全网互通实现
现在开始做IPSec VPN
H3C企业VPN解决方案
某医疗器械公司随着业务的扩大,在深圳建立分公司。公司数据业务由总公统一处理,数据的安全性尤为重要,H3C提出VPN解决方案,总公司与分公司部署H3C MSR50、MSR30路由器,配置IPSec VPN 保证数据的安全传输。
[BJ](应该先命名的)
The device is running!
############
<Huawei>
Mar 29 2014 15:25:48-05:13 Huawei %%01IFPDT/4/IF_STATE(l)[1]:Interface GigabitEth
ernet0/0/1 has turned into UP state.
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0 //g表示千兆以太网
[Huawei-GigabitEthernet0/0/0]ip add
[Huawei-GigabitEthernet0/0/0]ip address 10.1.1.1 255.0.0.0
[Huawei-GigabitEthernet0/0/0]
Mar 29 2014 15:26:26-05:13 Huawei %%01IFNET/4/LINK_STATE(l)[2]:The line protocol
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
[Huawei-GigabitEthernet0/0/0]undo shut
Info: Interface GigabitEthernet0/0/0 is not shutdown.
[Huawei-GigabitEthernet0/0/0]qui
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add
[Huawei-GigabitEthernet0/0/1]ip address 20.1.1.1 255.0.0.0 //IP
[Huawei-GigabitEthernet0/0/1]
Mar 29 2014 15:26:47-05:13 Huawei %%01IFNET/4/LINK_STATE(l)[3]:The line protocol
IP on the interface GigabitEthernet0/0/1 has entered the UP state.
[Huawei-GigabitEthernet0/0/1]undo shut
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[Huawei-GigabitEthernet0/0/1]qui
[Huawei]rip
[Huawei-rip-1]net
[Huawei-rip-1]network 10.0.0.0 //RIP动态路由
[Huawei-rip-1]net
[Huawei-rip-1]network 20.0.0.0
[Huawei-rip-1]qui
[Huawei]qui
<Huawei>sa
<Huawei>save //配置到此,全网互通,能ping通,但不能远程
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y
It will take several minutes to save configuration file, please wait.......
Configuration file had been saved successfully
Note: The configuration file will take effect after being activated
<Huawei>
Please check whether system data has been changed, and save data in time
Configuration console time out, please press any key to log on
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]
[Huawei]ac
[Huawei]acl nu
[Huawei]acl number 3000 //ACL
[Huawei-acl-adv-3000]ru
[Huawei-acl-adv-3000]rule per
[Huawei-acl-adv-3000]rule permit ip sou
[Huawei-acl-adv-3000]rule permit ip source 10.0.0.0 0.255.255.255 dde
[Huawei-acl-adv-3000]rule permit ip source 10.0.0.0 0.255.255.255 de
[Huawei-acl-adv-3000]rule permit ip source 10.0.0.0 0.255.255.255 destination 40
.0.0.0 0.255.255.255
[Huawei-acl-adv-3000]ru
[Huawei-acl-adv-3000]rule de
[Huawei-acl-adv-3000]rule deny ip sou
[Huawei-acl-adv-3000]rule deny ip source an
[Huawei-acl-adv-3000]rule deny ip source any dde
[Huawei-acl-adv-3000]rule deny ip source any de
[Huawei-acl-adv-3000]rule deny ip source any destination an
[Huawei-acl-adv-3000]rule deny ip source any destination any
[Huawei-acl-adv-3000]qui
[Huawei]
[Huawei]ips
[Huawei]ipsec prop
[Huawei]ipsec proposal tran
[Huawei]ipsec proposal transform //创建名为transform1 的传输集
[Huawei-ipsec-proposal-transform1]en
[Huawei-ipsec-proposal-transform1]encapsulation-mode tunn
[Huawei-ipsec-proposal-transform1]encapsulation-mode tunnel
//指定隧道模式
[Huawei-ipsec-proposal-transform1]
[Huawei-ipsec-proposal-transform1]tran
[Huawei-ipsec-proposal-transform1]transform es
[Huawei-ipsec-proposal-transform1]transform esp //安全协议采用ESP协议
[Huawei-ipsec-proposal-transform1]es
[Huawei-ipsec-proposal-transform1]esp en
[Huawei-ipsec-proposal-transform1]esp encryption-algorithm de
[Huawei-ipsec-proposal-transform1]esp encryption-algorithm des
