华为设备IPSec配置实现GRE封装
前提条件:在公网上建立通信隧道
配置步骤:
配置IKE策略
ike proposal 1
encryption-algorithm aes-cbc 128
integrity-algorithm sha256
dh group2
lifetime seconds 86400
ike peer XXX名称
pre-shared-key cipher xxx密钥
ike policy 1 proposal 1
pfs dh-group2
lifetime duration 86400 (协商通道保活时间需与对端保持一致)
peer XXX为IKE名称
配置IPSec策略
ipsec proposal 1
esp authentication-algorithm sha256
esp encryption-algorithm aes-cbc 128
lifetime seconds 86400
ipsec policy 1 isakmp
policy policy1
proposal 1
pfs group2
security acl number 100
tunnel select 1
tunnel encapsulation gre
peer XXX
配置ACL (用于匹配本段到对端激活传输数据流)
acl 100
rule permit ip source 192.168.1.0 0.0.0.255 d