1.公网ip固定方peiz
ike identity fqdn bj(区分身份)
2.ike提议
ike propoal 1
3.预共享密钥
ike keychain fz(一个密钥串创建两个密码)
pre-shared-key hostname sh key simple 123
pre-shared-key hostname wh key simple 321
4.创建ike模板文件
ike profile sh
exchange-mode aggressive(默认主模式)
match remote identity fqdn sh
proposal 1
keychain fz
ike profile wh
exchange-mode aggressive(默认主模式)
match remote identity fqdn wh
proposal 1
keychain fz
5.创建IPsec的转换集
ipsec transform-set fz
esp authentication-algorithm md5
esp encryption-algorithm des
6.创建策略模板
ipsec policy-template sh 1
transform-set fz
ike-profile sh
ipsec policy-template wh 1
transform-set fz
ike-profile wh
7.绑定模板策略
ipsec policy fz 1 isakmp template sh
ipsec policy fz 2 isakmp template wh
8.进入公网接口下发策略
ipsec apply policy fz
公网ip不固定配置
1.感兴趣流
acl advanced 3000
rule permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
2.ike 身份
ike identity fqdn sh
3.ike提议
ike proposal
4.ike共享密钥
ike keychain bj
pre-shared-key address 100.1.1.1 key simp 123456
5.ike 的配置文件
ike profile bj
exchange-mode aggressive
match remote identity fqdn bj
proposal 1
keychain bj
6.ipsec的转换集
ipsec transform-set bj
esp encryption-algorithm des-cbc
esp authentication-algorithm md5
7.ipsec的协议
ipsec policy bj 1 isakmp
security acl 3000
remote-address 100.1.1.1
transform-set bj
ike-profile bj
8.进入公网接口下发策略
IPSec apply policy bj