H3C secpath防火墙IPSEC+L2TP配置案例
H3C secpath防火墙IPSEC+L2TP配置案例H3C secpath防火墙IPSEC+L2TP配置案例
组网:内网--SECPATH F100-C防火墙---SECPATH F100-S防火墙--PC机(安装INODE客户端),PC机要采用IPSEC+L2TP的方式拨到F100-C防火墙上,访问内网资源。
<A>dis cu
#
sysname A
#
super password level 3 cipher I!]2">*=$'T=[;";Q!!
#
l2tp enable
#
ike local-name server
#
firewall packet-filter enable
firewall packet-filter default permit
#
firewall statistic system enable
#
radius scheme system
server-type huawei
#
domain system
ip pool 0 192.168.128.1 192.168.128.253
#
local-user l2tp
password simple l2tp
service-type ppp
#
ike peer qzrb
exchange-mode aggressive
pre-shared-key quidway
id-type name
remote-name client
nat traversal
#
ipsec proposal qzrb
#
ipsec policy-template temp 1
ike-peer qzrb
proposal qzrb
#
ipsec policy qzrb 1 isakmp template temp
#
acl number 2002
rule 0 permit source 192.168.245.0 0.0.0.255
#
interface Virtual-Template0
ppp authentication-mode pap
ip address 192.168.128.254 255.255.255.0
remote address pool
#
interface Aux0
async mode flow
#
interface GigabitEthernet0/0
duplex full
ip address 61.130.55.82 255.255.255.248
nat outbound 2002
ipsec policy qzrb
#
interface GigabitEthernet0/1
http://bbs.hh010.com/xwb/images/bgimg/icon_logo.png 该贴已经同步到 COCO999的微博 {:6_268:} ipio ipiopi iupuiop 不错 真心不错 {:6_267:} 学习 学习 学习一下 配置文件好像不全啊
页:
[1]