请问怎样通过ACL把对GRE感兴趣的流量匹配出来,环回口为私网地址,tunnel口ip地址在图中所示,哪一个为正确的?
1.[H3C-acl-ipv4-adv-3000]rule permit ip source 1.1.1.1 0 destination 3.3.3.3 0
2.[H3C-acl-ipv4-adv-3000]rule permit ip source 100.100.100.1 0 destination 100.100 .100.2 0
3.[H3C-acl-ipv4-adv-3000]rule permit ip source 10.1.12.1 0 destination 10.1.23.3 0
(0)
最佳答案
没有使用loopback
acl number 3102
rule 0 permit ip source 10.218.105.150 0 destination 86.215.205.140 0
#
ike peer br_peer
exchange-mode aggressive
pre-shared-key simple 123
id-type name
remote-name br
remote-address 86.215.205.140
nat traversal
#
ipsec proposal 1
#
ipsec policy po_all 1 isakmp
security acl 3102
ike-peer br_peer
proposal 1
#
interface GigabitEthernet0/1
port link-mode route
ip address 10.218.105.150 255.255.255.252
ipsec policy po_all
#
interface Tunnel0
ip address 20.1.1.1 255.255.255.252
source 10.218.105.150
destination 86.215.205.140
#
ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/1 10.218.105.149
使用loopback
Acl number 3000 //配置感兴趣的流量
rule 0 permit ip source 6.6.6.0 0.0.0.255 destination 7.7.7.0 0.0.0.255
#
ipsec policy 1 10 isakmp
security acl 3000
ike-peer test
proposal 1
#
interface LoopBack100
ip address 6.6.6.6 255.255.255.255
#
interface GigabitEthernet0/0
port link-mode route
loopback
ip address 200.1.1.1 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
ip address 202.103.2.1 255.255.255.0
ipsec policy 1
#
interface Tunnel0 //创建Tunnel接口,采用环回口封装
ip address 1.1.1.2 255.255.255.0
source 6.6.6.6
destination 7.7.7.7
(0)
你这没有图啊,你还是直接告诉我答案吧。。。。。
我刚刚也在找资料, 之前的也记不清楚立了 有两种情况, 我这个配置中,没用用到loopback, 那么acl 就写公网IP地址。 另一种,比如你的图中,使用loopback接口, 那么acl就写本端loopback地址和对端loopback地址。 Acl number 3000 //配置感兴趣的流量 rule 0 permit ip source 6.6.6.0 0.0.0.255 destination 7.7.7.0 0.0.0.255 # ipsec policy 1 10 isakmp security acl 3000 ike-peer test proposal 1 # interface LoopBack100 ip address 6.6.6.6 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route loopback ip address 200.1.1.1 255.255.255.0 # interface GigabitEthernet0/1 port link-mode route ip address 202.103.2.1 255.255.255.0 ipsec policy 1 # interface Tunnel0 //创建Tunnel接口,采用环回口封装 ip address 1.1.1.2 255.255.255.0 source 6.6.6.6 destination 7.7.7.7
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
我刚刚也在找资料, 之前的也记不清楚立了 有两种情况, 我这个配置中,没用用到loopback, 那么acl 就写公网IP地址。 另一种,比如你的图中,使用loopback接口, 那么acl就写本端loopback地址和对端loopback地址。 Acl number 3000 //配置感兴趣的流量 rule 0 permit ip source 6.6.6.0 0.0.0.255 destination 7.7.7.0 0.0.0.255 # ipsec policy 1 10 isakmp security acl 3000 ike-peer test proposal 1 # interface LoopBack100 ip address 6.6.6.6 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route loopback ip address 200.1.1.1 255.255.255.0 # interface GigabitEthernet0/1 port link-mode route ip address 202.103.2.1 255.255.255.0 ipsec policy 1 # interface Tunnel0 //创建Tunnel接口,采用环回口封装 ip address 1.1.1.2 255.255.255.0 source 6.6.6.6 destination 7.7.7.7