2023年VPN实验报告范文_第1页
2023年VPN实验报告范文_第2页
2023年VPN实验报告范文_第3页
2023年VPN实验报告范文_第4页
2023年VPN实验报告范文_第5页
已阅读5页,还剩22页未读, 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

VPN实验报告

L拓扑图

图i-i

2.实验环境

2.1实验规定

如图1-1,RouterAR1为公司总部出口路由器,RouterAR3为分支机构出

口路由器。公司希望对分支与总部之间互相访问的流量进行安全保护,Router

AR2和RouterAR3RouterARl之间运营ospf协议模拟外网环境(不宣告内

网接口,内网访问外网采用NAT转换),PC1及PC2之间通信通过greover

ipsecvpn及ipsecovergrevpn来进行互访。

2.2网络规划

2.2.1GreoverIpsec规划

内网网段10.0.0.0/24

Center内网网关g0/0/o10.0.0.254/24

出口地址go/0/112.12.12.1/24

PCl地址10.0.0.1/24

回环口地址1.1.1.32

GreTunnel0/0/3192.168.2.1/24

内网网段10.1.1.V24

Branch1

内网网关gOA)/i10.1.1.254/24

出口地址gOM23.23.23.^24

PC2地址10.1.1.1/24

回环口地址3.3.3.豹2

GreTunne10/0/0192.168.2.2/24

gO/O/O12.12.12.^24

ISP

G0/0/123.23.23224

回环口地址2.2.2.2/32

2.2.21psecoverGre规戈lj

内网网段10.0.0.0/24

Center内网网关go/o由10.0.0.25412A

出口地址go/0/112.12.12.3/24

PC1地址10.0.0.V24

回环口地址1.1.1.1B2

GreTunnel0/0/0192.168.2.1/24

1psecTunnel0/0/1192.168.3.1/24

内网网段10.1.1.]/24

Branch1

内网网关g0/0/110.1.1.254/24

出口地址gO/3/D23.23.23.3/24

PC2地址10.1.1.1/24

回环口地址3.3.3.3/32

GreTunnel0/0/0192.168.2.2/24

IpsecTunnel0/0/1192.168.3.2/24

go/0/012.12.12.2/24

ISP

G0/0/123.23.23.2/24

回环口地址2.2.2232

3.GreoverIpsec

3.1实验配置

3.1.1配置思绪

1.配置物理接口的IP地址及ospf配置,保证ISP路由可达。

2.配置IPSec安全建议,定义IPSec的保护方法。

3.配置IKE对等体,定义对等体间IKE协商时的属性。

4.配置安全框架,并引用安全建议和IKE对等体。

5.配置GRETunnel接口,在Tunnel接口上应用安全框架,

6.配置Tunne1接口的转发路由。

7.配置nat

3.1.2配置文档

Center配置为例:

[[Huawei]discurrent-configuration

[V200RO03C00]

#

snmp-agent1ocal-engineid800007DB00

snmp—agent

c1ocktimezoneChina-Standard-Timeminus08:00:00

8ZX-oc(0—saeLUqa!JO6Je-uoi^dAjous

乙[esodojd0x!

#

g乙T-saeuiq4TJobye-uoT^dAjousdsa

9GZ-Zeqsuiq;TJoBje-uoT;BOT;USq】nedse

Iyesodo□asdj

#

dT4Tuijedqejnj

000CJ^quinume

*

QLQJO4saJ08p[oqsa式qaebesn-ndo4es

#

0pToepiJ9TJjeo[eqo16-□euBTM

#

mJBTeoeui-feba771dojp

dyz,sBedTBaJOd/:qsp।jpeojjeA^es-yeooT[e】j:od

ikepeerar3v2

pre-shared-keycipher%$%$u'Vj70TpBO@>_K8vu710,.2n%$%$

ike-proposal2

#

ipsecprofile123

ike-peerar3

proposal1

#

aaa

authentication-schemedefault

authorization-schemedefault

accounting-schemedefau1t

domaindefault

domaindefau1t_admin

1ocal-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0'8bmE3U

w}%$%$

1oca1-useradminservice-typehttp

*

firewa11zoneLocal

0/0/013usrmqag4TqeeoejJa4uI

#

L/0/O4eujeq4aeoejje4ui

#

9/0/01aujeq43eoejJe;ui

*

S/0/04eujeq4aeoejje^UT

0/0/019UJa叫HmoeJ式8uT

€/0/019ujeq^asoejmo”!

