总部(固定IP)配置关键命令:
1. IKEv2提议:
ikev2 proposal vpn-proposal
encryption aes-256-cbc
integrity sha256
dh group5
lifetime 3600
2. IKEv2对等体(分支动态IP用域名):
ikev2 peer branch
remote-address domain ***.*** // 分支DDNS域名
pre-shared-key cipher 123456 // 预共享密钥(分支需一致)
proposal vpn-proposal
nat-traversal 20 // 启用NAT-T穿透
3. IPsec安全提议:
ipsec proposal vpn-proposal
esp encryption aes-256-cbc
esp integrity sha256
transform esp
lifetime 3600
4. IPsec安全策略:
ipsec policy vpn-policy 1 isakmp
ike-peer branch
proposal vpn-proposal
security acl 3000 // 感兴趣流ACL
5. 感兴趣流ACL:
acl 3000
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
6. 应用IPsec策略到公网接口:
interface GigabitEthernet0/0/1 // 公网接口
ipsec policy vpn-policy
分支(动态IP)配置关键命令:
1. IKEv2提议和IPsec提议:同总部。
2. IKEv2对等体(指向总部固定IP):
ikev2 peer headquarter
remote-address 202.100.1.1 // 总部公网IP
pre-shared-key cipher 123456
proposal vpn-proposal
nat-traversal 20
3. IPsec安全策略和ACL:同总部(ACL源地址为分支内网网段,如192.168.2.0/24)。
4. DDNS动态IP处理:
ddns client ***.***
primary 202.100.1.100 // DDNS服务器IP
domain ***.***
暂无评论