Example For Establishing An Ipsec Tunnel Using An Ipsec Tunnel Interface - Huawei AR1200 series Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200 series:
Table of Contents

Advertisement

Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN
5.8.4 Example for Establishing an IPSec Tunnel Using an IPSec
Tunnel Interface
An IPSec tunnel can be established using an IPSec tunnel interface. This method simplifies the
IPSec configuration, reduces costs between devices on the IPSec network, and makes service
application flexible.
Networking Requirements
As shown in
traffic on the IPSec tunnel interface. The IPSec tunnel uses the AH-ESP protocol, 3DES
encryption algorithm, and SHA-1 authentication algorithm.
Figure 5-6 Networking diagram for establishing an IPSec tunnel using the IPSec tunnel interface
RouterA
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
3.
4.
5.
6.
7.
Issue 01 (2012-04-20)
#
ip route-static 10.1.1.0 255.255.255.0 202.138.162.2
#
interface Ethernet1/0/0
ip address 202.138.162.1 255.255.255.0
ipsec policy use1
#
return
Figure
5-6, an IPSec tunnel is established between RouterA and RouterB to protect
Eth1/0/0
202.138.163.1/24
Tunnel0/0/0
192.168.1.1/24
10.1.1.2/24
Network A
Assign IP addresses to interfaces.
Configure static routes to peers.
Configure IKE proposals.
Specify the local IDs and IKE peers required in IKE negotiation.
Configure IPSec proposals.
Configure IPSec profiles and bind the IPSec proposals and IKE peers to the IPSec profiles.
Apply the IPSec profiles to the IPSec tunnel interfaces.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Internet
Tunnel0/0/0
192.168.1.2/24
IPSec Tunnel
5 IPSec Configuration
Eth1/0/0
202.138.162.1/24
RouterB
10.1.2.2/24
Network B
331

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ar3200 series

Table of Contents