华为ensp基于路由器点到多点的ipsec v-p-n加密隧道配置(1总2分部场景)

AR4路由器配置

[Huawei]undo info-center enable // 关闭信息中心
[Huawei]sysname AR4 // 设置系统名称为 AR4
#
[AR4]interface Serial4/0/0 // 进入 Serial4/0/0 接口
[AR4-Serial4/0/0]ip address 200.22.103.4 255.255.255.0 // 配置 IP 地址为 200.22.103.4/24
#
[AR4]interface GigabitEthernet0/0/0 // 进入 GigabitEthernet0/0/0 接口
[AR4-GigabitEthernet0/0/0]ip address 192.22.103.254 255.255.255.0 // 配置 IP 地址为 192.22.103.254/24
#
[AR4]ip route-static 192.22.104.0 255.255.255.0 200.22.103.1 // 配置静态路由到 192.22.104.0/24
[AR4]ip route-static 192.22.105.0 255.255.255.0 200.22.103.1 // 配置静态路由到 192.22.105.0/24
[AR4]ip route-static 200.22.104.0 255.255.255.0 200.22.103.1 // 配置静态路由到 200.22.104.0/24
[AR4]ip route-static 200.22.105.0 255.255.255.0 200.22.103.1 // 配置静态路由到 200.22.105.0/24
#
[AR4]acl number 3000 // 创建 ACL 编号 3000
[AR4-acl-adv-3000] rule 5 permit ip source 192.22.103.0 0.0.0.255 destination 192.22.104.0 0.0.0.255 // 允许源 IP 192.22.103.0/24 到目标 IP 192.22.104.0/24 的流量
#
[AR4]acl number 3001 // 创建 ACL 编号 3001
[AR4-acl-adv-3001] rule 5 permit ip source 192.22.103.0 0.0.0.255 destination 192.22.105.0 0.0.0.255 // 允许源 IP 192.22.103.0/24 到目标 IP 192.22.105.0/24 的流量
#
[AR4]ipsec proposal 1 // 配置 IPsec 提案 1
[AR4-ipsec-proposal-1]esp authentication-algorithm md5 // 配置 ESP 认证算法为 MD5
[AR4-ipsec-proposal-1]esp encryption-algorithm des // 配置 ESP 加密算法为 DES
#
[AR4]ipsec proposal 2 // 配置 IPsec 提案 2
[AR4-ipsec-proposal-2] esp authentication-algorithm sha1 // 配置 ESP 认证算法为 SHA1
[AR4-ipsec-proposal-2]esp encryption-algorithm des // 配置 ESP 加密算法为 DES
#
[AR4]ike proposal 1 // 配置 IKE 提案 1
[AR4-ike-proposal-1] encryption-algorithm aes-cbc-128 // 配置加密算法为 AES-CBC-128
[AR4-ike-proposal-1] dh group14 // 配置 DH 组为 Group 14
#
[AR4]ike peer ar2 v1 // 配置 IKE 对等体 ar2
[AR4-ike-peer-ar2] pre-shared-key cipher xxx // 配置预共享密钥
[AR4-ike-peer-ar2] ike-proposal 1 // 关联 IKE 提案 1
[AR4-ike-peer-ar2] remote-address 200.22.104.2 // 配置远端地址为 200.22.104.2
#
[AR4]ike peer ar3 v1 // 配置 IKE 对等体 ar3
[AR4-ike-peer-ar3] pre-shared-key cipher xxx // 配置预共享密钥
[AR4-ike-peer-ar3] ike-proposal 1 // 关联 IKE 提案 1
[AR4-ike-peer-ar3] remote-address 200.22.105.3 // 配置远端地址为 200.22.105.3
#
[AR4]ipsec policy ips 1 isakmp // 配置 IPsec 策略 ips 1,模式为 ISAKMP
[AR4-ipsec-policy-isakmp-ips-1] security acl 3000 // 关联 ACL 3000
[AR4-ipsec-policy-isakmp-ips-1] ike-peer ar2 // 关联 IKE 对等体 ar2
[AR4-ipsec-policy-isakmp-ips-1] proposal 1 // 关联 IPsec 提案 1
#
[AR4]ipsec policy ips 2 isakmp // 配置 IPsec 策略 ips 2,模式为 ISAKMP
[AR4-ipsec-policy-isakmp-ips-2] security acl 3001 // 关联 ACL 3001
[AR4-ipsec-policy-isakmp-ips-2] ike-peer ar3 // 关联 IKE 对等体 ar3
[AR4-ipsec-policy-isakmp-ips-2] proposal 2 // 关联 IPsec 提案 2
#
[AR4]interface Serial4/0/0 // 进入 Serial4/0/0 接口
[AR4-Serial4/0/0]ipsec policy ips // 应用 IPsec 策略 ips

公网路由器只有ip配置 

[Huawei]un in en 
[Huawei]sys AR1
[AR1]inte s4/0/0
[AR1-Serial4/0/0]ip ad 200.22.103.1 24
[AR1-Serial4/0/0]inte s4/0/1
[AR1-Serial4/0/1]ip ad 200.22.104.1 24
[AR1-Serial4/0/1]inte s3/0/0
[AR1-Serial3/0/0]ip ad 200.22.105.1 24
[AR1-Serial3/0/0]

