最佳答案
没看懂你要做什么
(0)
明显是ipsec
明显是ipsec
山石防火墙(总部)设置:
动态IP地址,指定一个FQDN(zongbu),共享密钥:xxxxxxxx,加密方式为:aes-cbc-128,验证方式为sha1,这些要与对端相对应设置就行,不需要一样
H3C(分部)设置:
nqa entry admin admin1 //nqa可以自动触发响应,保证内网一直持续向总部发起请求,确保隧道建立
type icmp-echo
destination ip 172.10.0.5 //总部内网服务器IP,根据实际情况修改
frequency 5000
history-record enable
history-record number 10
probe count 10
probe timeout 500
source ip 192.168.10.10 //分部内网客户端IP,根据实际情况修改
nqa schedule admin admin1 start-time now lifetime forever
ip route-static 172.10.0.0 24 Dialer1 //设置个路由
acl advanced 3100
description 允许分部流量到总部内网
rule 1 permit ip source 192.168.10.0 0.0.0.255 destination 172.10.0.0 0.0.0.255
acl advanced 3001
description 拒绝分部流量被NAT出公网
rule 1 deny ip source 192.168.10.0 0.0.0.255 destination 172.10.0.0 0.0.0.255
rule 100 permit ip
ipsec transform-set connect
esp encryption-algorithm aes-cbc-128
esp authentication-algorithm sha1
pfs dh-group2
ipsec policy connect 5 isakmp
transform-set connect
security acl 3100
remote-address 59.0.0.1 //总部公网IP
description ToGLDataCenter
ike-profile connect
ike dpd interval 10 periodic
ike identity fqdn
ike profile connect
keychain 10
dpd interval 10 on-demand
exchange-mode aggressive
local-identity fqdn fenbu
match remote identity address 59.0.0.1 255.255.255.255 //总部公网IP地址
match remote identity fqdn zongbu
match local address Dialer1
proposal 100
ike proposal 100
encryption-algorithm aes-cbc-128
dh group2
ike keychain 10
match local address Dialer1
pre-shared-key address 59.0.0.1 255.255.255.0 key simple xxxxxxxx //总部公网IP地址和共享密钥
pre-shared-key hostname gldatacenter key simple xxxxxxxx //总部公网IP地址和共享密钥
interface Dialer1
ipsec apply policy fenbu
nat outbound 3001
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明