3分支GRE OVER IPSEC + OSPF

3分支GRE OVER IPSEC + OSPF

在这里插入图片描述注意:ospf宣告不要用0.0.0.0 255.255.255.255 宣告
AR21 与 23之间的ipsce 和 21 与 24、23 与24之间不一样。

AR21
[AR 21]dis cu
[V200R003C00]

sysname AR 21

snmp-agent local-engineid 800007DB03000000000000
snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load flash:/portalpage.zip

drop illegal-mac alarm

wlan ac-global carrier id other ac id 0

set cpu-usage threshold 80 restore 75

acl number 3000
rule 5 permit ip
acl number 3001
rule 5 permit ip source 100.0.12.1 0 destination 100.0.23.3 0

ipsec proposal huawei
ipsec proposal ospf

ike proposal 10

ike peer ospf v2
pre-shared-key simple 12345678
ike-proposal 10
peer-id-type ip
ike peer r1 v2
pre-shared-key simple 12345678
ike-proposal 10
remote-address 100.0.23.3

ipsec policy huawei 10 isakmp
security acl 3001
ike-peer r1
proposal huawei

ipsec profile ospf
ike-peer ospf
proposal ospf

aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher % % K8m.Nt84DZ}e#<0`8bmE3Uw}% %
local-user admin service-type http

firewall zone Local
priority 15

interface GigabitEthernet0/0/0
ip address 100.0.12.1 255.255.255.0
ipsec policy huawei
nat outbound 3000

interface GigabitEthernet0/0/1

interface GigabitEthernet0/0/2
ip address 192.168.1.1 255.255.255.0

interface NULL0

interface LoopBack0
ip address 1.1.1.1 255.255.255.255

interface Tunnel0/0/0
ip address 10.1.1.21 255.255.255.0
tunnel-protocol gre
source 100.0.12.1
destination 100.0.23.3

interface Tunnel0/0/1
ip address 10.1.2.21 255.255.255.0
tunnel-protocol gre
source 100.0.12.1
destination 100.0.24.24
ipsec profile ospf

ospf 1 router-id 1.1.1.1
area 0.0.0.0
network 1.1.1.1 0.0.0.0
network 10.1.1.0 0.0.0.255
network 10.1.2.0 0.0.0.255
network 192.168.1.0 0.0.0.255

ip route-static 0.0.0.0 0.0.0.0 100.0.12.2

user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20

wlan ac

return

AR23

<AR 23>DIS CU
[V200R003C00]

sysname AR 23

snmp-agent local-engineid 800007DB03000000000000
snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load flash:/portalpage.zip

drop illegal-mac alarm

wlan ac-global carrier id other ac id 0

set cpu-usage threshold 80 restore 75

acl number 3000
rule 5 permit ip
acl number 3001
rule 5 permit ip source 100.0.23.3 0 destination 100.0.12.1 0

ipsec proposal huawei
ipsec proposal ospf

ike proposal 10

ike peer ospf v2
pre-shared-key simple 12345678
ike-proposal 10
peer-id-type ip
ike peer r3 v2
pre-shared-key simple 12345678
ike-proposal 10
remote-address 100.0.12.1

ipsec policy huawei 10 isakmp
security acl 3001
ike-peer r3
proposal huawei

ipsec profile ospf
ike-peer ospf
proposal ospf

aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher % % K8m.Nt84DZ}e#<0`8bmE3Uw}% %
local-user admin service-type http

firewall zone Local
priority 15

interface GigabitEthernet0/0/0

interface GigabitEthernet0/0/1
ip address 100.0.23.3 255.255.255.0
ipsec policy huawei
nat outbound 3000

interface GigabitEthernet0/0/2
ip address 192.168.2.1 255.255.255.0

interface NULL0

interface LoopBack0
ip address 2.2.2.2 255.255.255.255

interface Tunnel0/0/0
ip address 10.1.1.23 255.255.255.0
tunnel-protocol gre
source 100.0.23.3
destination 100.0.12.1

interface Tunnel0/0/1
ip address 10.1.2.23 255.255.255.0
tunnel-protocol gre
source 100.0.23.3
destination 100.0.24.24
ipsec profile ospf

ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 2.2.2.2 0.0.0.0
network 10.1.1.0 0.0.0.255
network 10.1.2.0 0.0.0.255
network 192.168.2.0 0.0.0.255

ip route-static 0.0.0.0 0.0.0.0 100.0.23.2

user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20

wlan ac

return

AR24

<AR 24>DIS CU
[V200R003C00]

sysname AR 24

snmp-agent local-engineid 800007DB03000000000000
snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load portalpage.zip

drop illegal-mac alarm

set cpu-usage threshold 80 restore 75

acl number 3000
rule 10 permit ip

ipsec proposal ospf

ike proposal 10

ike peer ospf v2
pre-shared-key simple 12345678
ike-proposal 10
peer-id-type ip

ipsec profile ospf
ike-peer ospf
proposal ospf
ipsec profile ospf1
ike-peer ospf
proposal ospf

aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher % % K8m.Nt84DZ}e#<0`8bmE3Uw}% %
local-user admin service-type http

firewall zone Local
priority 15

interface GigabitEthernet0/0/0
ip address 100.0.24.24 255.255.255.0
nat outbound 3000

interface GigabitEthernet0/0/1

interface GigabitEthernet0/0/2
ip address 192.168.3.1 255.255.255.0

interface NULL0

interface LoopBack0
ip address 24.24.24.24 255.255.255.255

interface Tunnel0/0/0
ip address 10.1.2.25 255.255.255.0
tunnel-protocol gre
source 100.0.24.24
destination 100.0.23.3
ipsec profile ospf1

interface Tunnel0/0/1
ip address 10.1.1.24 255.255.255.0
tunnel-protocol gre
source 100.0.24.24
destination 100.0.12.1
ipsec profile ospf

ospf 1 router-id 24.24.24.24
area 0.0.0.0
network 10.1.1.0 0.0.0.255
network 10.1.2.0 0.0.0.255
network 24.24.24.24 0.0.0.0
network 192.168.3.0 0.0.0.255

ip route-static 0.0.0.0 0.0.0.0 100.0.24.22

user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20

wlan ac

return

AR 22

dis cu
[V200R003C00]

snmp-agent local-engineid 800007DB03000000000000
snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load flash:/portalpage.zip

drop illegal-mac alarm

wlan ac-global carrier id other ac id 0

set cpu-usage threshold 80 restore 75

aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher % % K8m.Nt84DZ}e#<0`8bmE3Uw}% %
local-user admin service-type http

firewall zone Local
priority 15

interface GigabitEthernet0/0/0
ip address 100.0.12.2 255.255.255.0

interface GigabitEthernet0/0/1
ip address 100.0.23.2 255.255.255.0

interface GigabitEthernet0/0/2
ip address 100.0.24.22 255.255.255.0

interface NULL0

user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20

wlan ac

return

  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

信飞翔

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值