IPSEC VPN 点到多点配置
更新时间:2023-03-15 15:07:01 阅读量: 教育文库 文档下载
总部为静态IP地址,分支为动态拨号获得IP地址不稳定。搭建IPSEC VPN
总部USG-1配置
[USG-1]firewall zone trust [USG-1-zone-trust]add int g0/0/0 [USG-1-zone-trust]quit [USG-1]firewall zon untrust
[USG-1-zone-untrust]add int g0/0/1 [USG-1-zone-untrust]quit
[USG-1]ip route-static 0.0.0.0 0.0.0.0 11.0.0.1 [USG-1]int g0/0/1
[USG-1-GigabitEthernet0/0/1]ip add 11.0.0.2 24 [USG-1-GigabitEthernet0/0/1]int g0/0/0
[USG-1-GigabitEthernet0/0/0]ip add 192.168.10.1 24 [USG-1-GigabitEthernet0/0/0]quit
------------------------阶段一---------------------------- [USG-1]ike proposal 1//配置一个安全提议
[USG-1-ike-proposal-1]authentication-method pre-share
//配置IKE认证方式为预共享密钥
[USG-1-ike-proposal-1]authentication-algorithm sha1
//配置IKE认证算法为sha1
[USG-1-ike-proposal-1]integrity-algorithm aes-xcbc-96
//配置IKE完整性算法
[USG-1-ike-proposal-1]dh group2
//配置IKE密钥协商DH组
[USG-1-ike-proposal-1]quit
[USG-1]ike peer usg-n//创建一个IKE对等体名字为usg-n [USG-1-ike-peer-usg-n]ike-proposal 1//调用ike安全提议 [USG-1-ike-peer-usg-n]pre-shared-key abc123//配置预共享密钥 [USG-1-ike-peer-usg-n]quit
注意:由于对端地址不是固定的所以不需要指定对端地址
------------------------阶段二----------------------------- [USG-1]ipsec proposal test //配置一个ipsec安全提议
[USG-1-ipsec-proposal-test]encapsulation-mode tunnel//封装方式采用隧道 [USG-1-ipsec-proposal-test]transform esp//配置IPSEC安全协议为ESP [USG-1-ipsec-proposal-test]esp authentication-algorithm sha1
//配置ESP协议认证算法
[USG-1-ipsec-proposal-test]esp encryption-algorithm aes
//配置ESP协议加密算法为aes
[USG-1-ipsec-proposal-test]quit
[USG-1]acl 3000//创建一个ACL定义感兴趣流
[USG-1-acl-adv-3000]rule permit ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255 [USG-1-acl-adv-3000]quit
-------------------------配置策略模板----------------------------- [USG-1]ipsec policy-template tem 1 //创建一个策略模板
[USG-1-ipsec-policy-template-tem-1]ike-peer usg-n//调用ike对等体 [USG-1-ipsec-policy-template-tem-1]proposal test//调用IPsec安全提议 [USG-1-ipsec-policy-template-tem-1]security acl 3000//配置感兴趣流 [USG-1-ipsec-policy-template-tem-1]quit [USG-1]ipsec policy map 1 isakmp template tem //创建一个策略叫map然后和配置模板关联起来 [USG-1]int g0/0/1
[USG-1-GigabitEthernet0/0/1]ipsec policy map //接口下调用策略 [USG-1-GigabitEthernet0/0/1]quit
区域间策略配置
[USG-1]policy interzone trust untrust outbound
[USG-1-policy-interzone-trust-untrust-outbound]policy 1
[USG-1-policy-interzone-trust-untrust-outbound-1]action permit [USG-1-policy-interzone-trust-untrust-outbound-1]quit [USG-1-policy-interzone-trust-untrust-outbound]quit [USG-1]policy interzone trust untrust inbound
[USG-1-policy-interzone-trust-untrust-inbound]policy 1
[USG-1-policy-interzone-trust-untrust-inbound-1]policy source 192.168.20.0 0.0.0.255
[USG-1-policy-interzone-trust-untrust-inbound-1]policy destination 192.168.10.0 0.0.0.255
[USG-1-policy-interzone-trust-untrust-inbound-1]action permit [USG-1-policy-interzone-trust-untrust-inbound-1]quit [USG-1-policy-interzone-trust-untrust-inbound]quit [USG-1]policy interzone local untrust inbound
[USG-1-policy-interzone-local-untrust-inbound]policy 1 [USG-1-policy-interzone-local-untrust-inbound-1]policy
destination
11.0.0.2 0 //允许任何人访问目标为11.0.0.2
[USG-1-policy-interzone-local-untrust-inbound-1]action permit [USG-1-policy-interzone-local-untrust-inbound-1]quit [USG-1-policy-interzone-local-untrust-inbound]quit
分支配置
[USG-2]firewall zone trust [USG-2-zone-trust]add int g0/0/0 [USG-2-zone-trust]quit [USG-2]firewall zone untrust [USG-2-zone-untrust]add int g0/0/1 [USG-2-zone-untrust]quit [USG-2]int g0/0/0
[USG-2-GigabitEthernet0/0/0]ip add 192.168.20.1 24 [USG-2-GigabitEthernet0/0/0]int g0/0/1
