><wbr></wbr>crypto map dyvpn 1 ipsec-isakmp dynamic dyvpn<br>
            </strong><wbr></wbr></em><wbr></wbr><font style="line-height: 1.5em" color="#ff0000" size="3">//&nbsp;&nbsp;  配置在静态映射条目中关联动态加密映射</font><wbr></wbr><br>
            <br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第七步&nbsp;&nbsp;  在接口上激活静态加密映射</font><wbr></wbr></strong><wbr></wbr><br>
            R1(config)#<strong><wbr></wbr><em><wbr></wbr>int e1/0<br>
            </em><wbr></wbr></strong><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr>crypto map dyvpn<br>
            </strong><wbr></wbr></em><wbr></wbr>R1(config-if)#<em><wbr></wbr><strong><wbr></wbr> ^Z</strong><wbr></wbr></em><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第八步&nbsp;&nbsp;  在PC机上打开Cisco VPN Client进行配置，点击New创建一个新的VPN连接</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3"><wbr></wbr><wbr></wbr></font><wbr></wbr></strong><wbr></wbr>
            <div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/4e551801dcffe520728da50f.jpg"></div>
            <br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第九步&nbsp;&nbsp;  在VPN连接中进行配置，连接名填写easyvpn，主机填写VPN Server 192.168.1.200，name填写vpn-client-user，密码填写norvel.com.cn</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3"><wbr></wbr><wbr></wbr></font><wbr></wbr></strong><wbr></wbr>
            <div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/7def3a5058b2c6418435240f.jpg"></div>
            <br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第十步&nbsp;&nbsp;  测试VPN连接，选中easyvpn，点击Connect</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3"><wbr></wbr><wbr></wbr></font><wbr></wbr></strong><wbr></wbr>
            <div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/86707833b4e4c260ac4b5f08.jpg"></div>
            <br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3">第十一步&nbsp;&nbsp;  连接成功后查看连接的统计信息</font><wbr></wbr></strong><wbr></wbr><br>
            <strong><wbr></wbr><font style="line-height: 1.5em" color="#6600ff" size="3"><wbr></wbr>
            <div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/75e292fac0f9b53da9d31109.jpg"></div>
            </font></strong></div>
            </div>
            </td>
        </tr>
    </tbody>
</table>
</div> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/766071a294434fa5caefd0fc.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/cisco%D1%A7%CF%B0">cisco学习</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/766071a294434fa5caefd0fc.html#comment">查看评论</a>]]></description>
        <pubDate>2009-04-22  09:31</pubDate>
        <category><![CDATA[cisco学习]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/766071a294434fa5caefd0fc.html</guid>
</item>

<item>
        <title><![CDATA[IPSEC VPN 配置]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/699c7013643bfe0a5baf53cf.html]]></link>
        <description><![CDATA[
		
		<wbr></wbr>
<p> </p>
<div forimg="1"> </div>
<p><wbr></wbr></p>
<p><wbr></wbr></p>
<p> </p>
<div forimg="1"> </div>
<p> </p>
<div forimg="1"> 
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/pic/item/072a5d03fa58dcabd53f7c7c.jpg"></div>
</div>
<p>环境：接口地址都已经配置完，路由也配置了，双方可以互相通信了</p>
<p><wbr></wbr>密钥认证的算法2种：md5和sha1</p>
<p><wbr></wbr>加密算法2种： <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>des和3des</p>
<p><wbr></wbr>IPsec传输模式3种：</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>AH验证参数:ah-md5-hmac(md5验证)、ah-sha-hmac(sha1验证)</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>ESP加密参数：esp-des(des加密)、esp-3des(3des加密)、esp-null（不对数据进行加密）</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>ESP验证参数：esp-md5-hma(md5验证)、esp-sha-hmac(采用sha1验证)</p>
<p><strong><font style="font-size: 20px">1 启用IKE协商</font></strong></p>
<p><strong><wbr></wbr></strong>routerA(config）#<strong>crypto isakmp policy</strong> 1 <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>建立IKE协商策略（1是策略编号1-1000，号<br>
<wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>越小，优先级越高</p>
<p><wbr></wbr><wbr></wbr></p>
<p><wbr></wbr><wbr></wbr>routerA(config-isakmap)#hash md5 <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>密钥认证的算法</p>
<p><wbr></wbr>routerA(config-isakmap)#<strong>authentication pre-share</strong> <wbr></wbr><wbr></wbr>告诉路由使用预先共享的密钥</p>