//选择算法
[Huawei-ipsec-proposal-transform1]es
[Huawei-ipsec-proposal-transform1]esp au
[Huawei-ipsec-proposal-transform1]esp authentication-algorithm sh
[Huawei-ipsec-proposal-transform1]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-transform1]ik
[Huawei-ipsec-proposal-transform1]ik
[Huawei-ipsec-proposal-transform1]qui
[Huawei]ik
[Huawei]ike pee
[Huawei]ike peer bj v2 //配置IKE对等体
[Huawei-ike-peer-bj]pre
[Huawei-ike-peer-bj]pre-shared-key bene
[Huawei-ike-peer-bj]pre-shared-key ci
[Huawei-ike-peer-bj]pre-shared-key cipher benet
[Huawei-ike-peer-bj]rem
[Huawei-ike-peer-bj]remote-address 30.1.1.2
[Huawei-ike-peer-bj]qui
[Huawei]ips
[Huawei]ipsec po
[Huawei]ipsec policy ma
[Huawei]ipsec policy map1 10 is
[Huawei]ipsec policy map1 10 isakmp //创建一条安全策略,协商方式为isakmp
[Huawei-ipsec-policy-isakmp-map1-10]se
[Huawei-ipsec-policy-isakmp-map1-10]security ac//调用访问控制列表
[Huawei-ipsec-policy-isakmp-map1-10]security acl 3000
[Huawei-ipsec-policy-isakmp-map1-10]prop
[Huawei-ipsec-policy-isakmp-map1-10]proposal tran
[Huawei-ipsec-policy-isakmp-map1-10]proposal transform1
//调用安全协议
[Huawei-ipsec-policy-isakmp-map1-10]ik
[Huawei-ipsec-policy-isakmp-map1-10]ike-peer bj //调用对等体
[Huawei-ipsec-policy-isakmp-map1-10]qui
[Huawei]
[Huawei]int g0/0/1 //在接口启用IPSec策略
[Huawei-GigabitEthernet0/0/1]ips
[Huawei-GigabitEthernet0/0/1]ipsec po
[Huawei-GigabitEthernet0/0/1]ipsec policy ma
[Huawei-GigabitEthernet0/0/1]ipsec policy map1
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]qui
[Huawei]qui
<Huawei>sa
<Huawei>save //保存
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y //输入Y
It will take several minutes to save configuration file, please wait.....
Configuration file had been saved successfully
Note: The configuration file will take effect after being activated
<Huawei>
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]
[Huawei]dis
[Huawei]display ips
[Huawei]display ipsec sa //验证IPSec VPN
===============================
Interface: GigabitEthernet0/0/1
Path MTU: 1500
===============================
-----------------------------
IPSec policy name: "map1" //名字
Sequence number : 10 //序列号
Acl Group : 3000 //ACL组
Acl rule : 5 //知道是ACL,但具体是什么就不清楚了
Mode : ISAKMP //VPN模式ISAKMP
-----------------------------
Connection ID : 8
Encapsulation mode: Tunnel //隧道模式
Tunnel local : 20.1.1.1 //本地接口
Tunnel remote : 30.1.1.2 //对端接口
Flow source : 10.0.0.0/255.0.0.0 0/0
Flow destination : 40.0.0.0/255.0.0.0 0/0
Qos pre-classify : Disable
[Outbound ESP SAs]
SPI: 1769755811 (0x697c54a3)
Proposal: ESP-ENCRYPT-DES-64 ESP-AUTH-SHA1
SA remaining key duration (bytes/sec): 1887436800/3570
Max sent sequence-number: 0
UDP encapsulation used for NAT traversal: N
[Inbound ESP SAs]
SPI: 26166062 (0x18f432e)
Proposal: ESP-ENCRYPT-DES-64 ESP-AUTH-SHA1
SA remaining key duration (bytes/sec): 1887436800/3570
Max received sequence-number: 0
Anti-replay window size: 32
UDP encapsulation used for NAT traversal: N
[Huawei]
[Huawei]
[Huawei]sysn
[Huawei]sysname BJ //命名
[BJ]
【ISP】
The device is running!
################################################################################
##########################################################
<Huawei>
Mar 29 2014 15:25:47-05:13 Huawei %%01IFPDT/4/IF_STATE(l)[0]:Interface GigabitEth
ernet0/0/0 has turned into UP state.
