首页 > 其他 > 详细

IPSec实验配置

时间:2021-07-30 22:50:37      阅读:17      评论:0      收藏:0      [点我收藏+]

IPSec实验配置

技术分享图片

AR5

<Huawei>sys
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip ad 10.1.1.2 24
[Huawei-GigabitEthernet0/0/0]int e0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 20.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 192.168.1.0 24 10.1.1.1
[Huawei]ip route-static 192.168.2.0 24 20.1.1.2

AR4

<Huawei>sys
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip ad 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip ad 10.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 192.168.2.0 24 10.1.1.2
[Huawei]ip route-static 20.1.1.0 24 10.1.1.2
[Huawei]ipsec proposal ipsec
[Huawei-ipsec-proposal-ipsec]q
[Huawei]alc 3000
[Huawei-acl-adv-3000]rule permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
[Huawei-acl-adv-3000]q
[Huawei]ipsec policy huawei 10 manual #配置ipsec策略
[Huawei-ipsec-policy-manual-huawei-10]security acl 3000 #设置被保护的数据流
[Huawei-ipsec-policy-manual-huawei-10]proposal ipsec
[Huawei-ipsec-policy-manual-huawei-10]sa spi inbound esp 12345
[Huawei-ipsec-policy-manual-huawei-10]sa spi outbound esp 54321
[Huawei-ipsec-policy-manual-huawei-10]sa string-key inbound esp cipher huawei
[Huawei-ipsec-policy-manual-huawei-10]sa string-key outbound esp cipher huawei
[Huawei-ipsec-policy-manual-huawei-10]tunnel local 10.1.1.1
[Huawei-ipsec-policy-manual-huawei-10]tunnel remote 20.1.1.2
[Huawei-ipsec-policy-manual-huawei-10]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ipsec policy huawei 10
[Huawei-GigabitEthernet0/0/1]q
[Huawei]q
<Huawei>save

AR6

<Huawei>sys
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip ad 192.168.2.254 24
[Huawei-GigabitEthernet0/0/1]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip ad 20.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 192.168.1.0 24 20.1.1.1
[Huawei]ip route-static 10.1.1.0 24 20.1.1.1
[Huawei]ipsec proposal ipsec
[Huawei-ipsec-proposal-ipsec]q
[Huawei]alc 3000
[Huawei-acl-adv-3000]rule permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
[Huawei-acl-adv-3000]q
[Huawei]ipsec policy huawei 10 manual #配置ipsec策略
[Huawei-ipsec-policy-manual-huawei-10]security acl 3000 #设置被保护的数据流
[Huawei-ipsec-policy-manual-huawei-10]proposal ipsec
[Huawei-ipsec-policy-manual-huawei-10]sa spi inbound esp 54321
[Huawei-ipsec-policy-manual-huawei-10]sa spi outbound esp 12345
[Huawei-ipsec-policy-manual-huawei-10]sa string-key inbound esp cipher huawei
[Huawei-ipsec-policy-manual-huawei-10]sa string-key outbound esp cipher huawei
[Huawei-ipsec-policy-manual-huawei-10]tunnel local 20.1.1.2
[Huawei-ipsec-policy-manual-huawei-10]tunnel remote 10.1.1.1
[Huawei-ipsec-policy-manual-huawei-10]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ipsec policy huawei 10
[Huawei-GigabitEthernet0/0/0]q
[Huawei]q
<Huawei>save

P15

技术分享图片

P14

技术分享图片

IPSec实验配置

原文:https://blog.51cto.com/u_14900190/3237372

(0)
(0)
   
举报
评论 一句话评论(0
分享档案
最新文章
教程昨日排行
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!