<p><wbr></wbr>routerA(config)#<strong>crypto isakmp key</strong> 123456 <strong>address</strong> 20.20.20.22 <wbr></wbr><wbr></wbr>(123456是设置的共享密</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>20.20.20.22是对端的IP地</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>址）。</p>
<p><wbr></wbr>routerB(config)#<strong>crypto isakmp policy</strong> 1</p>
<p><wbr></wbr>routerB(config-isakmap)#hash md5 <wbr></wbr></p>
<p><wbr></wbr><wbr></wbr>routerB(config-isakmap)#<strong>authentication pre-share</strong> <wbr></wbr><wbr></wbr></p>
<p><wbr></wbr>routerB(config)#<strong>crypto isakmp key</strong> 123456 <strong>address</strong> 20.20.20.21 <wbr></wbr><wbr></wbr>(路由B和A的配置除了这里</p>
<p><wbr></wbr>的对端IP地址变成了20.20.20.21，其他都要一样的）。</p>
<p><wbr></wbr></p>
<p><strong><font style="font-size: 20px">2 配置IPSec相关参数</font></strong></p>
<p><strong><wbr></wbr></strong>routerA(cnfog)#crypto ipsec transform-set test <wbr></wbr>ah-md5-hamc esp-des <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>(test传输模式的名 <wbr></wbr></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>称。ah-md5-hamc esp-des表示传输模式中采用的验证和加</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>密参数 <wbr></wbr>）。</p>
<p>routerA(config)#<strong>acess-list</strong> 101 <strong>permit</strong> ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>（定义哪些地址的报文加密或是不加密）</p>
<p><wbr></wbr>routerB(config)#<strong>crypto ipsec transform-set</strong> test ah-md5-hamc esp-des</p>
<p><wbr></wbr>routerB(config)#<strong>acess-list</strong> 101 <strong>permit</strong> ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>（路由器B和A的配置除了这里的源和目的IP地址变了，其他都一样）</p>
<p><strong><font style="font-size: 20px">3 <wbr></wbr><wbr></wbr>设置crypto map （目的把IKE的协商信息和IPSec的参数，整合到一起，起一个名字）</font></strong></p>
<p><wbr></wbr>routerA(config)#<strong>crypto map</strong> testmap 1 ipsec-isakmp <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>(testmap:给crypto map起的名字。</p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>1：优先级。ipsec-isakmp:表示此IPSec链接采用IKE自动协商）</p>
<p><wbr></wbr>routerA(config-crypto-map)#<strong>set peer</strong> 20.20.20.22 <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>(指定此VPN链路，对端的IP地址）。</p>
<p><wbr></wbr>routerA(config-crypto-map)#set transform-set test <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>(IPSec传输模式的名字）</p>
<p><wbr></wbr>routerA(config-crypto-map)#match address 101 <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>(上面定义的ACL列表号）</p>
<p><strong><font style="font-size: 20px"><wbr></wbr></font></strong></p>
<p><strong><wbr></wbr><wbr></wbr></strong>routerA(config)#<strong>crypto map</strong> testmap 1 ipsec-isakmp <wbr></wbr></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr>routerA(config-crypto-map)#<strong>set peer</strong> 20.20.20.21 <wbr></wbr>（和A路由的配置只有这里的对端IP不一样）</p>
<p><wbr></wbr>routerA(config-crypto-map)#set transform-set test</p>
<p><wbr></wbr><wbr></wbr>routerA(config-crypto-map)#match address 101 <wbr></wbr><wbr></wbr></p>
<p><strong><font style="font-size: 20px">4 把crypto map 的名字应用到端口</font></strong></p>
<p><wbr></wbr>routerA(config)#inter s0/0 <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>(进入应用VPN的接口）</p>
<p><wbr></wbr>routerA(config-if)#<strong>crypto map</strong> testmap <wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr>（testmap：crypto map的名字）</p>
<p><wbr></wbr>B路由和A完全一样</p>
<p><wbr></wbr></p>
<p><strong><font style="font-size: 20px">查看VPN的配置</font></strong></p>
<p>查看安全联盟（SA）</p>
<p>Router#show crypto ipsec sa</p>
<p>显示crypto map 内的所有配置</p>
<p>router#show crypto map</p>
<p>查看优先级</p>
<p><wbr></wbr>router#show crypto isakmp policy</p> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/699c7013643bfe0a5baf53cf.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/cisco%D1%A7%CF%B0">cisco学习</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/699c7013643bfe0a5baf53cf.html#comment">查看评论</a>]]></description>
        <pubDate>2009-04-21  12:08</pubDate>
        <category><![CDATA[cisco学习]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/699c7013643bfe0a5baf53cf.html</guid>
</item>

<item>
