IPSEC VPN配置

来源:互联网 发布:python在哪里下载 编辑:程序博客网 时间:2024/06/06 18:24

本端是ADSL,远端是静态IP,在USG2100上IPSEC配置


sysname USG2100


 ike local-name USG2100
 ike dpd interval 10


 dialer-rule 1 ip permit                  
 
runmode firewall
acl number 3000
 rule 5 permit ip source 192.168.11.0 0.0.0.255 destination 10.208.28.0 0.0.0.255


ike proposal 1
 encryption-algorithm aes-128
 dh group2 group1
 integrity-algorithm aes-xcbc-96 hmac-sha1-96 hmac-md5-96
#
ike peer IKE_site2
 pre-shared-key 123456
 ike-proposal 1
 undo version 2
 remote-address 149.126.183.11
#
ipsec proposal SITE2
 esp authentication-algorithm sha1
 esp encryption-algorithm aes-128
#
ipsec policy ipsecVPN 1 isakmp
 security acl 3000
 pfs dh-group1
 ike-peer IKE_site2
 alias map1                               
 proposal SITE2
 local-address applied-interface
 reverse-route enable static
 sa duration traffic-based 1843200
 sa duration time-based 28800


interface Dialer0
 ipsec policy ipsecVPN auto-neg


ip route-static 10.208.28.0 255.255.255.0 149.126.183.91


nat-policy interzone trust untrust outbound
 policy 0
  action no-nat
  policy source 192.168.11.0 0.0.0.255
  policy destination 10.208.28.0 0.0.0.255

1 0
原创粉丝点击