set vpn ipsec ike-group IKE-1W proposal 1
set vpn ipsec ike-group IKE-1W proposal 1 encryption 3des
set vpn ipsec ike-group IKE-1W proposal 1 hash sha1
set vpn ipsec ike-group IKE-1W proposal 1 dh-group 2
set vpn ipsec ike-group IKE-1W lifetime 3600
show vpn ipsec ike-group IKE-1W

set vpn ipsec esp-group ESP-1W proposal 1
show vpn ipsec esp-group
set vpn ipsec esp-group ESP-1W proposal 1 encryption 3des
set vpn ipsec esp-group ESP-1W proposal 1 hash sha1
set vpn ipsec esp-group ESP-1W lifetime 1800
show vpn ipsec esp-group ESP-1W

edit vpn ipsec site-to-site peer 111
set authentication mode pre-shared-secret
set authentication pre-shared-secret 111
set default-esp-group ESP-1W
set ike-group IKE-1W
set local-address 111
set tunnel 1 local prefix 111/24
set tunnel 1 remote prefix 192.168.0.0/16
top
commit

show vpn ipsec sa
show vpn ipsec status

set nat source rule 5 destination address '192.168.0.0/16'
set nat source rule 5 'exclude'
set nat source rule 5 outbound-interface 'eth0'
set nat source rule 5 source address '111/24'

set nat source rule 10 outbound-interface 'eth0'
set nat source rule 10 source address '111/24'
set nat source rule 10 translation address 'masquerade'
commit
Copyright © opschina.org 2017 with zzlyzq@gmail.com all right reserved,powered by Gitbook该文件修订时间: 2018-03-19 14:40:08

results matching ""

    No results matching ""