Vyos IPsec Server 对接 Huawei 路由器 IPsec Client(GRE Over IPsec)
设备环境
Vyos 1.3 ETH0 公网IP
Huawei AR651W G0/0/8 DHCP
IPsec感兴趣流
Vyos_100.64.0.1/32 === Huawei_100.64.0.2/32
Vyos 公网IP IPsec Server 模板
echo '>>>IPSec Server 配置<<<'
set vpn ipsec esp-group esp_proposal1 compression 'disable'
set vpn ipsec esp-group esp_proposal1 lifetime '3600'
set vpn ipsec esp-group esp_proposal1 mode 'tunnel'
set vpn ipsec esp-group esp_proposal1 pfs 'dh-group2'
set vpn ipsec esp-group esp_proposal1 proposal 1 encryption '3des'
set vpn ipsec esp-group esp_proposal1 proposal 1 hash 'sha1'
set vpn ipsec ike-group ike_proposal1 ikev2-reauth 'no'
set vpn ipsec ike-group ike_proposal1 key-exchange 'ikev1'
set vpn i