设置列表
对齐方式
<H3C>dis cur
#
version 5.20, Release 2516P19
#
sysname H3C
#
password-control enable
undo password-control aging enable
undo password-control history enable
password-control length 6
password-control login-attempt 3 exceed lock-time 10
password-control password update interval 0 password-control login idle-time 0
password-control complexity user-name check
#
domain default enable system
#
dns proxy enable
#
telnet server enable
#
dar p2p signature-file flash:/p2p_default.mtd
#
ndp enable
#
ntdp enable
#
cluster enable
#
port-security enable
#
password-recovery enable
#
acl number 3000 rule 0 permit ip source 10.42.100.0 0.0.0.255 destination 10.42.1.0 0.0.0.255
#
vlan 1
# domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
ike proposal 1
encryption-algorithm 3des-cbc
dh group2
authentication-algorithm md5
sa duration 3600
#
ike dpd vpn
# ike peer vpn
exchange-mode aggressive
proposal 1
pre-shared-key cipher $c$3$Xgn679fXUp2MIXoNblsjF57VLCbX7SjoDl1EaKnqLBZe
id-type name
remote-name glsangfor
remote-address 112.91.208.162
local-name fqh3c
nat traversal
dpd vpn
#
ipsec transform-set vpn
encapsulation-mode tunnel
transform esp esp
authentication-algorithm md5
esp encryption-algorithm 3des
#
ipsec policy 720896 1 isakmp
connection-name vpn
security acl 3000
ike-peer vpn
transform-set vpn
sa duration traffic-based 1843200
sa duration time-based 3600
#
dhcp server ip-pool vlan1 extended
network ip range 10.42.100.21 10.42.100.220
network mask 255.255.255.0
gateway-list 10.42.100.1
dns-list 114.114.114.114 8.8.8.8
#
user-group system
group-attribute allow-guest
#
local-user admin
authorization-attribute level 3
service-type telnet
service-type web
local-user fengquan
authorization-attribute level 3
service-type telnet
service-type web
# cwmp
undo cwmp enable
#
interface Cellular0/0
async mode protocol
link-protocol ppp
tcp mss 1024
#
interface Dialer10
nat outbound
link-protocol ppp
ppp chap user CZ1376283481@16900.gd
ppp chap password cipher $c$3$8Szg/akfkg8T7q1Yg8sjC0G/gZN5oEewrg==
ppp pap local-user CZ1376283481@16900.gd password cipher $c$3$3Jp/TYT5VsWwT+8WGZD/cTmu8sBjx9vN2g==
ppp ipcp dns admit-any
ppp ipcp dns request
mtu 1492
ip address ppp-negotiate
tcp mss 1024
dialer user username
dialer-group 10
dialer bundle 10
ipsec no-nat-process enable
ipsec policy 720896
#
interface NULL0
#
interface Vlan-interface1
ip address 10.42.100.1 255.255.255.0
tcp mss 1024
dhcp server apply ip-pool vlan1
#
interface GigabitEthernet0/0
port link-mode route
nat outbound
pppoe-client dial-bundle-number 10
ipsec no-nat-process enable
#
interface GigabitEthernet0/4
port link-mode
route tcp mss 1024
#
interface GigabitEthernet0/1
port link-mode bridge
#
interface GigabitEthernet0/2
port link-mode bridge
#
interface GigabitEthernet0/3
port link-mode bridge
#
ip route-static 0.0.0.0 0.0.0.0 Dialer10
#
dhcp enable
#
dialer-rule 10 ip permit
#
nms primary monitor-interface Dialer10
#
load xml-configuration
#
load tr069-configuration
#
user-interface con 0
user-interface tty 13
user-interface vty 0 4
authentication-mode scheme
# return
这是华三MSR810的的配置,请问下配置有没有问题,对端是深信服防火墙,使用野蛮模式隧道模式建立,目前建立不起来,这华三路由器配置哪里有问题呢
(0)
最佳答案
IPSEC一般大部分都是配置问题,建议参考配置案例:https://www.h3c.com/cn/d_201807/1094144_30005_0.htm仔细核对一下,还有模式也要选择正确
(0)
暂无评论
不一定是华三设备配置问题,连不上有什么提示,一般都是IKE IPSEC 设置,感兴趣流不做nat 转换,分支路由这几个原因,要具体原因具体分析
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论