        <title><![CDATA[GRE OVER IPSEC VPN 配置]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/69b97cc450a4fdc338db493a.html]]></link>
        <description><![CDATA[
		
		<div forimg="1"><img class="blogimg" src="http://hiphotos.baidu.com/sdf286/pic/item/10d22b7b4f78cae90ad187b1.jpg" border="0" small="0">PN</div>
<p> </p>
<div style="float: right" align="right"> </div>
<span class="bold">IPSec VPN 专题四：GRE over IPSec</span><br>
<br>
<div class="t_msgfont">环境：<br>
1：R4/R5/R6之间通过Static Route来建立联通性：<br>
2：R4&lt;--&gt;R6之间建立GRE Tunnel<br>
3：R4&lt;--&gt;R6之间建立IPSec VPN<br>
需求：要求PC3 和 PC7能够互通<br>
涉及技术点：GRE Tunnel的建立、IPSec 建立 、 分析数据包的流程<br>
配置步骤：<br>
1：R4/R5/R6之间通过Static Route来互通<br>
2：内网之间的互通通过OSPF来建立：R4/R6的Loopback口通过OSPF学到<br>
3：IPSec 的Peer互指对端Loopack（分析问题的原因）<br>
4：测试GRE Over IPSec的特性：<br>
5：解决方法：<br>
在R4/R6之间指定Static路由到达对端的Loopback口<br>
IPSec Peer指对端的物理接口，而不是Loopback口（推荐）<br>
<br>
==============================================<br>
如果对端Peer使用Loopback那么Tunnel和IPSec均将无法建立成功：<br>
1：R4/R6配置静态路由：（互通）<br>
R4上的静态路由：<br>
ip route 1.1.56.0 255.255.255.0 1.1.45.5<br>
R6上的静态路由：<br>
ip route 1.1.45.0 255.255.255.0 1.1.56.5<br>
<br>
2：R4/R6之间建立GRE Tunnel:<br>
==&gt;R4的配置:<br>
interface Tunnel0<br>
ip address 172.16.10.4 255.255.255.0<br>
tunnel source 1.1.45.4<br>
tunnel destination 1.1.56.6<br>
==&gt;R6的配置:<br>
interface Tunnel0<br>
ip address 172.16.10.6 255.255.255.0<br>
tunnel source 1.1.56.6<br>
tunnel destination 1.1.45.4<br>
==&gt;查看GRE状态：<br>
R4#show ip int b &nbsp;&nbsp;&nbsp;<br>
Tunnel0 &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;&nbsp;  172.16.10.4 &nbsp;&nbsp;&nbsp;  YES manual up &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;&nbsp;  up&nbsp;&nbsp;<br>
R6#show ip int b&nbsp;&nbsp;<br>
Tunnel0 &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;&nbsp;  172.16.10.6 &nbsp;&nbsp;&nbsp;  YES manual up &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;&nbsp;  up &nbsp;&nbsp;  <br>
<br>
3：内网之间通过GRE建立OSPF连接：<br>
==&gt;R4的配置：<br>
router ospf 110<br>
log-adjacency-changes<br>
network 4.4.4.4 0.0.0.0 area 0<br>
network 172.16.10.0 0.0.0.255 area 0<br>
network 192.168.1.0 0.0.0.255 area 0<br>
==&gt;R6的配置：<br>
router ospf 110<br>
network 6.6.6.6 0.0.0.0 area 0<br>
network 172.16.10.0 0.0.0.255 area 0<br>
network 172.16.1.0 0.0.0.255 area 0<br>
==&gt;查看R4/R6的路由表：内网已经互通：<br>
R4#show ip route ospf <br>
O &nbsp;&nbsp;  6.6.6.6 [110/11112] via 172.16.10.6, 00:11:38, Tunnel0<br>
O &nbsp;&nbsp;  172.16.1.0 [110/11112] via 172.16.10.6, 00:11:38, Tunnel0<br>
R6#show ip route ospf <br>
O &nbsp;&nbsp;  4.4.4.4 [110/11112] via 172.16.10.4, 00:11:23, Tunnel0<br>
O 192.168.1.0/24 [110/11112] via 172.16.10.4, 00:11:23, Tunnel0<br>
R6#<br>
==&gt;R3测试：<br>
R3#traceroute 172.16.1.1<br>
&nbsp;&nbsp;  1 192.168.1.2 92 msec 136 msec 48 msec<br>
&nbsp;&nbsp;  2 172.16.10.6 136 msec 132 msec 140 msec ：表明当前数据包是通过GRE Tunnel来转发的<br>
&nbsp;&nbsp;  3 172.16.1.1 148 msec *&nbsp;&nbsp;  168 msec<br>
R3#<br>
<br>
<br>
<br>
4：R4/R6之间建立IPSec VPN :<img src="http://www.netyourlife.net/forum/images/smilies/tongue.gif" border="0" smilieid="7">eer指向R4/R6的环回口：4.4.4.4/6.6.6.6<br>
==&gt;R6上的配置修改:<br>
crypto isakmp key cisco address 4.4.4.4<br>
crypto map MYMAP 10 ipsec-isakmp <br>
set peer 4.4.4.4<br>
set transform-set TS<br>
match address 110 &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  &nbsp;&nbsp;  ：指定感兴趣流量：<br>
crypto map MYMAP local-address Loopback1 ：这里一定要指定更新源：类似BGP的更新源：否则发送数据包的将是本地的物理接口<br>
==&gt;R4上的配置修改:<br>
crypto isakmp key cisco address 6.6.6.6<br>
crypto map MYMAP 10 ipsec-isakmp <br>
set peer 6.6.6.6<br>
set transform-set TS<br>
match address 110<br>
crypto map MYMAP local-address Loopback1<br>
<br>
<br>
5：由于是GRE over IPSec:于是在物理接口下调用感兴趣流量:<br>
interface FastEthernet0/0<br>
ip address 1.1.1.1 255.255.255.0<br>
no cdp log mismatch duplex<br>
crypto map MYMAP<br>
此时如果指定感兴趣流量:access-list 110 permit host 1.1.1.1 host 2.2.2.3 :那么随后OSPF 邻居将Down：<br>
*Dec 11 23:13:56.355: %OSPF-5-ADJCHG: Process 110, Nbr 6.6.6.6 on Tunnel0 from FULL to DOWN, Neighbor Down: Dead timer expired<br>
分析：<br>
1：GRE Tunnel的可达性是通过静态路由来实现的：通过步骤一：可知目的1.1.56.0从F1/1走： <br>
2：R4上的OSPF通过Tunnel学习到6.6.6.6的路由下一条指向Tunnel0<br>
