GRE在里,IPsec在外。IPsec不支持组播,GRE支持。所以用GRE去封装路由协议。
总部:(多个分部时,使用模板)
ike local-name zongbu
ike peer fenbu
exchange-mode aggressive //野蛮模式
pre-shared-key simple h3c
id-type name
remote-name fenbu
ipsec proposal PROPOSAL
ipsec policy-template fenbu 1
ike-peer fenbu
proposal PROPOSAL
ipsec policy h3c 1 isakmp template fenbu
interface GigabitEthernet0/0/2
ipsec policy h3c
分部:
ike local-name fenbu //所有分部都使用一样的name
ike peer zongbu
exchange-mode aggressive
pre-shared-key simple h3c
id-type name
remote-name zongbu
remote-address 61.67.1.1 //总部IP地址
acl number 3001
rule permit ip source 192.168.255.3 0 destination 192.168.255.1 0 //GRE的IP地址
ipsec proposal PROPOSAL
ipsec policy h3c 1 isakmp
security acl 3001
ike-peer zongbu
proposal PROPOSAL
interface GigabitEthernet0/0/1
ipsec policy h3c