H3C MSR20 series router ipsec vpn settings H3C MSR20 series router ipsec vpn settings (the peer end is consistent except the IKE name and ACL data flow direction), local ADSL access mode, access www.2cto.com [ruby] version 5.20, Release 2207P02, basic # sysname testvpn # ike local-name testvpn ike sa keepalive-timer timeout 28800 # domain default enable system # telnet server enable # dar p2p signature-file cfa0: /p2p_default.mtd # port-security enable # acl number 3001 name nat rule 0 den Y ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.0.255 (two ip address ranges are set for peer VPN) rule 20 permit ip source 192.168.2.94 0 ip addresses that allow Intranet nat (ip addresses that can access the Internet) rule 30 permit ip source 192.168.2.80 0 acl number 3026 rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.255 defines the VPN tunnel data flow (peer VPN sets two ip address segments for Reconciliation) www.2cto.com # vlan 1 # domain system access-limit disable state active idle-cut disa Ble self-service-url disable # ike peer testvpn sets IKE peer exchange-mode aggressive mode pre-shared-key cipher nWUE29323vCRHSJ19231231hkSNpRHtg = shared key id-type name ID type to name remote-name testpeer remote IKE name remote-address 202.106.0.20 (because local ADSL Access dynamic IP address, you do not need to specify a remote IP address when specifying the IKE name on the peer end.) local-name testvpn local IKE name nat traversal # ipsec proposal testvpn # ipsec policy testvpn 10 isakmp security acl 3026 matched ACL Pfs dh-group1 ike-peer testvpn IKE peer name proposal testvpn IPSEC Security proposal name www.2cto.com # user-group system group-attribute allow-guest # local-user admin password cipher.] @ QWEUSEWEW = B, 53Q123 = ^ q'm12daaf4 <1 !! Authorization-attribute level 3 service-type telnet service-type web # interface Aux0 async mode flow link-protocol ppp # interface Cellular0/0 async mode protocol link-protocol ppp # interface Dialer1 set PPPOE nat outbound 3001 link-protocol ppp pap local-user 9009239392939 password cipher) ^ 6g123166s032316; R3Q = ^ q'maf4 <1 !! Mtu 1450 ip address ppp-negotiate tcp mss 1024 dialer user admin dialer-group 1 dialer bundle 1 ipsec policy testvpn # interface Ethernet0/0 port link-mode route description inside ip address 192.168.2.1 255.255.255.0 # interface Ethernet0/1 port link-mode route description outside pppoe-client dial-bundle-number 1 tcp mss 1024 ip address dhcp-alloc # interface NULL0 # ip route-static 0.0.0.0 0.0.0.0 Dialer1 # ssh server enable # load xml-configuration # user-interface con 0 user-interface tty 13 user-interface aux 0 user-interface vty 0 4 authentication-mode scheme # return