分部1路由器,ipsec内容与总部互为镜像 

[Huawei]un in en 
Info: Information center is disabled.
[Huawei]
[Huawei]sys AR2
[AR2]
[AR2]inte g0/0/0
[AR2-GigabitEthernet0/0/0]
[AR2-GigabitEthernet0/0/0]ip ad 192.22.104.254 24
[AR2-GigabitEthernet0/0/0]
[AR2-GigabitEthernet0/0/0]inte s4/0/0
[AR2-Serial4/0/0]
[AR2-Serial4/0/0]ip ad 200.22.104.2 24
[AR2-Serial4/0/0]
[AR2-Serial4/0/0]ip route-sta 200.22.103.0 24 200.22.104.1
[AR2]
[AR2]ip route-sta 192.22.103.0 24 200.22.104.1
[AR2]
[AR2]acl number 3000  
[AR2-acl-adv-3000]
[AR2-acl-adv-3000] rule 5 permit ip source 192.22.104.0 0.0.0.255 destination 192.22.103.0 0.0.0.255 
[AR2-acl-adv-3000]ipsec proposal 1
[AR2-ipsec-proposal-1]q
[AR2]ike proposal 1
[AR2-ike-proposal-1]
[AR2-ike-proposal-1] encryption-algorithm aes-cbc-128
[AR2-ike-proposal-1]
[AR2-ike-proposal-1] dh group14
[AR2-ike-proposal-1]q
[AR2]ike peer ar4 v1
[AR2-ike-peer-ar4]
[AR2-ike-peer-ar4] pre-shared-key cipher xxx
[AR2-ike-peer-ar4]
[AR2-ike-peer-ar4] ike-proposal 1
[AR2-ike-peer-ar4]
[AR2-ike-peer-ar4] remote-address 200.22.103.1
[AR2-ike-peer-ar4]ipsec policy ips 1 isakmp
[AR2-ipsec-policy-isakmp-ips-1]
[AR2-ipsec-policy-isakmp-ips-1] security acl 3000
[AR2-ipsec-policy-isakmp-ips-1]
[AR2-ipsec-policy-isakmp-ips-1] ike-peer ar4
[AR2-ipsec-policy-isakmp-ips-1]
[AR2-ipsec-policy-isakmp-ips-1] proposal 1
[AR2-ipsec-policy-isakmp-ips-1]inte s4/0/0
[AR2-Serial4/0/0]ipsec policy ips
[AR2-Serial4/0/0]q

分部2路由器,ipsec内容与总部互为镜像 

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]
[Huawei]un in en 
Info: Information center is disabled.
[Huawei]
[Huawei]sys AR3
[AR3]
[AR3]inte g0/0/0
[AR3-GigabitEthernet0/0/0]
[AR3-GigabitEthernet0/0/0]ip ad 192.22.105.254 24
[AR3-GigabitEthernet0/0/0]
[AR3-GigabitEthernet0/0/0]inte s4/0/0
[AR3-Serial4/0/0]
[AR3-Serial4/0/0]ip ad 200.22.105.3 24
[AR3-Serial4/0/0]
[AR3-Serial4/0/0]ip route-sta 200.22.103.0 24 200.22.105.1
[AR3]
[AR3]ip route-sta 192.22.103.0 24 200.22.105.1
[AR3]acl number 3000 
[AR3-acl-adv-3000]
[AR3-acl-adv-3000] rule 5 permit ip source 192.22.105.0 0.0.0.255 destination 192.22.103.0 0.0.0.255
[AR3-acl-adv-3000]ipsec proposal 2
[AR3-ipsec-proposal-2]
[AR3-ipsec-proposal-2] esp authentication-algorithm sha1
[AR3-ipsec-proposal-2]ike proposal 1
[AR3-ike-proposal-1]
[AR3-ike-proposal-1] encryption-algorithm aes-cbc-128
[AR3-ike-proposal-1]
[AR3-ike-proposal-1] dh group14
[AR3-ike-proposal-1]q
[AR3]ike peer ar4 v1
[AR3-ike-peer-ar4]
[AR3-ike-peer-ar4] pre-shared-key cipher xxx
[AR3-ike-peer-ar4]
[AR3-ike-peer-ar4] ike-proposal 1
[AR3-ike-peer-ar4]
[AR3-ike-peer-ar4] remote-address 200.22.103.1
[AR3-ike-peer-ar4]q
[AR3]ipsec policy ips 1 isakmp
[AR3-ipsec-policy-isakmp-ips-1]
[AR3-ipsec-policy-isakmp-ips-1] security acl 3000
[AR3-ipsec-policy-isakmp-ips-1]
[AR3-ipsec-policy-isakmp-ips-1] ike-peer ar4
[AR3-ipsec-policy-isakmp-ips-1]
[AR3-ipsec-policy-isakmp-ips-1] proposal 2
[AR3-ipsec-policy-isakmp-ips-1]inte s4/0/0
[AR3-Serial4/0/0]ipsec policy ips
[AR3-Serial4/0/0]

 查看ike sa和ipsec sa摘要信息

连通性测试

 根据抓包内容,可见总部访问分部1和2的流量都被加上密,报文为esp

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

B站-白话聊网络

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值