1.测试拓扑:
参见:http://333234.blog.51cto.com/323234/958557的测试拓扑
有隧道分离 时不用配置NAT免除,可以参考如下博文: http://blog.sina.com.cn/s/blog_52ddfea30100ux80.html
Site-to-Site VPN从总部ASA上公网的配 置参考如下链接:http://www.packetu.com/2013/04/02/cisco-asa-8-4-vpn-dealing-with-internet- hairpin-traffic/
2.基本思路:
A.same-security-traffic permit intra- interface
---因为分支机构从总部上互联网,流量只是从ASA的outside口进出,所以开启流量相在同 安全数级别的同一接口进出
B.在总部ASA上针对分支机构内部流量做PAT
---假定分支机构 192.168.1.0/24
object network vpnnet
subnet 192.168.1.0 255.255.255.0
nat (outside,outside) dynamic interface
C.因为没有配置隧道分离,还需配置NAT免除
object network insidenet
subnet 10.1.1.0 255.255.255.0
object network vpnnet
subnet 192.168.1.0 255.255.255.0
nat (inside,outside) source static insidenet insidenet destination static vpnnet vpnnet
或:
nat (inside,any) source static insidenet insidenet destination static vpnnet vpnnet no-proxy-arp
3.基本配置:
A.R1:
interface FastEthernet1/0
ip address 10.1.1.1 255.255.255.0
no shut
ip route 0.0.0.0 0.0.0.0 10.1.1.10
B.R2:
interface FastEthernet1/0
ip address 202.100.1.2 255.255.255.0
no shut
interface FastEthernet0/0
ip address 209.165.201.2 255.255.255.0
no shut
interface FastEthernet0/1
ip address 202.100.2.2 255.255.255.0
no shut