IPSec主要功能:
- 给IP报文加密
- 提供隧道
IPSec可以点到点,也可以点到多点,点到多点建议使用DSv*n
IPSes配置
AR1配置
第一步:配置端口IP
<Huawei>sys
[Huawei]int gi 0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 192.168.1.1 24
[Huawei-GigabitEthernet0/0/1]int gi 0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 192.1.12.1 30
[Huawei-GigabitEthernet0/0/0]
第二步:配置静态路由,解决网络通讯问题
[Huawei]ip route-static 192.1.23.0 30 192.1.12.2
[Huawei]ip route-static 192.168.2.0 24 192.1.12.2
第三步:定义ACL,匹配流量
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule permit ip source 192.168.1.0 0.0.0.255 destination 192
.168.2.0 0.0.0.255
[Huawei-acl-adv-3000]q
第四步:创建一个安全协议
[Huawei]ipsec proposal xhlab
[Huawei-ipsec-proposal-xhlab]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-xhlab]esp encryption-algorithm aes-128
[Huawei-ipsec-proposal-xhlab]q
第五步:创建ipsec sa阶段
[Huawei]ipsec policy xhlab-policy 1 manual
[Huawei-ipsec-policy-manual-xhlab-policy-1]security acl 3000
[Huawei-ipsec-policy-manual-xhlab-policy-1]proposal xhlab
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel local 192.1.12.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel remote 192.1.23.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi inbound esp 54321
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key inbound esp simple huaw
ei
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi outbound esp 12345
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key outbound esp simple hua
wei
[Huawei-ipsec-policy-manual-xhlab-policy-1]q
第六步:接口下调用
[Huawei]int gi0/0/0
[Huawei-GigabitEthernet0/0/0]ipsec policy xhlab-policy
[Huawei-GigabitEthernet0/0/0]
AR2模拟的是Internet,AR2配置只需要配置IP保持连通性
<Huawei>sys
[Huawei]int gi 0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 192.1.12.2 30
[Huawei-GigabitEthernet0/0/0]int gi 0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 192.1.23.2 30
AR3配置
<Huawei>sys
[Huawei]int gi 0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 192.1.23.1 30
[Huawei-GigabitEthernet0/0/0]int gi 0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 192.168.2.1 24
[Huawei-GigabitEthernet0/0/1]
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.1.23.2
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule permit ip source 192.168.2.0 0.0.0.255 destination
192.168.1.0 0.0.0.255
[Huawei-acl-adv-3000]ipsec proposal xhlab
[Huawei-ipsec-proposal-xhlab]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-xhlab]esp encryption-algorithm aes-128
[Huawei-ipsec-proposal-xhlab]q
[Huawei]ipsec policy xhlab-policy 1 manual
[Huawei-ipsec-policy-manual-xhlab-policy-1]security acl 3000
[Huawei-ipsec-policy-manual-xhlab-policy-1]proposal xhlab
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel local 192.1.23.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]tunnel remote 192.1.12.1
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi inbound esp 12345
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key inbound esp simple huaw
ei
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa spi outbound esp 54321
[Huawei-ipsec-policy-manual-xhlab-policy-1]sa string-key outbound esp simple hua
wei
[Huawei-ipsec-policy-manual-xhlab-policy-1]q
[Huawei]int gi0/0/0
[Huawei-GigabitEthernet0/0/0]ipsec policy xhlab-policy