Believe that if the reader participates in the work, more or less have been used VPN (virtual private network), this is a good thing ah, you can access the company intranet resources, small series is currently very like this technology, of course, use this technology is not only a point of advantage, the advantages of using VPN have the following points:
1. Reduce the cost of the enterprise. When using VPN for remote access, only pay the local telephone fee, save the expensive long-distance telephone charge;
2. Can greatly save the link rent, equipment acquisition and network maintenance costs, reduce the operating costs of enterprises;
3. The ability to integrate the Internet, corporate intranet (Intranet), Enterprise External Network (Extranet), and remote Access to the same external line, without having to manage Internet lanes as before, Long-distance data line, such as many different lines.
4. Use of encryption VPN technology to ensure that data travel through the network security
protocols used to implement a VPN
1. Two-layer protocol {PPTP L2TP l2f}
2. Three layer protocol {GRE IPSec}
Classification of VPN
1.VPDN dial-up VPN PPTP L2TP stand-alone---network (user VPN)
2. Private Line VPN Network---Network (Enterprise network VPN)
In this blog to achieve a small part of the first to implement a three-layer protocol GRE VPN, in the future of the article will also implement IPSec VPN
Configuration tasks:
1. Create an interface
Interface Tunnel number
Tunnel-protocol GRE
Sourec Tunnel Source Address
Destination Tunnel End Address
IP Add this interface address
2. Routing
Dynamic (RIP realizes connectivity between the tunnel and intranet)
The experimental topology is shown in Figure 1-1:
Figure 1-1
Huawei Equipment Implementation
The configuration of step 1:FW1
Fw1
[Fw1]dis CU
#
sysname FW1//Set device name
#
Firewall Packet-filter Enable
Firewall Packet-filter Default Permit
#
Insulate
#
Firewall statistic system Enable
#
RADIUS scheme System
Server-type Extended
#
Domain system
#
Local-user Admin
Password cipher.] @USE =b,53q=^q ' maf4<1!!
Service-type Telnet Terminal
Level 3
Service-type FTP
#
Interface Aux0
Async Mode Flow