AR4路由器配置
[Huawei]undo info-center enable // 关闭信息中心
[Huawei]sysname AR4 // 设置系统名称为 AR4
#
[AR4]interface Serial4/0/0 // 进入 Serial4/0/0 接口
[AR4-Serial4/0/0]ip address 200.22.103.4 255.255.255.0 // 配置 IP 地址为 200.22.103.4/24
#
[AR4]interface GigabitEthernet0/0/0 // 进入 GigabitEthernet0/0/0 接口
[AR4-GigabitEthernet0/0/0]ip address 192.22.103.254 255.255.255.0 // 配置 IP 地址为 192.22.103.254/24
#
[AR4]ip route-static 192.22.104.0 255.255.255.0 200.22.103.1 // 配置静态路由到 192.22.104.0/24
[AR4]ip route-static 192.22.105.0 255.255.255.0 200.22.103.1 // 配置静态路由到 192.22.105.0/24
[AR4]ip route-static 200.22.104.0 255.255.255.0 200.22.103.1 // 配置静态路由到 200.22.104.0/24
[AR4]ip route-static 200.22.105.0 255.255.255.0 200.22.103.1 // 配置静态路由到 200.22.105.0/24
#
[AR4]acl number 3000 // 创建 ACL 编号 3000
[AR4-acl-adv-3000] rule 5 permit ip source 192.22.103.0 0.0.0.255 destination 192.22.104.0 0.0.0.255 // 允许源 IP 192.22.103.0/24 到目标 IP 192.22.104.0/24 的流量
#
[AR4]acl number 3001 // 创建 ACL 编号 3001
[AR4-acl-adv-3001] rule 5 permit ip source 192.22.103.0 0.0.0.255 destination 192.22.105.0 0.0.0.255 // 允许源 IP 192.22.103.0/24 到目标 IP 192.22.105.0/24 的流量
#
[AR4]ipsec proposal 1 // 配置 IPsec 提案 1
[AR4-ipsec-proposal-1]esp authentication-algorithm md5 // 配置 ESP 认证算法为 MD5
[AR4-ipsec-proposal-1]esp encryption-algorithm des // 配置 ESP 加密算法为 DES
#
[AR4]ipsec proposal 2 // 配置 IPsec 提案 2
[AR4-ipsec-proposal-2] esp authentication-algorithm sha1 // 配置 ESP 认证算法为 SHA1
[AR4-ipsec-proposal-2]esp encryption-algorithm des // 配置 ESP 加密算法为 DES
#
[AR4]ike proposal 1 // 配置 IKE 提案 1
[AR4-ike-proposal-1] encryption-algorithm aes-cbc-128 // 配置加密算法为 AES-CBC-128
[AR4-ike-proposal-1] dh group14 // 配置 DH 组为 Group 14
#
[AR4]ike peer ar2 v1 // 配置 IKE 对等体 ar2
[AR4-ike-peer-ar2] pre-shared-key cipher xxx // 配置预共享密钥
[AR4-ike-peer-ar2] ike-proposal 1 // 关联 IKE 提案 1
[AR4-ike-peer-ar2] remote-address 200.22.104.2 // 配置远端地址为 200.22.104.2
#
[AR4]ike peer ar3 v1 // 配置 IKE 对等体 ar3
[AR4-ike-peer-ar3] pre-shared-key cipher xxx // 配置预共享密钥
[AR4-ike-peer-ar3] ike-proposal 1 // 关联 IKE 提案 1
[AR4-ike-peer-ar3] remote-address 200.22.105.3 // 配置远端地址为 200.22.105.3
#
[AR4]ipsec policy ips 1 isakmp // 配置 IPsec 策略 ips 1,模式为 ISAKMP
[AR4-ipsec-policy-isakmp-ips-1] security acl 3000 // 关联 ACL 3000
[AR4-ipsec-policy-isakmp-ips-1] ike-peer ar2 // 关联 IKE 对等体 ar2
[AR4-ipsec-policy-isakmp-ips-1] proposal 1 // 关联 IPsec 提案 1
#
[AR4]ipsec policy ips 2 isakmp // 配置 IPsec 策略 ips 2,模式为 ISAKMP
[AR4-ipsec-policy-isakmp-ips-2] security acl 3001 // 关联 ACL 3001
[AR4-ipsec-policy-isakmp-ips-2] ike-peer ar3 // 关联 IKE 对等体 ar3
[AR4-ipsec-policy-isakmp-ips-2] proposal 2 // 关联 IPsec 提案 2
#
[AR4]interface Serial4/0/0 // 进入 Serial4/0/0 接口
[AR4-Serial4/0/0]ipsec policy ips // 应用 IPsec 策略 ips
公网路由器只有ip配置
[Huawei]un in en
[Huawei]sys AR1
[AR1]inte s4/0/0
[AR1-Serial4/0/0]ip ad 200.22.103.1 24
[AR1-Serial4/0/0]inte s4/0/1
[AR1-Serial4/0/1]ip ad 200.22.104.1 24
[AR1-Serial4/0/1]inte s3/0/0
[AR1-Serial3/0/0]ip ad 200.22.105.1 24
[AR1-Serial3/0/0]
分部1路由器,ipsec内容与总部互为镜像
[Huawei]un in en
Info: Information center is disabled.