<Huawei>
Mar 29 2014 15:25:47-05:13 Huawei %%01IFPDT/4/IF_STATE(l)[1]:Interface GigabitEth
ernet0/0/1 has turned into UP state.
<Huawei>SYS
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add
[Huawei-GigabitEthernet0/0/0]ip address 20.1.1.2 255.0.0.0
[Huawei-GigabitEthernet0/0/0]
[Huawei-GigabitEthernet0/0/0]
Mar 29 2014 15:30:05-05:13 Huawei %%01IFNET/4/LINK_STATE(l)[2]:The line protocol
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
[Huawei-GigabitEthernet0/0/0]undo shut
Info: Interface GigabitEthernet0/0/0 is not shutdown.
[Huawei-GigabitEthernet0/0/0]qui
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add
[Huawei-GigabitEthernet0/0/1]ip address 30.1.1.1 255.0.0.0
[Huawei-GigabitEthernet0/0/1]
Mar 29 2014 15:30:27-05:13 Huawei %%01IFNET/4/LINK_STATE(l)[3]:The line protocol
IP on the interface GigabitEthernet0/0/1 has entered the UP state.
[Huawei-GigabitEthernet0/0/1]undo shut
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[Huawei-GigabitEthernet0/0/1]rip
[Huawei-rip-1]exi //华为退出的命令是quite
^
Error: Unrecognized command found at ‘^‘ position.
[Huawei-rip-1]qui
[Huawei]
[Huawei]rip
[Huawei-rip-1]net
Error:Incomplete command found at ‘^‘ position.
[Huawei-rip-1]
[Huawei-rip-1]net
[Huawei-rip-1]network 20.0.0.0
[Huawei-rip-1]net
[Huawei-rip-1]network 30.0.0.0
[Huawei-rip-1]
[Huawei-rip-1]qui
[Huawei]qui
<Huawei>sa
<Huawei>save
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y
It will take several minutes to save configuration file, please wait.......
Configuration file had been saved successfully
Note: The configuration file will take effect after being activated
<Huawei>
Please check whether system data has been changed, and save data in time
Configuration console time out, please press any key to log on
<Huawei>
Please check whether system data has been changed, and save data in time
Configuration console time out, please press any key to log on
<Huawei>
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn
[Huawei]sysname ISP
[ISP]
[SH]
The device is running!
######################
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add
[Huawei-GigabitEthernet0/0/0]ip address 30.1.1.2 255.0.0.0
[Huawei-GigabitEthernet0/0/0]
Mar 29 2014 15:27:42-05:13 Huawei %%01IFNET/4/LINK_STATE(l)[2]:The line protocol
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
[Huawei-GigabitEthernet0/0/0]
[Huawei-GigabitEthernet0/0/0]undo shut
Info: Interface GigabitEthernet0/0/0 is not shutdown.
[Huawei-GigabitEthernet0/0/0]qui
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add
[Huawei-GigabitEthernet0/0/1]ip address 40.1.1.1 255.0.0.0
[Huawei-GigabitEthernet0/0/1]
Mar 29 2014 15:27:58-05:13 Huawei %%01IFNET/4/LINK_STATE(l)[3]:The line protocol
IP on the interface GigabitEthernet0/0/1 has entered the UP state.
[Huawei-GigabitEthernet0/0/1]und shut
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[Huawei-GigabitEthernet0/0/1]undo shut
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[Huawei-GigabitEthernet0/0/1]undo shut
[Huawei-GigabitEthernet0/0/1]undo shutdown
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[Huawei-GigabitEthernet0/0/1]?
