网络拓扑如下:
实验目的是把两个私网打通,PC1可以ping通PC2。

【1】、PC的配置:
PC1

PC2

【2】、R1基本信息配置:
< Huawei >sys
[Huawei]undo info-center enable
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.10.254 24
[Huawei-GigabitEthernet0/0/0]undo shut
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 100.1.1.1 30
[Huawei-GigabitEthernet0/0/1]undo shut
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 100.1.1.2
【3】、R2基本信息配置:
< Huawei >sys
[Huawei]undo info-center enable
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.1 30
[Huawei-GigabitEthernet0/0/1]undo shut
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.20.254 24
[Huawei-GigabitEthernet0/0/0]undo shut
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 200.1.1.2
【4】、ISP基本信息配置:
< Huawei >sys
[Huawei]undo info-center enable
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 100.1.1.2 30
[Huawei-GigabitEthernet0/0/0]undo shut
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.2 30
[Huawei-GigabitEthernet0/0/1]undo shut
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]int LoopBack 0
[Huawei-LoopBack0]ip add 2.2.2.2 32
[Huawei-LoopBack0]quit
【5】、IPSec的配置:
(1)、定义需要保护的数据流(也就是定义感兴趣的流量)
R1的配置:
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule 10 permit ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
[Huawei-acl-adv-3000]
R2的配置:
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule 10 permit ip source 192.168.20.0 0.0.0.255 destination 192.168.10.0 0.0.0.255
[Huawei-acl-adv-3000


242

被折叠的 条评论
为什么被折叠?



