配置步骤
1、底层互通
2、Tunnel口互通
3、配置IPsec
题目:
FW1与FW2之间用Internet互联地址建立GRE Over IPSec VPN,实现loopback2之间的加密访问。
FW1:
tunnel gre "GRE"
source 200.200.200.2
destination 200.200.200.6
interface ethernet0/3
interface tunnel1
tunnel gre "GRE"
ip route 0.0.0.0/0 200.200.200.1
策略:
p1:
p2:
vpn对端:
ipsec:
interface tunnel1
next-tunnel ipsec ipsec
ip route 10.10.255.6/32 "tunnel1"
FW2:
tunnel gre "GRE"
source 200.200.200.6
destination 200.200.200.2
interface ethernet0/3
interface tunnel1
tunnel gre "GRE"
ip route 0.0.0.0/0 200.200.200.5
策略:
p1:
p2:
vpn对端:
ipsec:
interface tunnel1
next-tunnel ipsec ipsec
ip route 10.10.255.7/32 "tunnel1"