IKEv2无“野蛮模式”,但支持“身份ID协商”,分支IP不固定场景需用“名字(DN或FQDN)替代IP作为身份标识,总部采用“模板方式”响应策略模板。
关键配置思路(总部+分支)
1. 总部(F1000-M-XI)
IKEv2 Proposal:
ikev2 proposal 10
encryption-algorithm aes-256
authentication-algorithm sha256
dh group14
IKEv2 Policy:
ikev2 policy 10
proposal 10
IKEv2 Profile:
ikev2 profile branch_profile
keyring local key-name branch1 key simple 123456 // 预共享密钥,建议每个分支一个
identity local fqdn headquarter.h3c.com
match remote fqdn branch1.h3c.com // 匹配分支名字
IPSec Policy Template:
ipsec transform-set ts1
esp encryption-algorithm aes-256
esp authentication-algorithm sha256
ipsec policy-template temp1 10
transform-set ts1
ikev2-profile branch_profile
接口应用:
interface GigabitEthernet0/0
ipsec policy-template apply temp1
2. 分支
**明确配置总部公网IP。
identity local fqdn branch1.h3c.com。
ikev2 profile 中指向 remote-address 总部公网IP。
接口下常规 apply ipsec policy (isakmp方式)。
注意: 需确保预共享密钥和身份ID(Name/FQDN)两端必须匹配,并且注意设备版本需支持IKEv2典型分支场景。
暂无评论