tên người dùng nhân viên mật khẩu letmein bán kính-server host bán kính máy chủ quan trọng myRaDiUSpassWoRd giao diện nhóm async 1 nhóm phạm vi 1 16 encapsulation ppp! lựa chọn CHAP như các phương pháp chứng thực PPP và áp dụng! | Securing Dial-In Access serial-number 007462E4 key-string 17C11157 CC640BF3 3DC5B608 C5C60963 C0421A67 D2D7AF70 97728A9A BACA0E07 35288070 AD90A20F 56F1BFE7 D8A4BB68 2C2419E0 26CF8E17 B09CA9A0 3090942E quit Crypto map for the connection from Eesti to Vancouver-gw this defines the remote peer and what traffic to encrypt which is determined by access list 140 This gets applied to the tunnel and physical interfaces. crypto map Eesti-to-Vancouver 10 set peer VancouverESA match address 140 Tunnel interface from remote branch Eesti to home gateway Vancouver-gw interface Tunnel100 description network connection back to headquarters Vancouver ip unnumbered Ethernet1 0 no ip directed-broadcast tunnel source tunnel destination crypto map Eesti-to-Vancouver http cpress cc td cpress internl dns 62 of 103 02 02 2001 Securing Dial-In Access Apply the crypto map to the physical interface this is also the outside NAT interface. interface Serial0 0 description frame relay connection to ISP ip address no ip directed-broadcast ip nat outside encapsulation frame-relay frame-relay lmi-type ansi crypto map Eesti-to-Vancouver NAT inside interface interface Ethernet1 0 description private IP address for remote site ip address no ip directed-broadcast ip nat inside Translate IP addresses matching access list 150 into the IP address given to serial interface connected to the ISP http cpress cc td cpress internl dns 63 of 103 02 02 2001 Securing Dial-In Access ip nat inside source list 150 interface Serial0 0 overload ip classless default route to ISP ip route Routes for the networks inside the corporate intranet that the remote needs to access ip route Tunnel100 ip route Tunnel100 Traffic going to any other destination will take the default route and be translated by NAT .