Verifying the configuration, Network requirements – H3C Technologies H3C SecPath F1000-E User Manual
Page 210
198
•
Select SHA1 as the ESP authentication algorithm.
•
Select DES as the ESP encryption algorithm.
•
Click Apply.
# Configure IKE peer peer.
•
Select VPN > IKE > Peer from the navigation tree and then click Add.
•
Enter peer as the peer name.
•
Select Main as the negotiation mode.
•
Enter 2.2.2.1 as the IP address of the remote gateway.
•
Select Pre-Shared Key and enter abcde as the pre-shared key.
•
Click Apply.
# Configure IPsec policy map1.
•
Select VPN > IPSec > Policy from the navigation tree and then click Add.
•
Enter map1 as the policy name.
•
Enter 10 as the sequence number.
•
Select the IKE peer of peer.
•
Select the IPsec proposal of tran1 and click <<.
•
Enter 3101 as the ACL.
•
Click Apply.
# Apply IPsec policy map1 to GigabitEthernet 0/1.
•
Select VPN > IPSec > IPSec Application from the navigation tree, and then click the
icon of
interface GigabitEthernet 0/1.
•
Select the policy of map1.
•
Click Apply.
Verifying the configuration
After you complete the configuration, packets to be exchanged between subnet 10.1.1.0/24 and subnet
10.1.2.0/24 triggers the negotiation of SAs by IKE. After IKE negotiation succeeds and the IPsec SAs are
established, a static route to subnet 10.1.2.0/24 via 2.2.2.2 is added to the routing table on Device A,
and traffic between subnet 10.1.1.0/24 and subnet 10.1.2.0/24 is protected by IPsec.
Manual mode IPsec tunnel for IPv4 packets configuration
example at the CLI
Network requirements
As shown in
, configure an IPsec tunnel between SecPath A and SecPath B to protect data flows
between subnet 10.1.1.0/24 and subnet 10.1.2.0/24. Configure the tunnel to use the security protocol
ESP, the encryption algorithm DES, and the authentication algorithm SHA1-HMAC-96.
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS