Network security: GRE

Source: Internet
Author: User
Tags firewall

Believe that if the reader participates in the work, more or less have been used VPN (virtual private network), this is a good thing ah, you can access the company intranet resources, small series is currently very like this technology, of course, use this technology is not only a point of advantage, the advantages of using VPN have the following points:

1. Reduce the cost of the enterprise. When using VPN for remote access, only pay the local telephone fee, save the expensive long-distance telephone charge;

2. Can greatly save the link rent, equipment acquisition and network maintenance costs, reduce the operating costs of enterprises;

3. The ability to integrate the Internet, corporate intranet (Intranet), Enterprise External Network (Extranet), and remote Access to the same external line, without having to manage Internet lanes as before, Long-distance data line, such as many different lines.

4. Use of encryption VPN technology to ensure that data travel through the network security

protocols used to implement a VPN

1. Two-layer protocol {PPTP L2TP l2f}

2. Three layer protocol {GRE IPSec}

Classification of VPN

1.VPDN dial-up VPN PPTP L2TP stand-alone---network (user VPN)

2. Private Line VPN Network---Network (Enterprise network VPN)

In this blog to achieve a small part of the first to implement a three-layer protocol GRE VPN, in the future of the article will also implement IPSec VPN

Configuration tasks:

1. Create an interface

Interface Tunnel number

Tunnel-protocol GRE

Sourec Tunnel Source Address

Destination Tunnel End Address

IP Add this interface address

2. Routing

Dynamic (RIP realizes connectivity between the tunnel and intranet)

The experimental topology is shown in Figure 1-1:

Figure 1-1

Huawei Equipment Implementation

The configuration of step 1:FW1

Fw1

[Fw1]dis CU

#

sysname FW1//Set device name

#

Firewall Packet-filter Enable

Firewall Packet-filter Default Permit

#

Insulate

#

Firewall statistic system Enable

#

RADIUS scheme System

Server-type Extended

#

Domain system

#

Local-user Admin

Password cipher.] @USE =b,53q=^q ' maf4<1!!

Service-type Telnet Terminal

Level 3

Service-type FTP

#

Interface Aux0

Async Mode Flow

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.