前往小程序,Get更优阅读体验!
立即前往
首页
学习
活动
专区
工具
TVP
发布
社区首页 >专栏 >H3C配置IPSEC ×××

H3C配置IPSEC ×××

作者头像
py3study
发布2020-01-10 17:09:28
6660
发布2020-01-10 17:09:28
举报
文章被收录于专栏:python3python3

H3C配置IPSEC ×××思路跟思科差不多,无非就是命令不一样的,下面就演示一下

拓扑:

121001321.png
121001321.png

RT1背后有个1.1.1.1网段,RT3背后有个3.3.3.3网段,ISP没有这两条路由

RT2:

<RT2>system-view

System View: return to User View with Ctrl+Z.

[RT2]int g0/0/0

[RT2-GigabitEthernet0/0/0]ip add 12.1.1.2 24

[RT2-GigabitEthernet0/0/0]quit

[RT2]int g0/0/1

[RT2-GigabitEthernet0/0/1]ip add 23.1.1.2 24

[RT2-GigabitEthernet0/0/1]quit

RT1:

acl number 3000

rule 0 permit ip source 1.1.1.0 0.0.0.255 destination 3.3.3.0 0.0.0.255

ike proposal 1

encryption-algorithm 3des-cbc

authentication-algorithm md5

authentication-metod pre-share

dh group2

ike peer cisco

id-type ip

pre-shared-key simple cisco

remote-address 23.1.1.3

local-address 12.1.1.1

#

ipsec proposal cisco

transform esp

esp authentication-algorithm md5

esp encryption-algorithm 3des

ipsec policy cisco 10 isakmp

security acl 3000

ike-peer cisco

proposal cisco

int g0/0/0

ipsec policy cisco

ip route-static 0.0.0.0 0.0.0.0 12.1.1.2

RT3:

acl number 3000

rule 0 permit ip source 3.3.3.0 0.0.0.255 destination 1.1.1.0 0.0.0.255

ike proposal 1

encryption-algorithm 3des-cbc

authentication-algorithm md5

authentication-metod pre-share

dh group2

ike peer cisco

id-type ip

pre-shared-key simple cisco

remote-address 12.1.1.1

local-address 23.1.1.3

#

ipsec proposal cisco

transform esp

esp authentication-algorithm md5

esp encryption-algorithm 3des

ipsec policy cisco 10 isakmp

security acl 3000

ike-peer cisco

proposal cisco

int g0/0/1

ipsec policy cisco

ip route-static 0.0.0.0 0.0.0.0 23.1.1.2

效果:

123018194.png
123018194.png
本文参与 腾讯云自媒体分享计划,分享自作者个人站点/博客。
原始发表:2019-08-21 ,如有侵权请联系 cloudcommunity@tencent.com 删除

本文分享自 作者个人站点/博客 前往查看

如有侵权,请联系 cloudcommunity@tencent.com 删除。

本文参与 腾讯云自媒体分享计划  ,欢迎热爱写作的你一起参与!

评论
登录后参与评论
0 条评论
热度
最新
推荐阅读
领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档