IPsec同流双隧道的典型配置举例
根据上述实例进行模拟测试
需在D_A与D_B间建立IPSEC,但失败,问题点应该是D_A无法与D_B端loop0 3.3.3.3通讯,D_A端与D_B端外网路由是可达的.
如果保持D_A设备上图的remote-address,由A发起会话的话,就会提示对端没响应,如果由B发起会话的话,就会提示与对方POLICY地址不匹配(即3.3.3.3与44.44.44.254不匹配(假设44.44.44.254为主路))。如果把remote-address改成44.44.44.254的话单线IPSEC就可以建立成功。感觉问题应该就是A端无法与3.3.3.3通讯,不知道是哪里配置出问题了
以下为测试环境AB设备的配置
sysname D_A
#
interface GigabitEthernet0/0
port link-mode route
combo enable copper
ip address 192.168.0.254 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
combo enable copper
ip address 118.114.24.2 255.255.255.0
nat outbound 3100
ipsec apply policy shenxs
#
line vty 0 63
user-role network-operator
#
ip route-static 0.0.0.0 0 118.114.24.1
ip route-static 3.3.3.3 32 44.44.44.254
ip route-static 3.3.3.3 32 33.33.33.254
#
acl number 3000
rule 0 permit ip source 192.168.0.0 0.0.0.255 destination 172.16.20.0 0.0.0.255
#
acl number 3100
rule 0 deny ip source 192.168.0.0 0.0.0.255 destination 172.16.20.0 0.0.0.255
rule 100 permit ip
#
user-group system
#
ipsec transform-set shenxs
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
pfs dh-group2
#
ipsec policy shenxs 65535 isakmp
transform-set shenxs
security acl 3000
remote-address 3.3.3.3
ike-profile shenxs
#
ike profile shenxs
keychain shenxs
dpd interval 10 retry 10 periodic
local-identity address 118.114.24.2
match remote identity address 3.3.3.3 255.255.255.255
proposal 65534
#
ike proposal 65534
encryption-algorithm 3des-cbc
dh group2
authentication-algorithm md5
#
ike keychain shenxs
pre-shared-key address 3.3.3.3 255.255.255.255 key cipher $c$3$HVgf9VWiCkbiEHAuKpYQK9OiRr4mFv9ktYQK
pre-shared-key address 44.44.44.254 255.255.255.255 key cipher $c$3$K3/rlhOkWD88HMtZNOJXGdLsrvGUws4GUFrb
pre-shared-key address 33.33.33.254 255.255.255.255 key cipher $c$3$OPuJbnHHzmR8bL0V+6UvjEv6qfMXeqbsbZmW
#
#
interface LoopBack0
ip address 3.3.3.3 255.255.255.0
#
interface GigabitEthernet0/0
port link-mode route
combo enable copper
ip address 172.16.20.254 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
combo enable copper
ip address 33.33.33.254 255.255.255.0
nat outbound 3100
ipsec apply policy shenxs
#
interface GigabitEthernet0/2
port link-mode route
combo enable copper
ip address 44.44.44.254 255.255.255.0
nat outbound 3100
ipsec apply policy shenxs
#
#
ip route-static 0.0.0.0 0 44.44.44.1
ip route-static 0.0.0.0 0 33.33.33.1 preference 70
#
acl number 3000
rule 0 permit ip source 172.16.20.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
#
acl number 3100
rule 0 deny ip source 172.16.20.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 100 permit ip
#
#
ipsec transform-set shenxs
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
pfs dh-group2
#
ipsec policy shenxs 65535 isakmp
transform-set shenxs
security acl 3000
remote-address 118.114.24.2
ike-profile shenxs
#
ipsec policy shenxs local-address LoopBack0
#
ike profile shenxs
keychain shenxs
dpd interval 10 retry 10 periodic
match remote identity address 118.114.24.2 255.255.255.255
proposal 65534
#
ike proposal 65534
encryption-algorithm 3des-cbc
dh group2
authentication-algorithm md5
#
ike keychain shenxs
pre-shared-key address 118.114.24.2 255.255.255.255 key cipher $c$3$eWfHCeFAEIL7VJwSFAeQ2ovfbx1sPnRp2nJz
#
loop0 3.3.3.3相当于私地址,公网设备不可能加私网路由的.