3：在IPSec VPN中指定Peer为6.6.6.6，此时下一条指向Tunnel0（如步骤三），封装GRE：【SIP:1.1.45.4&nbsp;&nbsp;  DIP:1.1.56.6】，R4查看路由表到达1.1.56.0需要经过F1/1（如步骤一），此时GRE数据包被扔到F1/1，刚好匹配该接口下调用的IPSec感兴趣流，于是封装ESP，并新增IP包头【ESP| SIP:4.4.4.4 DIP:6.6.6.6】<br>
4：ESP数据包查看路由表, 发现到达6.6.6.6需要通过Tunnel 0 ，于是ESP又被转到Tunnel 0，并且又被封装【SIP:1.1.45.4&nbsp;&nbsp;  DIP:1.1.56.6】，以此在R4上的OSPF Hello包在Tunnel0和F1/1之间往复循环，而对端的OSPF在三个周期未收到Hello包，则提示Dead Time Expired。<br>
*Mar&nbsp;&nbsp;  14:43:51.743: %OSPF-5-ADJCHG: Process 110, Nbr 192.168.2.10 on Tunnel0 from FULL to DOWN, Neighbor Down&nbsp;&nbsp;  :OSPF邻居Down<br>
<br>
＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝<br>
==&gt;解决方法：（只要打破以上环路的任一环即可）<br>
在R4/R6之间指定Static路由到达对端的Loopback口<br>
IPSec Peer指对端的物理接口，而不是Loopback口（推荐）<br>
修改方法1：<br>
在R4/R6上配置Static Route 让到R4/R6对端Loopback口的数据包从物理接口走,而不是Tunnel 0:<br>
R4(config)#ip route 6.6.6.6 255.255.255.255 1.1.45.5<br>
R6(config)#ip route 4.4.4.4 255.255.255.255 1.1.56.5<br>
R5(config)#ip route 6.6.6.6 255.255.255.255 1.1.56.6 ：R5上增加到R4/R6的路由：<br>
R5(config)#ip route 4.4.4.4 255.255.255.255 1.1.45.4<br>
此时OSPF邻居就可以创建:而且IPSec VPN也是可以建立的:<br>
*Mar 14 15:21:36.395: %OSPF-5-ADJCHG: Process 110, Nbr 192.168.2.10 on Tunnel0 from LOADING to FULL, Loading Done<br>
R4#<br>
==================================================================================<br>
修改方法2<img src="http://www.netyourlife.net/forum/images/smilies/sad.gif" border="0" smilieid="2">推荐做法)<br>
在R4/R6上配置IPSec VPN时,对端Peer指向物理接口,而不是Loopback口地址:<br>
==&gt;R4的配置：<br>
crypto isakmp policy 10<br>
authentication pre-share<br>
crypto isakmp key cisco address 1.1.56.6<br>
R3(config)#crypto ipsec transform-set TS esp-md5-hmac esp-null&nbsp;&nbsp;  ：Null不对数据包加密：用于分析数据用<br>
crypto map MAY 10 ipsec-isakmp <br>
&nbsp;&nbsp;  set peer 1.1.56.6<br>
&nbsp;&nbsp;  set transform-set TS <br>
&nbsp;&nbsp;  match address GRE-VPN<br>
ip access-list extended GRE-VPN<br>
permit ip host 1.1.45.4 host 1.1.56.6<br>
==&gt;R6的配置：<br>
crypto isakmp policy 10<br>
&nbsp;&nbsp;  authentication pre-share<br>
crypto isakmp key cisco address 1.1.45.4<br>
R3(config)#crypto ipsec transform-set TS esp-md5-hmac esp-null <br>
crypto map MAY 10 ipsec-isakmp <br>
set peer 1.1.45.4<br>
set transform-set TS <br>
match address GRE-VPN<br>
ip access-list extended GRE-VPN<br>
permit ip host 1.1.56.6 host 1.1.45.4<br>
==&gt;测试：R3 ping R7：<br>
R3#ping 172.16.1.1 re 10 &nbsp;&nbsp;&nbsp;  !!!!!!!!!!<br>
<br>
抓取R5/R6之间的通信包:如图:<br>
从中可以看出,PING先封装GRE然后再封装IPSec,确实实现了GRE over IPSec的功能:<br>
<br>
==&gt;OSPF的Hello包,是IPSec的感兴趣流量,也被加密:<br>
0000 ca 00 0f 70 00 00 cc 00 07 18 f0 01 08 00 45 c0&nbsp;&nbsp;<br>
0010 00 84 01 1f 00 00 fe 32 b4 62 01 01 01 01 02 02&nbsp;&nbsp;  32:50=ESP<br>
0020 02 03 24 52 35 e7 00 00 00 02 45 c0 00 58 00 93&nbsp;&nbsp;  4:version&nbsp;&nbsp;  5:头长度=5*4=20<br>
0030 00 00 ff 2f b4 1d 01 01 01 01 02 02 02 03 00 00&nbsp;&nbsp;  2f:47=GRE<br>
0040 08 00 45 c0 00 40 01 1e 00 00 01 59 d1 7e 03 03&nbsp;&nbsp;  0x0800=IP&nbsp;&nbsp;  59:89=OSPF<br>
0050 03 01 e0 00 00 05 02 02 00 20 06 06 06 06 00 00&nbsp;&nbsp;  224.0.0.5&nbsp;&nbsp;  6.6.6.6<br>
0060 00 00 d0 f3 00 00 00 00 00 00 00 00 00 00 05 c4&nbsp;&nbsp;  ................<br>
0070 52 07 00 00 13 6c ff f6 00 03 00 01 00 04 00 00&nbsp;&nbsp;  R....l..........<br>
0080 00 01 01 02 02 04 20 03 a5 e4 2a 0c 23 7f 3d 87&nbsp;&nbsp;  ...... ...*.#.=.<br>
0090 eb cc <br>
分析::<br>
1:R3#ping 172.16.1.1<br>
2:此时R4:查看路由表:得知要从Tunnel 0出去<img src="http://www.netyourlife.net/forum/images/smilies/sad.gif" border="0" smilieid="2">看步骤1)<br>
3:数据一到Tunnel 0 就被封装GRE , 并产生个新的IP报头:SIP:1.1.45.4 DIP:1.1.56.6<br>
此时数据包的帧格式为: DATA|SIP|DIP|GRE|SIP|DIP &nbsp;&nbsp;&nbsp;  1.1.45.4---&gt;1.1.56.6<br>
4:此时GRE再次查看RT , 发现到达1.1.56.6/24 , 必须走F1/1, 可F1/1中调用了加密MAP ,并且GRE数据包匹配感兴趣流量(access-list GRE-VPN) ,<br>
5:于是GRE就又被ESP封装 , 并产生一个新的报头:SIP:1.1.45.4&nbsp;&nbsp;  DIP:1.1.56.6<br>
此时数据包的帧格式为: DATA|SIP|DIP|GRE|SIP|DIP|ESP|SIP|DIP&nbsp;&nbsp;  :但是有没发现GRE的IP报头和ESP的IP报头是一样的.<br>
192.168.1.1----&gt;172.16.1.1<br>
ESP：1.1.45.4---&gt;1.1.56.6<br>
GRE：1.1.45.4---&gt;1.1.56.6</div> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/69b97cc450a4fdc338db493a.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/cisco%D1%A7%CF%B0">cisco学习</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/69b97cc450a4fdc338db493a.html#comment">查看评论</a>]]></description>
