H3CIPV6之ipsec+IKE野蠻模式典型組網(wǎng)配置案例_第1頁(yè)
H3CIPV6之ipsec+IKE野蠻模式典型組網(wǎng)配置案例_第2頁(yè)
H3CIPV6之ipsec+IKE野蠻模式典型組網(wǎng)配置案例_第3頁(yè)
H3CIPV6之ipsec+IKE野蠻模式典型組網(wǎng)配置案例_第4頁(yè)
H3CIPV6之ipsec+IKE野蠻模式典型組網(wǎng)配置案例_第5頁(yè)
已閱讀5頁(yè),還剩4頁(yè)未讀 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

R1組網(wǎng)說(shuō)明:本案例采用H3CHCL模擬器來(lái)模擬IPV6IPSECIKE+蠻模式典型組網(wǎng)配置。為了確保數(shù)據(jù)的傳輸安全,在R1與R2之間建立IPSECVPF隧道采用野蠻模式。最后R1與R2之間采用OSPFV3路由協(xié)議互聯(lián)。配置思路:1、按照網(wǎng)絡(luò)拓?fù)鋱D正確配置 IP地址2、 R1與R2之間運(yùn)行OSPFV3路由協(xié)議3、 R1與R2采用IPSECIKE野蠻模式建立VPN隧道。配置過(guò)程:第一階段調(diào)試(基礎(chǔ)網(wǎng)絡(luò)配置):SW1:<H3C>sysSystemView:returntoUserViewwithCtrl+Z.[H3C]sysnameSW1[SW1]intloopback0[SW1-LoopBackO]ipaddress3.3.3.332[SW1-LoopBackO]quit[SW1]ospfv31[SW1-ospfv3-1]import-routedirect[SW1-ospfv3-1]router-id3.3.3.3[SW1-ospfv3-1]quit[SW1]intgi1/0/1[SW1-GigabitEthernet1/0/1]portlink-moderoute[SW1-GigabitEthernet1/0/1]des<connecttoR2>[SW1-GigabitEthernet1/0/1]ipv6address3::264[SW1-GigabitEthernet1/0/1]ospfv31area0[SW1-GigabitEthernet1/0/1]quitR1:<H3C>sysSystemView:returntoUserViewwithCtrl+Z.[H3C]sysnameR1[R1]intloopback0[R1-LoopBack0]ipaddress1.1.1.132[R1-LoopBack0]quit[R1]ospfv31[R1-ospfv3-1]router-id1.1.1.1[R1-ospfv3-1]import-routedirect[R1-ospfv3-1]quit[R1]intgi0/0[R1-GigabitEthernet0/0]ipv6address1::164[R1-GigabitEthernet0/0]ospfv31area0[R1-GigabitEthernet0/0]quit[R1]ints1/0[R1-Serial1/0]des<connecttoR2>[R1-Serial1/0]ipv6address2::164[R1-Serial1/0]ospfv31area0[R1-Serial1/0]quitR2:<H3C>sysSystemView:returntoUserViewwithCtrl+Z.[H3C]sysnameR2[R2]intloopback0[R2-LoopBack0]ipaddress2.2.2.232[R2-LoopBack0]quit[R2]ospfv31[R2-ospfv3-1]import-routedirect[R2-ospfv3-1]router-id2.2.2.2[R2-ospfv3-1]quit[R2]ints1/0[R2-Serial1/0]des<connecttoR1>[R2-Serial1/0]ipv6address2::264[R2-Serial1/0]ospfv31area0[R2-Serial1/0]quit[R2]intgi0/0[R2-GigabitEthernet0/0]des<connecttoSW1>[R2-GigabitEthernet0/0]ipv6address3::164[R2-GigabitEthernet0/0]ospfv31area0[R2-GigabitEthernet0/0]quit第一階段測(cè)試:物理機(jī)填寫(xiě)IP地址:第二階段調(diào)試(IPSEC+IKE予蠻模式關(guān)鍵配置點(diǎn)):[R1]aclipv6advaneed3000[R1-acl-ipv6-adv-3000]rule0permitipv6source1::/64destination3::/64[R1-acl-ipv6-adv-3000]quit[R1]ikeidentityfqdnr1[R1]ikeproposal1[R1-ike-proposal-1]quit[R1]ikekeychainjames[R1-ike-keychain-james]pre-shared-keyaddressipv62::264keysimplejames[R1-ike-keychain-james]quit[R1]ikeprofilejames[R1-ike-profile-james]keychainjames[R1-ike-profile-james]proposal1[R1-ike-profile-james]matchremoteidentityaddressipv62::2[R1-ike-profile-james]exchange-modeaggressive[R1-ike-profile-james]quit[R1]ipsectransform-setjames[R1-ipsec-transform-set-james]protocolesp[R1-ipsec-transform-set-james]encapsulation-modetunnel[R1-ipsec-transform-set-james]espauthentication-algorithmmd5[R1-ipsec-transform-set-james]espencryption-algorithmdes-cbc[R1-ipsec-transform-set-james]quit[R1]ipsecipv6-policyjames1isakmp[R1-ipsec-ipv6-policy-isakmp-james-1]securityaclipv63000[R1-ipsec-ipv6-policy-isakmp-james-1]transform