//这些都是?出来的命令,了解一下,没舍得删除
GigabitEthernet0/0/1 interface view commands:
arp <Group> arp command group
arp-fake ARP fake entry
arp-limit Limit the number of learnt ARP
arp-ping ARP-ping
arp-proxy ARP(Address Resolve Protocol) proxy configuration
command
auto Auto negotiates port mode
backup Backup information
bandwidth Specify mib-referenced bandwidth of the interface
bridge Bridge
clear <Group> clear command group
combo-port Set combo type
ddns DDNS
description Specify interface description
dhcp <Group> dhcp command group
dialer Dialer
direct-route Direct route
discard Discard packets
display Display information
dlsw Specify DLSW(Data Link Switching) configure
information
duplex Configure duplex operation mode
efm <Group> efm command group
enable Enable function
energy-efficient-ethernet Energy-efficient-ethernet
eth-trunk Add the interface into eth-trunk
flow-control Configure flow-control operation mode
icmp <Group> icmp command group
igmp Specify parameters for IGMP
ip <Group> ip command group
ipsec Specify IPSec(IP Security) configuration
information
ipv6 <Group> ipv6 command group
isis Configure interface parameters for ISIS
llc2 Specify LLC2(Logical Link Control Class 2)
configure information
lldp <Group> lldp command group
load-balance <Group> load-balance command group
log-threshold Set log threshold
loopback Configure port loopback
mdi Set mdi
mirror Specify Mirror feature
mpls <Group> mpls command group
mtrace Trace route to multicast source
mtu Specify Maximum Transmission Unit(MTU) of the
interface
multicast Multicast information
nat Specify NAT(Network Address Translation)
configuration information
negotiation Set negotiation mode
ntp-service Specify NTP(Network Time Protocol) configuration
information
ospf <Group> ospf command group
ospfv3 <Group> ospfv3 command group
pim Specify interface parameters for PIM
ping <Group> ping command group
port <Group> port command group
port-down Port down
portal Portal authentication
pppoe-client PPPoE Client Settings
pppoe-server Specify PPPoE(PPP over Ethernet) server
configuration information
qinq 802.1Q in 802.1Q
qos <Group> qos command group
quit Exit from current mode and enter prior mode
reset <Group> reset command group
restart Restart the specified interface
return Enter the privileged mode
rip <Group> rip command group
ripng RIPng (Routing Information Protocol next
generation)
rmon Specify RMON configuration
rmon-statistics Specify RMON statistics
set <Group> set command group
shutdown Shutdown the specified interface
single-fiber Configure port single fiber communication
speed Configure port speed mode
standby Specify interface standby configuration information
static-route IPv4 static routes
tcp Transmission Control Protocol
test-aaa Accounts test
tracert <Group> tracert command group
traffic-filter Filter packets based on acl
traffic-policy Apply specific traffic policy
trap-threshold <Group> trap-threshold command group
trust Specify trust parameters
udp-helper UDP Helper
undo Negate a command or set its defaults
urpf Unicast reverse path forward function
virtual-cable-test Virtual Cable Test
vrrp Specify configuration information about VRRP
vrrp6 Specify configuration information about VRRP6
web-auth-server Bind portal server name
zone Specify a security zone name
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]qui
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add
[Huawei-GigabitEthernet0/0/1]ip address 40.1.1.1 255.0.0.0
Error: The address already exists.
[Huawei-GigabitEthernet0/0/1]undo shut
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[Huawei-GigabitEthernet0/0/1]qui
[Huawei]rip
[Huawei-rip-1]net
[Huawei-rip-1]network 30.0.0.0
[Huawei-rip-1]
[Huawei-rip-1]net
[Huawei-rip-1]network 40.0.0.0
[Huawei-rip-1]
[Huawei-rip-1]qui
[Huawei]qui
<Huawei>sa
<Huawei>save
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y
It will take several minutes to save configuration file, please wait.......
Configuration file had been saved successfully
Note: The configuration file will take effect after being activated
<Huawei>
Please check whether system data has been changed, and save data in time
Configuration console time out, please press any key to log on
<Huawei>
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]acl nu
[Huawei]acl number 3000
[Huawei-acl-adv-3000]ru
[Huawei-acl-adv-3000]rule per
[Huawei-acl-adv-3000]rule permit
[Huawei-acl-adv-3000]rule permit ip sou
[Huawei-acl-adv-3000]rule permit ip source 40.0.0.0 0.255.255.255 de
[Huawei-acl-adv-3000]rule permit ip source 40.0.0.0 0.255.255.255 destination 10
.0.0.0 0.255.255.255
[Huawei-acl-adv-3000]ru
[Huawei-acl-adv-3000]rule de
[Huawei-acl-adv-3000]rule deny ip sou
[Huawei-acl-adv-3000]rule deny ip source an
[Huawei-acl-adv-3000]rule deny ip source any de
[Huawei-acl-adv-3000]rule deny ip source any destination an
[Huawei-acl-adv-3000]rule deny ip source any destination any
[Huawei-acl-adv-3000]qui
[Huawei]
[Huawei]ips
[Huawei]ipsec prop
[Huawei]ipsec proposal tran
[Huawei]ipsec proposal transform1
[Huawei-ipsec-proposal-transform1]
[Huawei-ipsec-proposal-transform1]en
[Huawei-ipsec-proposal-transform1]encapsulation-mode tunn
[Huawei-ipsec-proposal-transform1]encapsulation-mode tunnel
[Huawei-ipsec-proposal-transform1]tran
[Huawei-ipsec-proposal-transform1]transform es
[Huawei-ipsec-proposal-transform1]transform esp
[Huawei-ipsec-proposal-transform1]es
[Huawei-ipsec-proposal-transform1]esp en
[Huawei-ipsec-proposal-transform1]esp encryption-algorithm de
[Huawei-ipsec-proposal-transform1]esp encryption-algorithm des
[Huawei-ipsec-proposal-transform1]es
[Huawei-ipsec-proposal-transform1]esp au
[Huawei-ipsec-proposal-transform1]esp authentication-algorithm sh
[Huawei-ipsec-proposal-transform1]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-transform1]qui
[Huawei]ik
[Huawei]ike pee
[Huawei]ike peer sh
Error: This IKE peer is new, please indicate the mode to finish creating it.