        <pubDate>2009-04-21  09:46</pubDate>
        <category><![CDATA[cisco学习]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/69b97cc450a4fdc338db493a.html</guid>
</item>

<item>
        <title><![CDATA[第一天上课]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/072a5d03a8a5ee80d53f7ca4.html]]></link>
        <description><![CDATA[
		
		<p>&nbsp;&nbsp;&nbsp;    今天终于鼓起勇气，报名去上课了，花了4500块啊，对我来说，可是不小的数目啊，在取款机面前数了半天才离开，那可是我好几个月的工资啊，要是学不到东西，那可就心疼了。。。<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  今天上NA课程的老师是IE，很年轻，我感觉挺不错的，懂的东西挺多的，而不光是cisco的东西，感觉这钱没有白花。今天是第一天，上午主要讲了cisco一些整体的东西，下午讲了OSI模型，介绍了路由器，交换机。这些都能听得懂，跟以前自己看的错不多。<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 终于又回到课堂了，离开学校都差不多7,8年了，但我的书本始终都没有放下，该学的东西或多或少都学了点。但自己一个人看书始终是不能很好的学习的。这次我是下了本钱了，打算好好的，全面的学习了。<br>
&nbsp;&nbsp;&nbsp;&nbsp;  以后的课我都要认真的听，花了钱就要有回报的，也算是投资吧。<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 加油吧。相信自己，我能成功的。</p> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/072a5d03a8a5ee80d53f7ca4.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/%C4%AC%C8%CF%B7%D6%C0%E0">默认分类</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/072a5d03a8a5ee80d53f7ca4.html#comment">查看评论</a>]]></description>
        <pubDate>2009-03-23  20:00</pubDate>
        <category><![CDATA[默认分类]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/072a5d03a8a5ee80d53f7ca4.html</guid>
</item>

<item>
        <title><![CDATA[发现网页木马病毒http://ddddsss123.cn/1/rr.htm]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/16ccaff465165169dcc474c7.html]]></link>
        <description><![CDATA[
		
		<p>打开网页，360就显示拦截http://ddddsss123.cn/1/rr.htm，从网上搜索，好像是新出来的 ，打开网页，上面有一个 -_-o 标志。不知道应该解决啊？</p>
<p>&lt;iframe src=http://ddddsss123.cn/1/rr.htm width=0 height=0&gt;&lt;/iframe&gt;-_-o</p>
<p>打开部分网址代码会发现有类似的引入代码，请大家注意</p>
<p>上张截图，目前还没有找到相关的解决办法，另外打开IE浏览器的时候也发现让安装PA561401.CAB文件提示，是一个OFFICE的组件，</p>
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/zhaopeng/pic/item/c6847cd9169a85c939012f97.jpg"></div> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/16ccaff465165169dcc474c7.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/%C4%AC%C8%CF%B7%D6%C0%E0">默认分类</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/16ccaff465165169dcc474c7.html#comment">查看评论</a>]]></description>
        <pubDate>2009-02-26  11:00</pubDate>
        <category><![CDATA[默认分类]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/16ccaff465165169dcc474c7.html</guid>
</item>

<item>
        <title><![CDATA[Cisco路由器本地密码破解方法]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/62c909d308fb2233960a16a0.html]]></link>
        <description><![CDATA[
		
		<p>为几天在学ccna，正好看到路由器的密码破解方法。觉得这篇文章简单易懂，就给转过来了。另外还可以保存在这里，以备以后需要时再过来查查看。</p>
<p> </p>
<p>show version  !检查配置寄存器的值</p>
<p style="text-indent: 2em">&#8226;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  show flash ！检查Flash中的IOS</p>
<p style="text-indent: 2em">&#8226;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  show startup-config  ！检查NVRAM中的启动配置文件</p>
<p style="text-indent: 2em">&#8226;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  show running-config  ！检查RAM中的文件</p>
<p style="text-indent: 2em"> </p>
<p style="text-indent: 2em"> </p>
<p style="text-indent: 2em">1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  路器由密布的恢复.（以2600为例）</p>
<p style="text-indent: 2em"> </p>
<p style="text-indent: 2em">2600、3600等新系列路由器步骤：</p>
<p style="text-indent: 2em">1、启动路由器，60秒内按下ctrl+break键</p>
<p style="text-indent: 2em">2、rommon&gt;confreg 0x2142</p>
<p style="text-indent: 2em">3、rommon&gt;reset</p>
<p style="text-indent: 2em">4、router#copy startup-config running-config</p>
<p style="text-indent: 2em">5、router(config)#no enable secrect  //可以删除密码也可以更改,这里为删除</p>
<p style="text-indent: 2em">6、router(config-line)#no enable password</p>
<p style="text-indent: 2em">7、router#copy running-config startup</p>
<p style="text-indent: 2em">8、router(config)#config-register 0x2102</p>