-setjames[R1-ipsec-ipv6-policy-isakmp-james-1]ike-profilejames[R1-ipsec-ipv6-policy-isakmp-james-1]remote-addressipv62::2[R1-ipsec-ipv6-policy-isakmp-james-1]quit[R1]ints1/0[R1-Serial1/0]ipsecapplyipv6-policyjames[R1-Serial1/0]quitR2:[R2]aclipv6advanced3000[R2-acl-ipv6-adv-3000]rule0permitipv6source3::/64destination1::/64[R2-acl-ipv6-adv-3000]quit[R2]ikeidentityfqdnr2[R2]ikeproposal1[R2-ike-proposal-1]quit[R2]ikekeychainjames[R2-ike-keychain-james]pre-shared-keyhostnamer1keysimplejames[R2-ike-keychain-james]quit[R2]ipsectransform-setjames[R2-ipsec-transform-set-james]protocolesp[R2-ipsec-transform-set-james]encapsulation-modetunnel[R2-ipsec-transform-set-james]espauthentication-algorithmmd5[R2-ipsec-transform-set-james]espencryption-algorithmdes-cbc[R2-ipsec-transform-set-james]quit[R2]ikeprofilejames[R2-ike-profile-james]keychainjames[R2-ike-profile-james]proposal1[R2-ike-profile-james]matchremoteidentityfqdnr1[R2-ike-profile-james]exchange-modeaggressive[R2-ike-profile-james]quit[R2]ipsecipv6-policy-templatejames1[R2-ipsec-ipv6-policy-template-james-1]securityaclipv63000[R2-ipsec-ipv6-policy-template-james-1]ike-profilejames[R2-ipsec-ipv6-policy-template-james-1]transform-setjames[R2-ipsec-ipv6-policy-template-james-1]quit[R2]ipsecipv6-policyjames1isakmptemplatejames[R2]ints1/0[R2-Serial1/0]ipsecapplyipv6-policyjames[R2-Serial1/0]quit第二階段測(cè)試:查看R1的IPSEC顯示信息:[Rl]disipsectunnelTunnelID:0Sta七口日:ActivePerfectforwardaecrecy:Inaidevpn-instanc已=S真SFI:QU^QUD^;230707375 [ESP]inbound: 2239B5553 [ESF]Tunnel:Localaddress:2;:1remoteaddress;2;;2Flow:souraddr:1::port:0prorecal:ipv6descaddr:3::port:0protocol:ipvft[Rl]查看R2的IPSEC顯示信息:[R2]disipsecipv6-policyIPsecEolxcy:jamesInterface:Seriall/OSequencenumber:1Mode:TemplacePolicytemplatename:james[R2]|[R2]dlsipsecipv6-policy-templaceIPsecPolicyTexnplare:jam.esSequencenumber:1TrafficFlowConfidentiality:DisabledSecuritydataflow:3000Selectormode:standardLocaladdress:IKEprofile:JamesIKEv2profile:Remoteaddress:Transformset:JamesIPsecSAlocalduration(timebased.):IPsecSAlocalduration(trafficbased):SAidletime![R2]|TOC\o"1-5"\h\z[RZjaisipsecuransrorm-seu ■IPsectransformsec:james HState:complete ■Encapsulationmode:tunnel ■ESN:Disabled HPFS: .Transform:ESP HESPprotocol:Integrity;MD5 .Encryption:DE5-CBC ■[R2]|[R2]disIpseqvurmelTunnelID;QSeamus:ActivePerfectCoryraxdsecrecy:Insidevpn-insvance:SA"5Sfl;outbound:2239S5SS3 {0x0cl59b±51} [ESP]inbound: 2907B7375 {0itll551D2f) [ESP]Tunnel:localaddress;2;;2remoEeaddress:2::1Flow:sour耳口口匚;3;:/6^port;;0prorocol:ipv-&desLaddr:1!:/6^portiQprotocol:ipv^[R2]|[R3]disikema匚口口nection-ID RemoteFlagDOI12::1Flags:RD―EtEADYRL--ELEPLACEDFD-FADING[R2]|RDRE-REKEVIF^ec物理機(jī)依然可以PING通SW1:\_IKbL*-!iL_2 S5B0O^-Mfl5-GE_3Q<SWl>tFefc2414:24:SS:5?-62□SOSW1SHELL;S/BEELLLOGIS:Censelalegged二血fzamccnO?<S?1><SW1><3W1><5wi>pmoIDVfi1:52Pijig6(5€da:凰bycGfl)3n2--->1:i2rpeens7TRLZtabre

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

最新文檔

評(píng)論

0/150

提交評(píng)論