[Huawei]ike peer sh v2
[Huawei-ike-peer-sh]pre
[Huawei-ike-peer-sh]pre-shared-key ci
[Huawei-ike-peer-sh]pre-shared-key cipher benet
[Huawei-ike-peer-sh]
[Huawei-ike-peer-sh]reemo
[Huawei-ike-peer-sh]remo
[Huawei-ike-peer-sh]remote-address 20.1.1.1
[Huawei-ike-peer-sh]qui
[Huawei]ips
[Huawei]ipsec po
[Huawei]ipsec policy map1 10 is
[Huawei]ipsec policy map1 10 isakmp
[Huawei-ipsec-policy-isakmp-map1-10]se
[Huawei-ipsec-policy-isakmp-map1-10]security ac
[Huawei-ipsec-policy-isakmp-map1-10]security acl 3000
[Huawei-ipsec-policy-isakmp-map1-10]
[Huawei-ipsec-policy-isakmp-map1-10]pro
[Huawei-ipsec-policy-isakmp-map1-10]proposal tr
[Huawei-ipsec-policy-isakmp-map1-10]proposal transform1
[Huawei-ipsec-policy-isakmp-map1-10]
[Huawei-ipsec-policy-isakmp-map1-10]ik
[Huawei-ipsec-policy-isakmp-map1-10]ike-peer sh
[Huawei-ipsec-policy-isakmp-map1-10]
[Huawei-ipsec-policy-isakmp-map1-10]qui
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ips
[Huawei-GigabitEthernet0/0/0]ipsec po
[Huawei-GigabitEthernet0/0/0]ipsec policy ma
[Huawei-GigabitEthernet0/0/0]ipsec policy map1
[Huawei-GigabitEthernet0/0/0]qui
[Huawei]qui
<Huawei>sa
<Huawei>save
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y
It will take several minutes to save configuration file, please wait......
Configuration file had been saved successfully
Note: The configuration file will take effect after being activated
<Huawei>dis
<Huawei>display ips
<Huawei>display ipsec sa
===============================
Interface: GigabitEthernet0/0/0
Path MTU: 1500
===============================
-----------------------------
IPSec policy name: "map1"
Sequence number : 10
Acl Group : 3000
Acl rule : 5
Mode : ISAKMP
-----------------------------
Connection ID : 2
Encapsulation mode: Tunnel
Tunnel local : 30.1.1.2
Tunnel remote : 20.1.1.1
Flow source : 40.0.0.0/255.0.0.0 0/0
Flow destination : 10.0.0.0/255.0.0.0 0/0
Qos pre-classify : Disable
[Outbound ESP SAs]
SPI: 26166062 (0x18f432e)
Proposal: ESP-ENCRYPT-DES-64 ESP-AUTH-SHA1
SA remaining key duration (bytes/sec): 1887436800/3556
Max sent sequence-number: 0
UDP encapsulation used for NAT traversal: N
[Inbound ESP SAs]
SPI: 1769755811 (0x697c54a3)
Proposal: ESP-ENCRYPT-DES-64 ESP-AUTH-SHA1
SA remaining key duration (bytes/sec): 1887436800/3556
Max received sequence-number: 0
Anti-replay window size: 32
UDP encapsulation used for NAT traversal: N
<Huawei>
<Huawei>
<Huawei>
<Huawei>sya
Error: Unrecognized command found at ‘^‘ position.
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysna
[Huawei]sysname SH
[SH]
在H3C设备上配置IPSec VPN