<p style="text-indent: 2em">9、router#reload</p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">2500</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">系列路由器步骤：</span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">1</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">、启动路由器，</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">60</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">秒内按下</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">ctrl+break</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">键</span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">2</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">、</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">&gt;o/r 0x2142</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">3</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">、</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">&gt;i</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">其余步骤跟</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">2600</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">、</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">3600</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">一样</span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">2</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">．交换机密码恢复（以</span><span style="mso-bidi-font-weight: bold"><font face="Times New Roman">2950</font></span><span style=" mso-bidi-font-weight: bold; mso-ascii- mso-hansi-">为例）</span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow;  mso-bidi-font-weight: bold; mso-ascii- mso-hansi- mso-highlight: yellow">重起交换机：按</span><span style="background: yellow; mso-bidi-font-weight: bold; mso-highlight: yellow"><font face="Times New Roman">MODE</font></span><span style="background: yellow;  mso-bidi-font-weight: bold; mso-ascii- mso-hansi- mso-highlight: yellow">键进入到</span><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">switch:</font></span><span style="background: yellow;  mso-ascii- mso-hansi- mso-highlight: yellow">模式</span><font face="Times New Roman"> </font><span style=" mso-ascii- mso-hansi-">如下</span></p>
<p style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-weight: bold"><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">C2950 Boot Loader (C2950-HBOOT-M) Version 12.1(11r)EA1, RELEASE SOFTWARE (fc1)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Compiled Mon 22-Jul-02 17:18 by antonino</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">WS-C2950-24 starting...</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Base ethernet MAC Address: 00:13:1a:9a:2b:80</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Xmodem file system is available.</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">The system has been interrupted prior to initializing the</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flash filesystem.<span style="mso-spacerun: yes">  </span>The following commands will initialize</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">the flash filesystem, and finish loading the operating </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">system software:</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>flash_init</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>load_helper</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>boot</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">switch: flash_init</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Initializing Flash...</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flashfs[0]: 4 files, 1 directories</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flashfs[0]: 0 orphaned files, 0 orphaned directories</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flashfs[0]: Total bytes: 7741440</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flashfs[0]: Bytes used: 3090944</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flashfs[0]: Bytes available: 4650496</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">flashfs[0]: flashfs fsck took 6 seconds.</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">...done initializing flash.