上海公网地址:172.16.100.2
GRE隧道IP:12.0.0.1/24
内网:172.16.10.1/24,172.16.20.1/24
北京公网地址:172.16.100.3
GRE隧道IP:12.0.0.2/24
内网:172.17.10.1/24,172.17.20.1/24
上海:
[SH-FW]interface Tunnel0 mode gre
[SH-FW-Tunnel0]description ##Gre-Tunnel-BJ##
[SH-FW-Tunnel0]ip address 12.0.0.1 255.255.255.0
[SH-FW-Tunnel0]source 172.16.100.2
[SH-FW-Tunnel0]destination 172.16.100.3
[SH-FW-Tunnel0]quit
[SH-FW]ip route-static 18.18.18.0 30 Tunnel0 //对端设备网段静态路由到Tunnel口
[SH-FW]ip route-static 172.17.10.0 24 Tunnel0
[SH-FW]ip route-static 172.17.20.0 24 Tunnel0
北京:
[BJ-FW]interface Tunnel0 mode gre
[BJ-FW-Tunnel0]description ##Gre-Tunnel-SH##
[BJ-FW-Tunnel0]ip address 12.0.0.2 255.255.255.0
[BJ-FW-Tunnel0]source 172.16.100.3
[BJ-FW-Tunnel0]destination 172.16.100.2
[BJ-FW-Tunnel0]quit
[SH-FW]ip route-static 17.17.17.0 30 Tunnel0 //对端设备网段静态路由到Tunnel口
[SH-FW]ip route-static 172.16.10.0 24 Tunnel0
[SH-FW]ip route-static 172.16.20.0 24 Tunnel0
GRE是已经建立起来了。 怎么创建基于gre的ipsec呢?
(0)
最佳答案
[SH-FW]acl advanced name IPSec-SH-To-BJ
[SH-FW-acl-ipv4-adv-IPSec-SH-To-BJ]rule permit gre source 172.16.100.2 0 destination 172.16.100.3 0
[SH-FW-acl-ipv4-adv-IPSec-SH-To-BJ]quit
ACL上关键是 gre参数。之前没写。。
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
可以了。谢谢