按照手册配置的手工建立SA的方式,但是IPSecVPN不通,问题出在哪里?
配置如下:
[Route-A]dis cur
# version 7.1.075, Alpha 7571
# sysname Route-A
# system-working-mode standard
xbar load-single
password-recovery enable
lpu-type f-series
# vlan 1
# dhcp server ip-pool PC
gateway-list 10.112.64.254
network 10.112.64.0 mask 255.255.255.0
# .......
#
interface GigabitEthernet0/0
port link-mode route
combo enable copper
ip address 45.65.78.143 255.255.255.0
ipsec apply policy map1
# .
.......
#
interface GigabitEthernet6/0
port link-mode route
combo enable copper
ip address 10.112.64.254 255.255.255.0
#
.......
#
ip route-static 0.0.0.0 0 45.65.78.254
ip route-static 10.112.63.0 24 GigabitEthernet6/0 45.65.78.143
#
acl advanced 3101 rule 0 permit ip source 10.112.64.0 0.0.0.255 destination 10.112.63.0 0.0.0.255
#
..........
#
ipsec transform-set tran1
esp encryption-algorithm aes-cbc-128
esp authentication-algorithm sha1
# ipsec policy map1 10 manual
transform-set tran1
security acl 3101
remote-address 222.232.222.23
sa spi inbound esp 54321
sa string-key inbound esp cipher $c$3$JDrfMl7RAHCbK/yDFzpnxRpiUZInncHO
sa spi outbound esp 12345
sa string-key outbound esp cipher $c$3$rtQkrJIxE68YUOBkBUPOaNEDeZhOXHUt
# return
典例地址:http://www.h3c.com/cn/d_201405/828769_30005_0.htm#_Toc387663537 采用手工方式建立保护IPv4报文的IPsec隧道
未配置IPSecVPN前,PC_A可以ping通到45.65.78.143,ROUTER-A可以ping通到222.232.222.23,反之亦然。
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
使用IKE的自动协商也不通,都是比这手册敲的。