配置拓扑图
1、配置2/1/0口
set interface state GigabitEthernet2/1/0 up
set interface ip address GigabitEthernet2/1/0 10.66.0.1/24
set interface promiscuous on GigabitEthernet2/1/0
2、配置2/4/0口
set interface state GigabitEthernet2/4/0 up
set interface ip address GigabitEthernet2/4/0 10.0.0.1/24
set interface promiscuous on GigabitEthernet2/4/0
create ipsec tunnel local-ip 10.66.0.1 local-spi 1031 remote-ip 10.66.0.2 remote-spi 1030
set interface ipsec key ipsec0 local crypto aes-cbc-128 123456
set interface ipsec key ipsec0 remote crypto aes-cbc-128 123456
set interface ipsec key ipsec0 local integ sha1-96 123456
set interface ipsec key ipsec0 remote integ sha1-96 123456
set int state ipsec0 up
ip route add 11.0.0.0/24 via ipsec0
set interface unnumbered ipsec0 use GigabitEthernet2/1/0
1、配置2/2/0口
set int state GigabitEthernet2/2/0 up
set int ip address GigabitEthernet2/2/0 11.0.0.1/24
set int promiscuous on GigabitEthernet2/2/0
2、配置2/3/0口
set int state GigabitEthernet2/3/0 up
set int ip address GigabitEthernet2/3/0 10.66.0.2/24
set int promiscuous on GigabitEthernet2/3/0
create ipsec tunnel local-ip 10.66.0.2 local-spi 1030 remote-ip 10.66.0.1 remote-spi 1031
set interface ipsec key ipsec0 local crypto aes-cbc-128 123456
set interface ipsec key ipsec0 remote crypto aes-cbc-128 123456
set interface ipsec key ipsec0 local integ sha1-96 123456
set interface ipsec key ipsec0 remote integ sha1-96 123456
set int state ipsec0 up
ip route add 10.0.0.0/24 via ipsec0
set interface unnumbered ipsec0 use GigabitEthernet2/3/0