[Huawei]
[Huawei]sys AR2
[AR2]
[AR2]inte g0/0/0
[AR2-GigabitEthernet0/0/0]
[AR2-GigabitEthernet0/0/0]ip ad 192.22.104.254 24
[AR2-GigabitEthernet0/0/0]
[AR2-GigabitEthernet0/0/0]inte s4/0/0
[AR2-Serial4/0/0]
[AR2-Serial4/0/0]ip ad 200.22.104.2 24
[AR2-Serial4/0/0]
[AR2-Serial4/0/0]ip route-sta 200.22.103.0 24 200.22.104.1
[AR2]
[AR2]ip route-sta 192.22.103.0 24 200.22.104.1
[AR2]
[AR2]acl number 3000
[AR2-acl-adv-3000]
[AR2-acl-adv-3000] rule 5 permit ip source 192.22.104.0 0.0.0.255 destination 192.22.103.0 0.0.0.255
[AR2-acl-adv-3000]ipsec proposal 1
[AR2-ipsec-proposal-1]q
[AR2]ike proposal 1
[AR2-ike-proposal-1]
[AR2-ike-proposal-1] encryption-algorithm aes-cbc-128
[AR2-ike-proposal-1]
[AR2-ike-proposal-1] dh group14
[AR2-ike-proposal-1]q
[AR2]ike peer ar4 v1
[AR2-ike-peer-ar4]
[AR2-ike-peer-ar4] pre-shared-key cipher xxx
[AR2-ike-peer-ar4]
[AR2-ike-peer-ar4] ike-proposal 1
[AR2-ike-peer-ar4]
[AR2-ike-peer-ar4] remote-address 200.22.103.1
[AR2-ike-peer-ar4]ipsec policy ips 1 isakmp
[AR2-ipsec-policy-isakmp-ips-1]
[AR2-ipsec-policy-isakmp-ips-1] security acl 3000
[AR2-ipsec-policy-isakmp-ips-1]
[AR2-ipsec-policy-isakmp-ips-1] ike-peer ar4
[AR2-ipsec-policy-isakmp-ips-1]
[AR2-ipsec-policy-isakmp-ips-1] proposal 1
[AR2-ipsec-policy-isakmp-ips-1]inte s4/0/0
[AR2-Serial4/0/0]ipsec policy ips
[AR2-Serial4/0/0]q
分部2路由器,ipsec内容与总部互为镜像
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]
[Huawei]un in en
Info: Information center is disabled.
[Huawei]
[Huawei]sys AR3
[AR3]
[AR3]inte g0/0/0
[AR3-GigabitEthernet0/0/0]
[AR3-GigabitEthernet0/0/0]ip ad 192.22.105.254 24
[AR3-GigabitEthernet0/0/0]
[AR3-GigabitEthernet0/0/0]inte s4/0/0
[AR3-Serial4/0/0]
[AR3-Serial4/0/0]ip ad 200.22.105.3 24
[AR3-Serial4/0/0]
[AR3-Serial4/0/0]ip route-sta 200.22.103.0 24 200.22.105.1
[AR3]
[AR3]ip route-sta 192.22.103.0 24 200.22.105.1
[AR3]acl number 3000
[AR3-acl-adv-3000]
[AR3-acl-adv-3000] rule 5 permit ip source 192.22.105.0 0.0.0.255 destination 192.22.103.0 0.0.0.255
[AR3-acl-adv-3000]ipsec proposal 2
[AR3-ipsec-proposal-2]
[AR3-ipsec-proposal-2] esp authentication-algorithm sha1
[AR3-ipsec-proposal-2]ike proposal 1
[AR3-ike-proposal-1]
[AR3-ike-proposal-1] encryption-algorithm aes-cbc-128
[AR3-ike-proposal-1]
[AR3-ike-proposal-1] dh group14
[AR3-ike-proposal-1]q
[AR3]ike peer ar4 v1
[AR3-ike-peer-ar4]
[AR3-ike-peer-ar4] pre-shared-key cipher xxx
[AR3-ike-peer-ar4]
[AR3-ike-peer-ar4] ike-proposal 1
[AR3-ike-peer-ar4]
[AR3-ike-peer-ar4] remote-address 200.22.103.1
[AR3-ike-peer-ar4]q
[AR3]ipsec policy ips 1 isakmp
[AR3-ipsec-policy-isakmp-ips-1]
[AR3-ipsec-policy-isakmp-ips-1] security acl 3000
[AR3-ipsec-policy-isakmp-ips-1]
[AR3-ipsec-policy-isakmp-ips-1] ike-peer ar4
[AR3-ipsec-policy-isakmp-ips-1]
[AR3-ipsec-policy-isakmp-ips-1] proposal 2
[AR3-ipsec-policy-isakmp-ips-1]inte s4/0/0
[AR3-Serial4/0/0]ipsec policy ips
[AR3-Serial4/0/0]
查看ike sa和ipsec sa摘要信息
连通性测试
根据抓包内容,可见总部访问分部1和2的流量都被加上密,报文为esp