IPSec主要功能:

  • 给IP报文加密
  • 提供隧道

IPSec可以点到点,也可以点到多点,点到多点建议使用DSv*n

IPSes配置

IPSec配置

AR1配置

第一步:配置端口IP

<Huawei>sys
[Huawei]int gi 0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 192.168.1.1 24
[Huawei-GigabitEthernet0/0/1]int gi 0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 192.1.12.1 30
[Huawei-GigabitEthernet0/0/0]

第二步:配置静态路由,解决网络通讯问题

[Huawei]ip route-static 192.1.23.0 30 192.1.12.2
[Huawei]ip route-static 192.168.2.0 24 192.1.12.2

第三步:定义ACL,匹配流量

[Huawei]acl 3000
[Huawei-acl-adv-3000]rule permit ip source 192.168.1.0 0.0.0.255 destination 192
.168.2.0 0.0.0.255
[Huawei-acl-adv-3000]q

第四步:创建一个安全协议
[Huawei]ipsec proposal xhlab
[Huawei-ipsec-proposal-xhlab]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-xhlab]esp encryption-algorithm aes-128
[Huawei-ipsec-proposal-xhlab]q

第五步:创建ipsec sa阶段

[Huawei]ipsec policy xhlab-policy 1 manual
[Huawei-ipsec-policy-manual-xhlab-policy-1]security acl 3000
[Huawei-ipsec-policy-manual-xhlab-policy-1]proposal xhlab
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel local 192.1.12.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel remote 192.1.23.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi inbound esp 54321
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key inbound esp simple huaw
ei
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi outbound esp 12345
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key outbound esp simple hua
wei 
[Huawei-ipsec-policy-manual-xhlab-policy-1]q

第六步:接口下调用

[Huawei]int gi0/0/0
[Huawei-GigabitEthernet0/0/0]ipsec policy xhlab-policy
[Huawei-GigabitEthernet0/0/0]
 



AR2模拟的是Internet,AR2配置只需要配置IP保持连通性

<Huawei>sys
[Huawei]int gi 0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 192.1.12.2 30
[Huawei-GigabitEthernet0/0/0]int gi 0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 192.1.23.2 30
 

AR3配置

<Huawei>sys
[Huawei]int gi 0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 192.1.23.1 30
[Huawei-GigabitEthernet0/0/0]int gi 0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 192.168.2.1 24
[Huawei-GigabitEthernet0/0/1]

[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.1.23.2
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule permit ip source 192.168.2.0 0.0.0.255 destination 
192.168.1.0 0.0.0.255
[Huawei-acl-adv-3000]ipsec proposal xhlab
[Huawei-ipsec-proposal-xhlab]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-xhlab]esp encryption-algorithm aes-128
[Huawei-ipsec-proposal-xhlab]q
[Huawei]ipsec policy xhlab-policy 1 manual
[Huawei-ipsec-policy-manual-xhlab-policy-1]security acl 3000
[Huawei-ipsec-policy-manual-xhlab-policy-1]proposal xhlab
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel local 192.1.23.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel remote 192.1.12.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi inbound esp 12345
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key inbound esp simple huaw
ei
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi outbound esp 54321
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key outbound esp simple hua
wei
[Huawei-ipsec-policy-manual-xhlab-policy-1]q
[Huawei]int gi0/0/0
[Huawei-GigabitEthernet0/0/0]ipsec policy xhlab-policy

检测结果:

IPSec配置

相关文章: