以下的华为路由器的配置
[V200R007C00SPCb00]
#
drop illegal-mac alarm
#
vlan batch 2
#
dhcp enable
#
pki realm default
enrollment self-signed
#
ssl policy default_policy type server
pki-realm default
#
acl number 2001
rule 5 permit
#
web
user-set Default
user-set VIP
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user gytl password irreversible-cipher %^%#$7F{Yhh<T6EEXz9: m}Xl(Nv3},w.Fz%Yb*o:GBG kwW5H_BkCG;RyJ6i<$L%^%#
local-user gytl privilege level 15
local-user gytl service-type telnet terminal http
local-user admin password irreversible-cipher %^%#qO,*MTjG{58=}cT/CyXY$=Sz5f%Z_~l)_S""/Ni3-37M4:%lINZZA}"i-IdN%^%#
local-user admin privilege level 15
local-user admin service-type terminal http
#
firewall zone Local
priority 16
#
interface Vlanif1
ip address 192.168.1.1 255.255.255.0
dhcp select interface
dhcp server dns-list 202.98.192.67 118.118.118.9
#
interface Vlanif2
description to SP-VPN
ip address xxx.xxx.xxx.xxx 255.255.255.0
#
interface GigabitEthernet0/0/0
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
ip address xxx.xxx.xxx.xxx 255.255.255.128
nat outbound 2001
#
interface GigabitEthernet0/0/5
description VirtualPort
#
interface Cellular0/0/0
#
interface NULL0
#
interface Tunnel0/0/0
ip address xxx.xxx.xxx.xxx 255.255.255.0
tunnel-protocol gre p2mp
source GigabitEthernet0/0/4
nhrp entry 192.168.99.1 xxx.xxx.xxx.xxx register
#
rip 1
undo summary
version 2
network 192.168.99.0
network 172.16.0.0
#
snmp-agent local-engineid 800007DB03487B6B6B4B2B
#
http secure-server ssl-policy default_policy
http server enable
http secure-server enable
#
ip route-static 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx
#
fib regularly-refresh disable
#
user-interface con 0
authentication-mode aaa
user-interface vty 0
authentication-mode aaa
user privilege level 15
user-interface vty 1 4
#
wlan ac
#
ops
#
autostart
#
return
<Huawei>
假如总部的主机配置支持 GRE to IPsec协议,分支能否通过配置IPsec来实现呢?