ipsec vpn 对接不成功
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip address 124.128.23.26 255.255.255.248
nat outbound 3001
ipsec apply policy 1
acl advanced 3000 rule 0 permit ip source 192.168.10.0 0.0.0.255 destination 176.16.0.0 0.0.3.255
# acl advanced 3001 rule 0 deny ip source 192.168.10.0 0.0.0.255 destination 176.16.0.0 0.0.3.255
rule 5 permit ip
ipsec transform-set 1
esp encryption-algorithm aes-cbc-256
esp authentication-algorithm sha256
# ipsec policy 1 1 isakmp
transform-set 1 security acl 3000
remote-address 60.208.58.206
ikev2-profile 1
# ike logging negotiation enable
# ip http enable ip https enable
# loadbalance isp file flash:/lbispinfo_v1.5.tp
# ikev2 keychain 1
peer 1
address 60.208.58.206 255.255.255.255
identity address 60.208.58.206
pre-shared-key ciphertext $c$3$t3igpx18BX2RwX6o7JNCbVTWaC90BCeKtFNynw==
# ikev2 profile 1
authentication-method local pre-share
authentication-method remote pre-share keychain 1
match remote identity address 60.208.58.206 255.255.255.255
# ikev2 proposal 1
encryption des-cbc
integrity md5
# ikev2 policy 1
下面是思科的配置
Azure side,
Azure VPN Public IP: 159.27.123.52
Azure VNet
IKEv2
phase1
/Data/IKE_ENCRYPTION_1 = des
/Data/IKE_INTEGRITY_1 = md5
Address Space: 176.17.0.0/22
/Data/IKE_DHGROUP_1 = 2
/Data/IKE_SALIFETIME_1 = 28800
Phase2
/Data/IPsec_ENCRYPTION_1 = aes-256
/Data/IPsec_INTEGRITY_1 = sha-256
/Data/IPsec_PFSGROUP_1 = None
/Data/IPsec_SALIFETIME = 27000
/Data/IPsec_KB_SALIFETIME = 102400000 (Please ignore it if not supported)
/Data/CONNECTION_PSK = bDZbITx9F1gQWIdS371cCb5Aq5w25vRq
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论