msr930路由器在公网,路由可达的PC电脑通过公网使用VPN拨号建立L2TP隧道使用IPSEC加密链接公司办公网内网,需要一个域共享密钥,认证全部在路由器上完成,没有认证服务器。求具体配置。谢谢大佬们(不要发个链接哦,最好能直接将配置粘贴出来,实在是不会)
(0)
最佳答案
参考一下:
客户client端网段与LNS内网同网段,现客户想要通过L2TP over IPsec实现访问内部的telnet资源。
LNS侧配置:
#
version 5.20, Release 5142P03
#
sysname H3C
#
l2tp enable //使能L2TP
#
ike local-name lns //配置本端IKE对等体名字
#
interzone policy default by-priority
#
domain default enable system
#
telnet server enable
#
port-security enable
#
session synchronization enable
#
password-recovery enable
#
acl number 3010
rule 5 permit ip
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
ip pool 1 192.168.10.2 192.168.10.10 //配置L2TP地址池
#
pki domain default
crl check disable
#
ike peer pc //配置ike对等体
exchange-mode aggressive
pre-shared-key cipher simple
id-type name
remote-name pc
nat traversal
#
ipsec transform-set 1 //配置ipsec安全提议
encapsulation-mode tunnel
transform esp
esp authentication-algorithm sha1
esp encryption-algorithm des
#
ipsec policy-template temp1 1 //配置ipsec策略模板
security acl 3005
ike-peer pc
transform-set 1
sa duration traffic-based 1843200
sa duration time-based 3600
#
ipsec policy pc 1 isakmp template temp1 //配置ipsec策略
#
acl number 3005 //配置本地策略路由,将匹配L2TP的报文,重定向到公网接口
rule 0 permit udp source-port eq 1701
#
policy-based-route aaa permit node 5
if-match acl 3005
apply output-interface GigabitEthernet0/2
#
ip local policy-based-route aaa
#
user-group system
group-attribute allow-guest
#
local-user 3210 //配置L2TP用户
password cipher 3210
service-type ppp
#
cwmp
undo cwmp enable
#
l2tp-group 1 //配置L2TP组
undo tunnel authentication
allow l2tp virtual-template 1
#
interface Virtual-Template1 //配置VT接口,将内网的telnet服务器映射到VT虚接口
ppp authentication-mode chap
remote address pool 1
ip address 192.168.10.1 255.255.255.0
nat server 1 protocol tcp global current-interface 2323 inside 192.168.202.55 telnet
#
interface NULL0
#
interface GigabitEthernet0/0
port link-mode route
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode rout
ip address 192.168.202.11 255.255.255.0 //与服务器互联
#
interface GigabitEthernet0/2
port link-mode route
nat outbound 3010
ip address 11.1.1.1 255.255.255.0
ipsec policy pc //公网接口绑定ipsec策略
#
interface GigabitEthernet0/3
port link-mode route
#
interface GigabitEthernet0/4
port link-mode route
#
vd Root id 1
#
zone name Trust id 2 //测试方便起见,将所有接口加入trust安全域
priority 85
import interface GigabitEthernet0/1
import interface GigabitEthernet0/2
import interface Virtual-Template1
#
TELNET服务器配置:
#
telnet server enable
#
local-user admin
password cipher .]@USE=B,53Q=^Q`MAF4<1!!
authorization-attribute level 3
service-type telnet
#
interface GigabitEthernet0/2
port link-mode route
ip address 192.168.202.55 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 192.168.202.11
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
#
Client网卡信息:
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论