ip address inside 192.168.1.103 255.255.255.0
ip address outside 128.12.1.155 255.255.255.0
route outside 0.0.0.0 0.0.0.0 128.12.1.10
sysopt connection permit-ipsec 
access-list 100 permit ip host 128.12.1.155 128.12.3.0 255.255.255.0
crypto ipsec transform-set myset esp-3des esp-md5-hmac
crypto map mymap 10 ipsec-isakmp
crypto map mymap 10 match address 100
crypto map mymap 10 set peer 128.12.2.10
crypto map mymap 10 set transform-set myset
crypto map mymap interface outside
isakmp enable outside
isakmp identity address
isakmp key dobsekred address 128.12.2.10 netmask 255.255.255.255
isakmp policy 5 authentication pre-share
isakmp policy 5 encryption 3des
isakmp policy 5 hash md5
isakmp policy 5 group 2
isakmp policy 5 lifetime 28800
global (outside) 1 interface
access-list 101 permit ip 192.168.1.0 255.255.255.0 128.12.3.0 255.255.255.0
nat (inside) 1 access-list 101

Back to main article