IP XFRM配置示例:利用linux kernel自带的IPSec实现,手动配置IPSec
来源:互联网 发布:用淘宝联盟买多件宝贝 编辑:程序博客网 时间:2024/04/29 17:14
1、拓扑
192.168.18.101 <=======> 192.168.18.102
2、配置192.168.18.101
ip xfrm state add src 192.168.18.101 dst 192.168.18.102 proto esp spi 0x00000301 mode tunnel auth md5 0x96358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965dfip xfrm state add src 192.168.18.102 dst 192.168.18.101 proto esp spi 0x00000302 mode tunnel auth md5 0x99358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xffddb555acfd9d77b03ea3843f2653255afe8eb5573965dfip xfrm state get src 192.168.18.101 dst 192.168.18.102 proto esp spi 0x00000301ip xfrm policy add src 192.168.18.101 dst 192.168.18.102 dir out ptype main tmpl src 192.168.18.101 dst 192.168.18.102 proto esp mode tunnelip xfrm policy add src 192.168.18.102 dst 192.168.18.101 dir in ptype main tmpl src 192.168.18.102 dst 192.168.18.101 proto esp mode tunnelip xfrm policy ls
3、配置192.168.18.102
ip xfrm state add src 192.168.18.101 dst 192.168.18.102 proto esp spi 0x00000301 mode tunnel auth md5 0x96358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965dfip xfrm state add src 192.168.18.102 dst 192.168.18.101 proto esp spi 0x00000302 mode tunnel auth md5 0x99358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xffddb555acfd9d77b03ea3843f2653255afe8eb5573965dfip xfrm state get src 192.168.18.101 dst 192.168.18.102 proto esp spi 0x00000301ip xfrm policy add src 192.168.18.101 dst 192.168.18.102 dir in ptype main tmpl src 192.168.18.101 dst 192.168.18.102 proto esp mode tunnelip xfrm policy add src 192.168.18.102 dst 192.168.18.101 dir out ptype main tmpl src 192.168.18.102 dst 192.168.18.101 proto esp mode tunnelip xfrm policy ls4、测试4.1在192.168.18.101上执行
ping 192.168.18.102
4.2在192.168.18.102上抓包
tcpdump -p esptcpdump: verbose output suppressed, use -v or -vv for full protocol decodelistening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes11:12:00.771364 IP 192.168.18.101 > 192.168.18.102: ESP(spi=0x00000301,seq=0x41d), length 11611:12:00.771498 IP 192.168.18.102 > 192.168.18.101: ESP(spi=0x00000302,seq=0x183), length 11611:12:01.773378 IP 192.168.18.101 > 192.168.18.102: ESP(spi=0x00000301,seq=0x41e), length 11611:12:01.773787 IP 192.168.18.102 > 192.168.18.101: ESP(spi=0x00000302,seq=0x184), length 11611:12:02.774682 IP 192.168.18.101 > 192.168.18.102: ESP(spi=0x00000301,seq=0x41f), length 11611:12:02.774793 IP 192.168.18.102 > 192.168.18.101: ESP(spi=0x00000302,seq=0x185), length 116
- IP XFRM配置示例:利用linux kernel自带的IPSec实现,手动配置IPSec
- IP XFRM配置:利用linux kernel自带的IPSec实现,手动配置IPSec
- 用windows自带的L2TP/IPSec客户端进行配置L2TP/IPSec 预共享密钥VPN的配置
- IPSec的相关配置
- Linux IPsec点到点配置
- Cisco IPSec简单的配置
- IPSEC OVER GRE的配置
- 基于IPsec的虚拟专用网在Linux上的实现--安装配置篇
- IPSEC.CONF(5) - IPsec配置
- CENTOS LINUX 安装配置L2TP+IPSEC VPN
- 配置IPSec安全策略
- IPSEC VPN 配置
- IPSec-Tools配置
- IPsec tunnel配置
- ipsec-tools静态配置
- ipsec vpn 简单配置
- IPSec-Tools配置
- ipsec vpn配置
- Ubuntu 使用Git 使用
- 模式识别技术
- clickonce部署软件文件位置分析
- 第四次上机实验
- 正则表达式的应用(转)
- IP XFRM配置示例:利用linux kernel自带的IPSec实现,手动配置IPSec
- 用android LinearLayout和RelativeLayout实现精确布局
- ORA-00911: invalid character问题解决办法
- java序列化
- Structs1基础知识
- EasyJS 教程三 - 实现封装
- 黑马程序员--Java基础小结(一)
- 从头开始学习开发django系列-1、配置环境,以windows为例
- WIN7下protel 99se的“file not recognized”问题解决