拓撲圖如下, 僅供參考, 現實中應該是要用到GRE over IPSec

Guangzhou & Huizhou的配置文件如下:
*********************************************
Guangzhou:
*********************************************
!
!
crypto isakmp policy 10
encr 3des
authentication pre-share
group 2
crypto isakmp key 6 key address 200.1.1.2
!
!
crypto ipsec transform-set set esp-3des esp-sha-hmac
!
crypto map vpn 10 ipsec-isakmp
set peer 200.1.1.2
set transform-set set
match address 100
!
!
interface Loopback0
ip address 1.1.1.1 255.255.255.255
!
interface Loopback1
ip address 2.2.2.2 255.255.255.255
!
interface FastEthernet0/0
ip address 200.1.1.1 255.255.255.0
duplex auto
speed auto
crypto map vpn
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
router ospf 1
log-adjacency-changes
network 1.1.1.1 0.0.0.0 area 0
network 2.2.2.2 0.0.0.0 area 0
network 200.1.1.0 0.0.0.255 area 0
!
access-list 100 permit ip any any
*********************************************
*********************************************
Huizhou:
*********************************************
!
crypto isakmp policy 10
encr 3des
authentication pre-share
group 2
crypto isakmp key 6 key address 200.1.1.1
!
!
crypto ipsec transform-set set esp-3des esp-sha-hmac
!
crypto map vpn 10 ipsec-isakmp
set peer 200.1.1.1
set transform-set set
match address 100
!
interface Loopback0
ip address 3.3.3.3 255.255.255.255
!
interface Loopback1
ip address 4.4.4.4 255.255.255.255
!
interface FastEthernet0/0
ip address 200.1.1.2 255.255.255.0
duplex auto
speed auto
crypto map vpn
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
router ospf 1
log-adjacency-changes
network 3.3.3.3 0.0.0.0 area 0
network 4.4.4.4 0.0.0.0 area 0
network 200.1.1.0 0.0.0.255 area 0
!
access-list 100 permit ip any any
!
*********************************************