Ipsec vpn settings for H3C MSR20 series routers

Source: Internet
Author: User
Tags ssh server


H3C MSR20 series router ipsec vpn settings H3C MSR20 series router ipsec vpn settings (the peer end is consistent except the IKE name and ACL data flow direction), local ADSL access mode, access www.2cto.com [ruby] version 5.20, Release 2207P02, basic # sysname testvpn # ike local-name testvpn ike sa keepalive-timer timeout 28800 # domain default enable system # telnet server enable # dar p2p signature-file cfa0: /p2p_default.mtd # port-security enable # acl number 3001 name nat rule 0 den Y ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.0.255 (two ip address ranges are set for peer VPN) rule 20 permit ip source 192.168.2.94 0 ip addresses that allow Intranet nat (ip addresses that can access the Internet) rule 30 permit ip source 192.168.2.80 0 acl number 3026 rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.255 defines the VPN tunnel data flow (peer VPN sets two ip address segments for Reconciliation) www.2cto.com # vlan 1 # domain system access-limit disable state active idle-cut disa Ble self-service-url disable # ike peer testvpn sets IKE peer exchange-mode aggressive mode pre-shared-key cipher nWUE29323vCRHSJ19231231hkSNpRHtg = shared key id-type name ID type to name remote-name testpeer remote IKE name remote-address 202.106.0.20 (because local ADSL Access dynamic IP address, you do not need to specify a remote IP address when specifying the IKE name on the peer end.) local-name testvpn local IKE name nat traversal # ipsec proposal testvpn # ipsec policy testvpn 10 isakmp security acl 3026 matched ACL Pfs dh-group1 ike-peer testvpn IKE peer name proposal testvpn IPSEC Security proposal name www.2cto.com # user-group system group-attribute allow-guest # local-user admin password cipher.] @ QWEUSEWEW = B, 53Q123 = ^ q'm12daaf4 <1 !! Authorization-attribute level 3 service-type telnet service-type web # interface Aux0 async mode flow link-protocol ppp # interface Cellular0/0 async mode protocol link-protocol ppp # interface Dialer1 set PPPOE nat outbound 3001 link-protocol ppp pap local-user 9009239392939 password cipher) ^ 6g123166s032316; R3Q = ^ q'maf4 <1 !! Mtu 1450 ip address ppp-negotiate tcp mss 1024 dialer user admin dialer-group 1 dialer bundle 1 ipsec policy testvpn # interface Ethernet0/0 port link-mode route description inside ip address 192.168.2.1 255.255.255.0 # interface Ethernet0/1 port link-mode route description outside pppoe-client dial-bundle-number 1 tcp mss 1024 ip address dhcp-alloc # interface NULL0 # ip route-static 0.0.0.0 0.0.0.0 Dialer1 # ssh server enable # load xml-configuration # user-interface con 0 user-interface tty 13 user-interface aux 0 user-interface vty 0 4 authentication-mode scheme # return

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.