我来回答下:
A:
access-list vpn-list permit ip
access-list 100 permit ip
nat(inside) 0 access-list 100
crypto map vpnpeer 10 ipsec-isakmp
crypto map vpnpeer 10 match address vpn-list
crypto map vpnpeer 10 set peer 公网对方IP
crypto map vpnpeer 10 set transform-set myset
crypto map vpnpeer interface outside
isakmp enable outside
isakmp key 12345 address 公网对方IP
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
B:
类似