資源描述:
《H3C-Secpath-1000F防火墻-IPsec-VPN-NAT穿越模板方式-典型配置.doc》由會(huì)員上傳分享,免費(fèi)在線閱讀,更多相關(guān)內(nèi)容在教育資源-天天文庫。
1、H3CSecpath1000F防火墻IPsecVPNNAT穿越模板方式典型配置一、組網(wǎng)需求1.實(shí)現(xiàn)武漢和北京兩個(gè)私網(wǎng)的互通。2.北京總部必須是靜態(tài)地址,武漢分部可以是動(dòng)態(tài)獲得也可以是靜態(tài)配置,為私網(wǎng)地址,去Internet需經(jīng)過ISP的NAT網(wǎng)關(guān)。3.要求私網(wǎng)兩個(gè)網(wǎng)段之間的數(shù)據(jù)流量采用IPSEC隧道加密傳輸。二、組網(wǎng)圖三、典型配置防火墻Secpath100F最終配置wuhandiscu#sysnamewuhan#ikelocal-namewuhan#firewallpacket-fi一、組網(wǎng)需求1.???????
2、實(shí)現(xiàn)武漢和北京兩個(gè)私網(wǎng)的互通。2.???????北京總部必須是靜態(tài)地址,武漢分部可以是動(dòng)態(tài)獲得也可以是靜態(tài)配置,為私網(wǎng)地址,去Internet需經(jīng)過ISP的NAT網(wǎng)關(guān)。3.???????要求私網(wǎng)兩個(gè)網(wǎng)段之間的數(shù)據(jù)流量采用IPSEC隧道加密傳輸。??二、組網(wǎng)圖三、典型配置防火墻Secpath100F最終配置discu#sysnamewuhan#ikelocal-namewuhan#firewallpacket-filterenablefirewallpacket-filterdefaultpermit
3、#insulate#undoconnection-limitenableconnection-limitdefaultdenyconnection-limitdefaultamountupper-limit50lower-limit20#firewallstatisticsystemenable#radiusschemesystem#domainsystem#ikepeer1//配置IKE參數(shù)exchange-modeaggressive//配置為野蠻模式pre-shared-key12345//配置預(yù)共享密鑰i
4、d-typename//ID類型為名字remote-namebeijing//對(duì)端名字為beijingremote-address202.38.1.1//對(duì)端公網(wǎng)IPnattraversal//支持NAT穿越#ipsecproposalp1//定義安全提議#ipsecpolicypolicy11isakmp//定義安全策略securityacl3000//定義所保護(hù)的數(shù)據(jù)流ike-peer1//應(yīng)用的IKEproposalp1//應(yīng)用的安全提議#aclnumber3000rule0permitipsource10
5、.1.2.00.0.0.255destination10.1.1.00.0.0.255rule1denyip#interfaceAux0asyncmodeflow#interfaceEthernet0/0ipaddress172.16.1.1255.255.255.0#interfaceEthernet0/1#interfaceEthernet0/2#interfaceEthernet0/3#interfaceEthernet1/0#interfaceEthernet1/1#interfaceEthernet1/
6、2#interfaceNULL0#interfaceLoopBack0ipaddress10.1.2.1255.255.255.0#firewallzonelocalsetpriority100#firewallzonetrustaddinterfaceEthernet0/0setpriority85#firewallzoneuntrustsetpriority5#firewallzoneDMZsetpriority50#firewallinterzonelocaltrust#firewallinterzonel
7、ocaluntrust#firewallinterzonelocalDMZ#firewallinterzonetrustuntrust#firewallinterzonetrustDMZ#firewallinterzoneDMZuntrust#iproute-static0.0.0.00.0.0.0172.16.1.2preference60#user-interfacecon0user-interfaceaux0user-interfacevty04#return防火墻Secpath1000F最終
8、配置[beijing]discu#sysnamebeijing#ikelocal-namebeijing#firewallpacket-filterenablefirewallpacket-filterdefaultpermit#undoconnection-limitenableconnection-limitdefaultdenyconnection-limitdef