Advertisement

华为IPsec IKE协商方式

阅读量:
1

AR1:
acl number 3000
rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255

ipsec proposal ike

ike proposal 10

ike peer to_ar3 v1
pre-shared-key cipher %%u`Vj70TpB0@>_K8vu71O,.2n%%
ike-proposal 10
remote-address 10.1.23.2

ipsec policy ike 10 isakmp
security acl 3000
ike-peer to_ar3
proposal ike

interface GigabitEthernet0/0/0
ip address 192.168.1.254 255.255.255.0

interface GigabitEthernet0/0/1
ip address 10.1.12.1 255.255.255.0
ipsec policy ike

ip route-static 0.0.0.0 0.0.0.0 10.1.12.2

AR3:
acl number 3000
rule 5 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255

ipsec proposal ike

ike proposal 10

ike peer to_ar1 v1
pre-shared-key cipher %%u`Vj70TpB0@>_K8vu71O,.2n%%
ike-proposal 10
remote-address 10.1.12.1

ipsec policy ike 10 isakmp
security acl 3000
ike-peer to_ar1
proposal ike

interface GigabitEthernet0/0/0
ip address 192.168.2.254 255.255.255.0

interface GigabitEthernet0/0/1
ip address 10.1.23.2 255.255.255.0
ipsec policy ike

ip route-static 0.0.0.0 0.0.0.0 10.1.23.1

dis ipsec proposal name ipsec
dis ipsec proposal ike
dis ike proposal number 10

全部评论 (0)

还没有任何评论哟~