Конфиги на цисках следующие:=================================================
Конфиг циски 800:
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
lifetime 10800
crypto isakmp key PRESHARED_KEY address AA.AA.AA.AA no-xauth
crypto isakmp invalid-spi-recovery
crypto isakmp keepalive 120 periodic
!
!
crypto ipsec transform-set CENTR esp-aes esp-sha-hmac
!
crypto map CENTR 10 ipsec-isakmp
set peer AA.AA.AA.AA
set security-association lifetime seconds 86400
set transform-set CENTR
set pfs group2
match address IPSec
interface FastEthernet4
ip address BB.BB.BB.BB 255.255.255.240
ip access-group FROMOUTSIDE in
ip nat outside
ip inspect FROMINSIDE out
no ip virtual-reassembly
duplex auto
speed auto
crypto map CENTR
============================================================================
Конфиг циски 2800:
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
lifetime 10800
crypto isakmp key PRESHARED_KEY address BB.BB.BB.BB no-xauth
crypto isakmp invalid-spi-recovery
crypto isakmp keepalive 120 periodic
!
!
crypto ipsec transform-set BRANCH esp-aes esp-sha-hmac
!
crypto map BRANCH 10 ipsec-isakmp
set peer BB.BB.BB.BB
set security-association lifetime seconds 86400
set transform-set BRANCH
set pfs group2
match address IPSec
interface FastEthernet0/1
ip address AA.AA.AA.AA 255.255.255.128
ip access-group FROMOUTSIDE in
ip inspect FW out
ip ips IDS in
ip nat outside
no ip virtual-reassembly
duplex auto
speed auto
crypto map BRANCH