</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Boot Sector Filesystem (bs:) installed, fsid: 3</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Parameter Block Filesystem (pb:) installed, fsid: 4</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">switch: load_helper</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">switch: dir</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">List of filesystems currently registered:</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>flash[0]: (read-write)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>xmodem[1]: (read-only)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>null[2]: (read-write)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>bs[3]: (read-only)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">switch: dir flash:</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Directory of flash:/</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">2<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>-rwx<span style="mso-spacerun: yes">  </span>736<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>&lt;date&gt;<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>vlan.dat</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">3<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>-rwx<span style="mso-spacerun: yes">  </span>3086336<span style="mso-spacerun: yes">&nbsp;&nbsp;  </span>&lt;date&gt;<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>c2950-i6q4l2-mz.121-22.EA2.bin</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">5<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>-rwx<span style="mso-spacerun: yes">  </span>1558<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>&lt;date&gt;<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span><span style="background: yellow; mso-highlight: yellow">config.text</span><span style="mso-spacerun: yes">  </span></font></span><span style=" mso-ascii- mso-hansi-">／／交换机启动时应用的配置</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">6<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>-rwx<span style="mso-spacerun: yes">  </span>5<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>&lt;date&gt;<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>private-config.text</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">4650496 bytes available (3090944 bytes used)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><font face="Times New Roman"><span style="background: yellow; mso-highlight: yellow">switch: rename flash:config.text </span><span style="background: red; mso-highlight: red">flash:config-old.txt</span><span> //</span></font><span style=" mso-ascii- mso-hansi-">重命名</span><font face="Times New Roman"><span style="background: yellow; mso-highlight: yellow">config.text</span><span> </span></font></p>
<p style="margin: 0cm 0cm 0pt"><font face="Times New Roman"><span style="background: yellow; mso-highlight: yellow">switch: reset</span><span><span style="mso-spacerun: yes">&nbsp;&nbsp;  </span>//</span></font><span style=" mso-ascii- mso-hansi-">重起交换机</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Are you sure you want to reset the system (y/n)?y</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">System resetting...</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style=" mso-ascii- mso-hansi-">重起交换机后由于交换机不会再应用配置文件，因为刚才已把配置文件的名字更改。交换机会进入到配置的对话模式。如查</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">  </span>--- System Configuration Dialog ---</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Would you like to enter the initial configuration dialog? [yes/no]: n</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Switch#dir</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Directory of flash:/</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>2<span style="mso-spacerun: yes">  </span>-rwx<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>736<span style="mso-spacerun: yes">  </span>Mar 01 1993 00:19:14 +00:00<span style="mso-spacerun: yes">  </span>vlan.dat</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>3<span style="mso-spacerun: yes">  </span>-rwx<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;  </span>3086336<span style="mso-spacerun: yes">  </span>Jan 01 1970 01:12:26 +00:00<span