crypto isakmp enable
crypto isakmp policy 10
encryption 3des
hash md5
authentication pre-share
group 2
crypto isakmp key cisco address 202.100.1.10
crypto isakmp keepalive 10 periodic
crypto ipsec transform-set Trans1 esp-3des esp-md5-hmac
mode tunnel
crypto map cry-map 10 ipsec-isakmp
set peer 202.100.1.10
set security-association idle-time 180
set transform-set Trans1
set pfs group2
match address vpn
#在接口调用
crypto map cry-map
#HA配置