[USG-2-GigabitEthernet0/0/1]ip add 12.0.0.2 24 [USG-2-GigabitEthernet0/0/1]quit
[USG-2]ip route-static 0.0.0.0 0.0.0.0 12.0.0.1
----------------------------阶段一----------------------------- [USG-2]ike proposal 1
[USG-2-ike-proposal-1]authentication-method pre-share [USG-2-ike-proposal-1]authentication-algorithm sha1 [USG-2-ike-proposal-1]integrity-algorithm aes-xcbc-96 [USG-2-ike-proposal-1]dh group2 [USG-2-ike-proposal-1]quit [USG-2]ike peer usg-1
[USG-2-ike-peer-usg-1]ike-proposal 1
[USG-2-ike-peer-usg-1]pre-shared-key abc123 [USG-2-ike-peer-usg-1]remote-address 11.0.0.2 [USG-2-ike-peer-usg-1]quit
----------------------------阶段二-------------------------------- [USG-2]ipsec proposal test
[USG-2-ipsec-proposal-test]encapsulation-mode tunnel [USG-2-ipsec-proposal-test]transform esp
[USG-2-ipsec-proposal-test]esp authentication-algorithm sha1 [USG-2-ipsec-proposal-test]esp encryption-algorithm aes [USG-2-ipsec-proposal-test]quit [USG-2]acl 3000
[USG-2-acl-adv-3000]rule permit ip source 192.168.20.0 0.0.0.255 destination 192.168.10.0 0.0.0.255 [USG-2-acl-adv-3000]quit
-----------------------------配
置
安
全
策
-------------------------------
略
[USG-2]ipsec policy map 1 isakmp
[USG-2-ipsec-policy-isakmp-map-1]ike-peer usg-1 [USG-2-ipsec-policy-isakmp-map-1]proposal test [USG-2-ipsec-policy-isakmp-map-1]security acl 3000 [USG-2-ipsec-policy-isakmp-map-1]quit [USG-2]int g0/0/1
[USG-2-GigabitEthernet0/0/1]ipsec policy map auto-neg
//如果不加auto-neg的话,只有分支主动触发流量隧道才会建立否则总公司不能和分支通信。加了auto-neg的话隧道则会自动建立 [USG-2-GigabitEthernet0/0/1]quit
[USG-2]policy interzone trust untrust outbound
[USG-2-policy-interzone-trust-untrust-outbound]policy 1
[USG-2-policy-interzone-trust-untrust-outbound-1]action permit [USG-2-policy-interzone-trust-untrust-outbound-1]quit [USG-2-policy-interzone-trust-untrust-outbound]quit [USG-2]policy interzone trust untrust inbound
[USG-2-policy-interzone-trust-untrust-inbound]policy 1
[USG-2-policy-interzone-trust-untrust-inbound-1]policy source 192.168.10.0 0.0.0.255
[USG-2-policy-interzone-trust-untrust-inbound-1]policy destination 192.168.20.0 0.0.0.255
[USG-2-policy-interzone-trust-untrust-inbound-1]action permit [USG-2-policy-interzone-trust-untrust-inbound-1]quit [USG-2-policy-interzone-trust-untrust-inbound]quit [USG-2]policy interzone local untrust inbound
[USG-2-policy-interzone-local-untrust-inbound]policy 1
[USG-2-policy-interzone-local-untrust-inbound-1]policy source 11.0.0.2 0
[USG-2-policy-interzone-local-untrust-inbound-1]action permit
正在阅读:
IPSEC VPN 点到多点配置03-15
13级法理学教案104-09
食品广告语大全02-10
花香伴我成长作文07-09
云南省人民政府关于印发云南省旅游宣传促销费征收管理暂行规定03-24
第4章发动机2要点03-07
一叶知秋作文500字07-15
五年级英语下册第五单元测试卷03-29
小学生安全知识手册102-20
国学包括哪些书02-18
- exercise2
- 铅锌矿详查地质设计 - 图文
- 厨余垃圾、餐厨垃圾堆肥系统设计方案
- 陈明珠开题报告
- 化工原理精选例题
- 政府形象宣传册营销案例
- 小学一至三年级语文阅读专项练习题
- 2014.民诉 期末考试 复习题
- 巅峰智业 - 做好顶层设计对建设城市的重要意义
- (三起)冀教版三年级英语上册Unit4 Lesson24练习题及答案
- 2017年实心轮胎现状及发展趋势分析(目录)
- 基于GIS的农用地定级技术研究定稿
- 2017-2022年中国医疗保健市场调查与市场前景预测报告(目录) - 图文
- 作业
- OFDM技术仿真(MATLAB代码) - 图文
- Android工程师笔试题及答案
- 生命密码联合密码
- 空间地上权若干法律问题探究
- 江苏学业水平测试《机械基础》模拟试题
- 选课走班实施方案
- 多点
- 点到
- 配置
- IPSEC
- VPN
- 人教版试题试卷第7章 现代生物进化理伦 单元测试
- 中共区委政法委书记办公会议制度
- 室内环境的重要性
- 福师15春大学英语(1)在线作业一答案
- 试验室自查自纠整改情况的报告样本 - 图文
- 北工大自行车里程表 - 图文
- 基站开通流程及常见问题
- 第一章 数码相机的基本知识
- 《面向对象程序设计》实验指导书
- 江苏区域经济发展差异及对策
- 小学保障适龄儿童、少年入学措施
- 二级C上机考试考试题库、程序修改题
- 山东省利津县第一实验学校九年级化学上册 第三单元 课题3 元素导学案2无答案新版新人教版
- 大学物理第二章
- 山东省武城县第二中学2016届高三下学期第一次月考数学(理)试题含答案
- BiOI光催化剂对亚甲基蓝降解性能研究 - 图文
- 计算机组成原理期末复习资料
- 国际经济学练习题及其答案
- 江苏省射阳县第二中学2015届高三数学一轮复习 第9课时 函数与方程导学案 苏教版
- 畜牧标准化养殖等项目 中央预算内投资专项管理办法(试行)