style="mso-spacerun: yes">  </span>c2950-i6q4l2-mz.121-22.EA2.bin</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>5<span style="mso-spacerun: yes">  </span>-rwx<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>1558<span style="mso-spacerun: yes">  </span>Mar 01 1993 02:36:44 +00:00<span style="mso-spacerun: yes">  </span><span style="background: yellow; mso-highlight: yellow">config-old.txt</span></font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;  </span>6<span style="mso-spacerun: yes">  </span>-rwx<span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>5<span style="mso-spacerun: yes">  </span>Mar 01 1993 02:36:44 +00:00<span style="mso-spacerun: yes">  </span>private-config.text</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">7741440 bytes total (4650496 bytes free)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">Switch#copy config-old.txt running-config</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Destination filename [running-config]? </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">1558 bytes copied in 1.152 secs (1352 bytes/sec)</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">sw#config t</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">Enter configuration commands, one per line.<span style="mso-spacerun: yes">  </span>End with CNTL/Z.</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">sw(config)#line console 0</font></span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">sw(config-line)#no pass cisco </font></span><span style=" mso-ascii- mso-hansi-">／／清除</span><span><font face="Times New Roman">console</font></span><span style=" mso-ascii- mso-hansi-">口密码</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">sw(config)#no enable secret <span style="mso-spacerun: yes"> </span></font></span><span style=" mso-ascii- mso-hansi-">／／清除</span><span><font face="Times New Roman">enable</font></span><span style=" mso-ascii- mso-hansi-">密码</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">sw(config)#no enable password </font></span><span style=" mso-ascii- mso-hansi-">／／清除</span><span><font face="Times New Roman">enable</font></span><span style=" mso-ascii- mso-hansi-">密码</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman">sw#write<span style="mso-spacerun: yes">  </span>//</font></span><span style=" mso-ascii- mso-hansi-">重新保存</span></p>
<p style="margin: 0cm 0cm 0pt"><span><font face="Times New Roman"> </font></span></p>
<p style="margin: 0cm 0cm 0pt"><span style="background: yellow;  mso-ascii- mso-hansi- mso-highlight: yellow">以为密码删除成功，很多情况下你可以不删除，就直接更改就</span><span style="background: yellow; mso-highlight: yellow"><font face="Times New Roman">OK</font></span><span style="background: yellow;  mso-ascii- mso-hansi- mso-highlight: yellow">了</span></p>
<p> </p> <a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/62c909d308fb2233960a16a0.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/cisco%D1%A7%CF%B0">cisco学习</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/62c909d308fb2233960a16a0.html#comment">查看评论</a>]]></description>
        <pubDate>2008-12-14  21:04</pubDate>
        <category><![CDATA[cisco学习]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/62c909d308fb2233960a16a0.html</guid>
</item>

<item>
        <title><![CDATA[该干点事情了]]></title>
        <link><![CDATA[http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/83c71812bbc438c8c2fd7873.html]]></link>
        <description><![CDATA[
		
		<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  现在工作了这么常时间了，都不知道自己整天在忙些什么？送送东西，打打杂。</p>
<p>为什么会这样了，我自己都不明白。要么就是整天耗在网上，聊天，吹牛。</p>
<p>跟本就没有心情去学习。起码要有一个明确的方向。</p>
<p>想想，应该干点事情了。不能在虚度时间了……</p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/category/%B8%F6%C8%CB%CB%E6%B1%CA">个人随笔</a>&nbsp;<a href="http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/83c71812bbc438c8c2fd7873.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-27  11:48</pubDate>
        <category><![CDATA[个人随笔]]></category>
        <author><![CDATA[落侠孤雾]]></author>
		<guid>http://hi.baidu.com/%C2%E4%CF%C0%B9%C2%CE%ED/blog/item/83c71812bbc438c8c2fd7873.html</guid>
</item>


</channel>
</rss>