· 6 years ago · Oct 28, 2019, 04:10 AM
1# crypto isakmp policy 10
2# encryption aes 256
3# authenticationpre-share
4# group 5
5# crypto isakmp key secretkey address 10.1.1.1
6# crypto ipsec transform-set R2>R0 esp-aes 256 esp-sha-hmac
7# crypto map IPSEC-MAP 10 ipsec-isakmp
8# set peer 10.1.1.1
9# set pfs group5
10# set security-association lifetime seconds 14400
11# set transform-set R2>R0
12# match address 100
13# ip route 0.0.0.0 0.0.0.0 10.2.2.2
14# access-list 100 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255