eNSP T2TP VPN命令行配置
时间: 2024-03-11 10:36:55 浏览: 63
以下是 eNSP T2TP VPN 的命令行配置步骤:
1. 配置 VPN Server 端:
① 创建虚拟接口:
[Huawei] interface virtual-template 1
[Huawei-Virtual-Template1] ip address 10.1.1.1 255.255.255.0
[Huawei-Virtual-Template1] quit
② 创建隧道协议:
[Huawei] ipsec proposal myproposal
[Huawei-proposal-myproposal] esp authentication-algorithm sha1
[Huawei-proposal-myproposal] esp encryption-algorithm aes-256
[Huawei-proposal-myproposal] quit
[Huawei] ipsec policy mypolicy 10 isakmp
[Huawei-ipsec-policy-mypolicy-10] security acl 3001
[Huawei-ipsec-policy-mypolicy-10] proposal myproposal
[Huawei-ipsec-policy-mypolicy-10] quit
[Huawei] quit
③ 创建隧道接口:
[Huawei] interface Tunnel 0
[Huawei-Tunnel0] ip address 192.168.1.1 255.255.255.0
[Huawei-Tunnel0] tunnel-protocol ipsec
[Huawei-Tunnel0] ipsec policy mypolicy
[Huawei-Tunnel0] tunnel source GigabitEthernet 0/0/1
[Huawei-Tunnel0] tunnel destination 1.1.1.1
[Huawei-Tunnel0] quit
2. 配置 VPN Client 端:
① 创建虚拟接口:
[Huawei] interface virtual-template 1
[Huawei-Virtual-Template1] ip address 10.1.1.2 255.255.255.0
[Huawei-Virtual-Template1] quit
② 创建隧道协议:
[Huawei] ipsec proposal myproposal
[Huawei-proposal-myproposal] esp authentication-algorithm sha1
[Huawei-proposal-myproposal] esp encryption-algorithm aes-256
[Huawei-proposal-myproposal] quit
[Huawei] ipsec policy mypolicy 10 isakmp
[Huawei-ipsec-policy-mypolicy-10] security acl 3000
[Huawei-ipsec-policy-mypolicy-10] proposal myproposal
[Huawei-ipsec-policy-mypolicy-10] quit
[Huawei] quit
③ 创建隧道接口:
[Huawei] interface Tunnel 0
[Huawei-Tunnel0] ip address 192.168.1.2 255.255.255.0
[Huawei-Tunnel0] tunnel-protocol ipsec
[Huawei-Tunnel0] ipsec policy mypolicy
[Huawei-Tunnel0] tunnel source GigabitEthernet 0/0/1
[Huawei-Tunnel0] tunnel destination 1.1.1.1
[Huawei-Tunnel0] quit
注意:以上命令中的 IP 地址、接口名称、ACL 名称等需要根据实际情况进行修改。另外,这里假设 VPN Server 端的公网 IP 地址为 1.1.1.1,VPN Server 端的 ACL 名称为 3001,VPN Client 端的 ACL 名称为 3000。
阅读全文