云计算防火墙IPsec实验

云计算防火墙IPsec实验:
拓扑图如下:
在这里插入图片描述

配置命令如下:

AR1:
system-view
sysname ISP
interface g0/0/1
ip address 6.6.6.2 29
interface g0/0/2
ip address 16.16.16.2 29
interface loopback 100
ip address 99.99.99.99 32
FW3:
system-view
sysname CQ
interface g1/0/0
ip address 6.6.6.1 29
interface g1/0/1
ip address 192.168.6.1 24
interface g0/0/0
service-manage all permit
ip route-static 0.0.0.0 0.0.0.0 6.6.6.2

nat-policy
rule name inside_no_nat
source-zone trust
destination-zone unreust
source-address 192.168.6.0 24
destination-address 192.168.16.0 24
action no-nat

interface tunnel0
ip address 10.10.10.1 30
tunnel-protocol gre
source 6.6.6.1
destination 16.16.16.1

ospf
area 0
network 192.168.6.0 0.0.0.255
network 10.10.10.0 0.0.0.3
ip route-static 192.168.16.0 255.255.255.0 tunnel0
firewall zone name untrust
add int tunnel0
FW5:
system-view
sysname SH
interface g1/0/0
ip address 16.16.16.1 29
interface g1/0/1
ip address 192.168.16.1 24
interface g0/0/0
ip address 192.168.0.2 24
service-manage all permit
ip route-static 0.0.0.0 0.0.0.0 16.16.16.2

nat-policy
rule name to_internet
source-zone trust
destination-zone untrust
action source-nat easy-ip

security-policy
rule name to_internet
source-zone trust
destination-zone untrust
action permit

nat-policy
rule name inside_no_nat
source-zone trust
destination-zone untrust
source-address 192.168.16.0 24
destination-address 192.168.6.0 24
action no-nat

interface tunnel0
ip address 10.10.10.2 30
tunnel-protocol gre
source 16.16.16.1
destination 6.6.6.1

ospf
area 0
network 192.168.16.0 0.0.0.255
network 10.10.10.0 0.0.0.3
ip route-static 192.168.6.0 255.255.255.0 tunnel0
firewall zone name untrust
add int tunnel0

PC机配置如下:
在这里插入图片描述
在这里插入图片描述
菜菜的代码,希望能够帮助到你哟!

猜你喜欢

转载自blog.csdn.net/Sconnie/article/details/113856910