日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當(dāng)前位置: 首頁 > 编程资源 > 编程问答 >内容正文

编程问答

华为USG Firewall Ipsec L2L

發(fā)布時(shí)間:2025/6/16 编程问答 65 豆豆
生活随笔 收集整理的這篇文章主要介紹了 华为USG Firewall Ipsec L2L 小編覺得挺不錯(cuò)的,現(xiàn)在分享給大家,幫大家做個(gè)參考.

*需要解決的問題
1、Untrust local inbound /esp ike (做策略放行IKE/ESP流量)
policy interzone local untrust inbound
policy 0
action permit
policy service service-set ike
policy service service-set esp

2、trust untrust inbound /source ip.destination ip (放行IP回傳的流量)
policy interzone trust untrust inbound
policy 0
action permit
policy source 192.168.10.0 mask 24
policy destination 172.16.10.0 mask 24
?
3、trust untrust outbound/source ip.destination ip (放行IP的出去流量)
policy interzone trust untrust outbound
policy 0
action permit
policy source 172.16.10.0 mask 24
policy destination 192.168.10.0 mask 24
?
4、放行端口UDP 500
ip service-set ike type object
service 0 protocol udp destination-port 500

?

?
<Site_1>dis current-configuration
[V200R003C00]
#
sysname Site_1
#
interface GigabitEthernet0/0/0
ip address 192.168.10.10 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 192.168.10.254
#
return
<Site_1>
?
?
<Firewall_1>dis current-configuration
09:01:29 2015/08/31
#
acl number 3000
rule 0 permit ip source 192.168.10.0 0.0.0.255 destination 172.16.10.0 0.0.0.255
#
ike peer fw2
pre-shared-key %$%$a)%OV{\VtHc7c+S#@4|<Fi`W%$%$
remote-address 100.100.200.100
#
ipsec proposal huawei
#
ipsec policy lab 10 isakmp
security acl 3000
ike-peer fw2
proposal huawei
#
interface GigabitEthernet0/0/0
alias GE0/MGMT
ip address 100.100.100.100 255.255.255.0
ipsec policy lab

interface GigabitEthernet0/0/1
ip address 192.168.10.254 255.255.255.0
#
firewall zone local
set priority 100

firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/0
#
firewall zone dmz
set priority 50
#
ip route-static 0.0.0.0 0.0.0.0 100.100.100.200
#
ip service-set ike type object
service 0 protocol udp destination-port 500 ---------解決端口號(hào)UDP500
#
sysname Firewall_1

policy interzone local untrust inbound ----------放行IKE ESP流量
policy 0
action permit
policy service service-set ike
policy service service-set esp
#
policy interzone trust untrust inbound ----------允許tr--un 流量進(jìn)來
policy 0
action permit
policy source 172.16.10.0 mask 24
policy destination 192.168.10.0 mask 24
#
policy interzone trust untrust outbound ----------允許tr--un 流量出去
policy 0
action permit
policy source 192.168.10.0 mask 24
policy destination 172.16.10.0 mask 24
#
return
<Firewall_1>
?
?
<Intenet>dis current-configuration
[V200R003C00]
#
sysname Intenet
#
interface GigabitEthernet0/0/0
ip address 100.100.100.200 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 100.100.200.200 255.255.255.0
#
return
<Intenet>
?
?
<Firewall_2>dis current-configuration
09:05:02 2015/08/31
#
acl number 3000
rule 5 permit ip source 172.16.10.0 0.0.0.255 destination 192.168.10.0 0.0.0.255
#
ike peer fw1
pre-shared-key %$%$>iw;;,1n$Xn:taCrVb`6FSJA%$%$
remote-address 100.100.100.100
#
ipsec proposal huawei
#
ipsec policy lab 10 isakmp
security acl 3000
ike-peer fw1
proposal huawei
#
interface GigabitEthernet0/0/0
alias GE0/MGMT
ip address 100.100.200.100 255.255.255.0
ipsec policy lab

interface GigabitEthernet0/0/1
ip address 172.16.10.254 255.255.255.0
#
firewall zone local
set priority 100

firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/0
#
firewall zone dmz
set priority 50
#
ip route-static 0.0.0.0 0.0.0.0 100.100.200.200
#
ip service-set ike type object
service 0 protocol udp destination-port 500
#
sysname Firewall_2

pki ocsp response cache refresh interval 0
pki ocsp response cache number 0
#
policy interzone local untrust inbound
policy 0
action permit
policy service service-set ike
policy service service-set esp
#
policy interzone trust untrust inbound
policy 0
action permit
policy source 192.168.10.0 mask 24
policy destination 172.16.10.0 mask 24
#
policy interzone trust untrust outbound
policy 0
action permit
policy source 172.16.10.0 mask 24
policy destination 192.168.10.0 mask 24
#
return
<Firewall_2>
?
?
<Site_2>dis current-configuration
[V200R003C00]
#
sysname Site_2
#
interface GigabitEthernet0/0/1
ip address 172.16.10.10 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 172.16.10.254
#
return
<Site_2>
?
?
Test:
<Firewall_2>dis ipsec sa ----------------------配置詳細(xì)詳細(xì)
09:08:52 2015/08/31

Interface: GigabitEthernet0/0/0
path MTU: 1500

?

