网络拓扑 : 192.168.6.11-----192.168.6.12
ip xfrm state add src 192.168.6.11 dst 192.168.6.12 proto esp spi 0x00000301 mode tunnel auth sm3 0x0123456789abcdef0123456789abcdef enc sm4 0x0123456789abcdef0123456789abcdef
ip xfrm state add src 192.168.6.12 dst 192.168.6.11 proto esp spi 0x00000302 mode tunnel auth sm3 0x0123456789abcdef0123456789abcdef enc sm4 0x0123456789abcdef0123456789abcdef
ip xfrm state get src 192.168.6.11 dst 192.168.6.12 proto esp spi 0x00000301
ip xfrm policy add src 192.168.6.11 dst 192.168.6.12 dir out ptype main tmpl src 192.168.6.11 dst 192.168.6.12 proto esp mode tunnel
ip xfrm policy add src 192.168.6.12 dst 192.168.6.11 dir in ptype main tmpl src 192.168.6.12 dst 192.168.6.11 proto esp mode tunnel
以上五条命令在6.11上执行。6.12上命令一致,但是要将第4/5条中的in/out换一下。别忘记装上驱动!
ip xfrm state/policy flush 输错了,用来清空。</