配置L2TP over IPSec VPN,让公司出差员工访问公司内部资源,配置完成后,手机端VPN登陆提示失败,防火墙端没响应,求助各位大神
防火墙相关配置如下:
#
version 7.1.064, Release 9510P12
#
sysname FW-100
#
ip pool vpn 10.1.1.2 10.1.1.30
#
object-group service l2tp1
0 service tcp destination eq 1701
10 service tcp destination eq 500
20 service tcp destination eq 4500
#
interface Virtual-Template1
ppp authentication-mode chap pap
remote address pool vpn
ip address 10.1.1.1 255.255.255.0
#
interface GigabitEthernet1/0/10
port link-mode route
ip last-hop hold
nat outbound 3000 address-group 10
ipsec apply policy 1
#
interface GigabitEthernet1/0/11
port link-mode route
ip address 172.16.16.254 255.255.255.252
nat hairpin enable
ip policy-based-route ddn
#
object-policy ip IPSec-Trust
rule 0 pass
object-policy ip Trust-IPSec
rule 0 pass
#
object-policy ip Untrust-Local
rule 1 pass service l2tp1 logging
rule 0 drop
#
security-zone name IPSec
import interface Virtual-Template1
#
acl advanced 3000
rule 5 deny udp destination-port eq 1701
rule 10 permit ip source 192.168.150.0 0.0.0.255
#
ipsec transform-set 1
encapsulation-mode transport
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
#
ipsec transform-set 2
encapsulation-mode transport
esp encryption-algorithm aes-cbc-128
esp authentication-algorithm sha1
#
ipsec transform-set 3
encapsulation-mode transport
esp encryption-algorithm aes-cbc-256
esp authentication-algorithm sha1
#
ipsec transform-set 4
encapsulation-mode transport
esp encryption-algorithm des-cbc
esp authentication-algorithm sha1
#
ipsec transform-set 5
encapsulation-mode transport
esp encryption-algorithm 3des-cbc
esp authentication-algorithm sha1
#
ipsec transform-set 6
encapsulation-mode transport
esp encryption-algorithm aes-cbc-192
esp authentication-algorithm sha1
#
ipsec policy-template olevpn 1
transform-set 1 2 3 4 5 6
ike-profile 1
#
ipsec policy 1 10 isakmp template olevpn
#
nat server-group 10
#
l2tp-group 1 mode lns
allow l2tp virtual-template 1
undo tunnel authentication
#
l2tp enable
#
#
ike profile 1
keychain 1
match remote identity address 0.0.0.0 0.0.0.0
proposal 1 2 3 4 5 6
#
ike proposal 1
encryption-algorithm aes-cbc-128
dh group2
authentication-algorithm md5
#
ike proposal 2
encryption-algorithm 3des-cbc
dh group2
authentication-algorithm md5
#
ike proposal 3
encryption-algorithm 3des-cbc
dh group2
#
ike proposal 4
encryption-algorithm aes-cbc-256
dh group2
#
ike proposal 5
dh group2
#
ike proposal 6
encryption-algorithm aes-cbc-192
dh group2
#
ike keychain 1
pre-shared-key address 0.0.0.0 0.0.0.0 key cipher $c$3$4uhwOd1uGRcRWaGyxEKJH1bkMDlzT+YhfMjl
#
按官方给的配置流程,再根据自己的使用情况配置的,跟你那个比,最大区别是没有使用INode,现在的情况,就是因为iNode不支持鸿蒙3.0,希望用手机自带的VPN功能,才从原来的SSL VPN转IPSec,现在是防火墙端不做回应,不知道问题出在那里