IPsec policy name: "lab"
sequence number: 10
mode: isakmp
***: public

connection id: 40001 rule number: 5 encapsulation mode: tunnel

.................................
<Firewall_2>
?
<Firewall_2>dis ipsec statistics ----------------------加密解密的數(shù)據(jù)
09:09:47 2015/08/31
the security packet statistics:
input/output security packets: 23/23
input/output security bytes: 1932/1932
input/output dropped security packets: 0/0
the encrypt packet statistics
send sae:23, recv sae:23, send err:0
local cpu:23, other cpu:0, recv other cpu:0
intact packet:7, first slice:0, after slice:0
the decrypt packet statistics
send sae:23, recv sae:23, send err:0
?
?
<Firewall_2>display ipsec sa brief --------------------看是否與對(duì)端設(shè)備建立的狀態(tài)
09:12:27 2015/08/31
current ipsec sa number: 2
current ipsec tunnel number: 1

Src Address Dst Address SPI Protocol Algorithm

100.100.100.100 100.100.200.100 1982786750 ESP E:DES;A:HMAC-MD5-96;
100.100.200.100 100.100.100.100 2672106707 ESP E:DES;A:HMAC-MD5-96;
<Firewall_2>

轉(zhuǎn)載于:https://blog.51cto.com/9616635/2056335

總結(jié)

以上是生活随笔為你收集整理的华为USG Firewall Ipsec L2L的全部?jī)?nèi)容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網(wǎng)站內(nèi)容還不錯(cuò),歡迎將生活随笔推薦給好友。

主站蜘蛛池模板: av在线超碰| 国产午夜精品无码一区二区 | 国产一区二区在线观看免费 | 成年午夜视频 | 九九九在线 | 狠狠爱综合网 | 少妇3p视频 | 国产99久久久 | 国产学生美女无遮拦高潮视频 | 天天色图片 | 俺去俺来也在线www色官网 | 久久在线视频精品 | 国产精品国产三级国产播12软件 | 中文天堂资源在线 | 99精彩视频| 国产精品久久久久久久久免费相片 | 在线不卡av | 亚洲综合免费观看高清完整版 | 亚洲中文一区二区三区 | 亚洲精品免费在线观看 | 秋霞国产一区 | 二三区视频 | 国产黄色视 | 亚洲国产欧美另类 | 日本做爰高潮又黄又爽 | 日韩免费观看一区二区 | 美女高潮视频在线观看 | 人妻饥渴偷公乱中文字幕 | 中国极品少妇xxxx | 北条麻妃一区二区三区在线观看 | 中国大陆高清aⅴ毛片 | 色肉色伦交av色肉色伦 | 色哟哟免费观看 | 久久久久久久国产精品毛片 | 久久久久亚洲 | 永久免费看片在线观看 | 制服丝袜一区 | www.av在线免费观看 | 国产精品久久久免费观看 | 神马久久久久久久久 | 欧美丰满老妇 | 国产毛片久久久久久国产毛片 | 好吊在线视频 | 不卡的一区二区 | 亚洲精品一卡 | 懂色av一区二区三区蜜臀 | 国产精品美女毛片真酒店 | 国产精品国产三级国产aⅴ 欧美bbbbbbbbbbbb18av | 国产亚洲av在线 | 亚洲综合自拍偷拍 | 天天摸天天舔 | 亚洲免费影院 | 性生活一区 | 青青青视频在线 | 欧美一区二区日韩 | 精品一区91 | 亚洲开心网| 国产一区视频观看 | 亚洲av无码久久忘忧草 | 后宫秀女调教(高h,np) | 日日干天天射 | 久久久久亚洲精品中文字幕 | 好看的中文字幕av | 日韩中文字幕av | 污黄网站在线观看 | 久久综合亚洲色hezyo国产 | 亚洲福利小视频 | 日韩精品网址 | av第一福利大全导航 | 两个人看的www视频免费完整版 | 少妇捆绑紧缚av | 久草手机在线观看 | 成人av免费网站 | 丰满人妻翻云覆雨呻吟视频 | 日韩精品亚洲精品 | 亚洲精品色 | 国内自拍偷拍 | 日本久久久久 | 性生交大全免费看 | 亚洲中文字幕无码不卡电影 | 春色影视| 麻豆传媒在线视频 | 人人妻人人爽人人澡人人精品 | 国产91页| 性久久久 | 亚洲国产日韩在线观看 | 黄色在线观看网站 | 涩涩在线播放 | 欧美性受xxxx | 高清中文字幕av | 99re在线精品视频 | 爱情岛论坛永久入口 | 日批视频免费看 | 国产精品扒开做爽爽爽的视频 | 国产白浆视频 | 精品免费一区二区 | 91在线观看 | 少妇人妻一区二区三区 | 久久精品国产亚洲av麻豆色欲 |