华为IPSEC 野蛮模式配置
时间: 2023-11-30 12:02:29 浏览: 201
配置华为IPSec野蛮模式需要以下步骤:
1. 创建安全策略
```
security policy 10
action permit
local selector 10.0.0.0/24
remote selector 20.0.0.0/24
```
其中,security policy 10是安全策略的编号,action permit表示允许通过,local selector是本地子网,remote selector是远程子网。
2. 创建IPSec策略
```
ipsec proposal proposal1
esp authentication-algorithm sha1
esp encryption-algorithm des
ah authentication-algorithm sha1
ah encryption-algorithm des
ipsec policy policy1 isakmp
security acl number 2000
proposal proposal1
pfs dh-group2
remote-address 20.0.0.0
```
其中,ipsec proposal是IPSec提案,ipsec policy是IPSec策略,security acl number是ACL编号,proposal是提案名称,pfs表示Perfect Forward Secrecy,remote-address是远程主机地址。
3. 创建IKE策略
```
ike proposal proposal1
authentication-method pre-shared-key
dh-group2
encryption-algorithm des
integrity-algorithm sha1
ike peer peer1 ike-proposal proposal1
pre-shared-key cipher %^%#LSJL9d$eQmW(]a9@G<g6hS#W%1yXn9iqk{PQD!%i%^%#
ike-version v1
remote-address 20.0.0.1
```
其中,ike proposal是IKE提案,ike peer是IKE对端,pre-shared-key是预共享密钥,remote-address是远程主机地址。
4. 创建VPN实例
```
ip vpn-instance vpn1
ipv4-family
route-distinguisher 100:1
vpn-target 100:1 export-extcommunity
vpn-target 100:1 import-extcommunity
route-target export 100:1
route-target import 100:1
```
其中,ip vpn-instance是VPN实例,ipv4-family是IPv4族,route-distinguisher是路由区分器,vpn-target是VPN目标,route-target是路由目标。
5. 创建VPN接口
```
interface Tunnel1
ip binding vpn-instance vpn1
ip address 192.168.1.1 255.255.255.0
tunnel-protocol ipsec
tunnel-policy policy1
tunnel source 10.0.0.1
tunnel destination 20.0.0.1
```
其中,interface Tunnel1是VPN接口,ip binding vpn-instance是绑定VPN实例,ip address是IP地址,tunnel-protocol是隧道协议,tunnel-policy是隧道策略,tunnel source是隧道源地址,tunnel destination是隧道目的地址。
配置完成后,可以通过ping测试隧道是否正常工作。
阅读全文