#

l/o/oaas3叫口eoejja^uT

#

1/0/04auJaqiaeoeJJ94uT

*

O/O/Oamuuaq^3ooejja4UT

gTA4TJoTJd

ipaddress10.0.0.254255.255.255.0

#

interfaceGigabitEthernet0/0/1

iPaddress12.12.12.1255.255.255.0

natoutbound3000

#

interfaceNULL0

#

interfaceLoopBack1

ipaddress1.1.1.1255.255.255.255

#

interfaceTunne10/0/0

ipaddress2.2.2.2255.255.255.0

tunnel-protocolgre

source12.12.12.1

destination23.23.23.3

ipsecprofile123

ospf1router-id1.1.1.1

[00DC00H002A]

uoTq.ejn6Tjuo□-q.uajjn□sxp[jeMenn]

[T9MenH]

[TOMenH]

usrnq.3J

#

□BU©TAV

#

0Z9iA4Aeoegje4u1-Jesn

。0XiA90BjJa;ui-JOSH

pJoMSSPd9pOUI-UOT4POT4uaq4up

0uooaoRjj9iUT-jesn

#

0/0/0Iauun10•qg乙•qq乙•GG40'T'T'0I□1s—a4noJdT

S*Sl*3I*ZT0'O'O^O0*0*0*0os-e4nojdT

*

qq4,0,o'00*21•乙1•乙1^JOM4eu

0*0,0*0e9Je

snmp—agentlocal-engineid800007DB00

snmp-agent

clocktimezoneChina—Standard-Timeminus08:00:00

#

porta1local-serverloadflash:/portalPage.zip

*

dropillega1-macalarm

#

wlanac-globa1carrieridotheracid0

#

setcpu-usagethresho1d80restore75

#

aclnumber3000

rule5permitip

#

ipsecproposal1

esPauthentication-algorithmsha2-256

espencryption-a1gorithmaes-128

ikeproposa12

encryption-algorithmaes-cbc-128

#

ikepeerar3v2

pre-shared-keycipher%$%$u'Vj70TpB0@>_K8vu710z.2n%$%$

ike-proposa12

#

ipsecprofi1e123

ike-peerar3

proposal1

#

aaa

authentication-schemedefauIt

authorization—schemedefault

accounting-schemedefault

domaindefault

domaindefau1t_admin

loca1-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0'8bm

E3Uw}%$%$

1oca1-useradminservice-typehttp

#

firewa11zoneLoca1

priority15

*

interfaceGigabitEthernet0/0/0

ipaddress10.0.0.254255.255.255.0

#

interfaceGigabitEthernet0/0/1

ipaddress12.12.12.1255.255.255.0

natoutbound3000

#

interfaceNULL0

#

interfaceLoopBackl

ipaddress1.1.1.1255.255.255.255

#

interfaceTunnel0/0/0

iPaddress2.2.2.2255.255.255.0

tunne1-protocolgre

source12.12.12.1

destination23.23.23.3

ipsecprofile123

#

ospf1router-id1.1.1.1

area0.0.0.0

network12.12.12.00.0.0.255

#

iproute-static0.0.0.00.0.0.012.12.12.2

iproute-static10.1.1.0255.255.255.0TunnelO/0/0

#

user-interfacecon0

authentication-modepassword

user-interfacevty04

user—interfacevty1620

*

w1anac

return

ISP酉己置

[Huawei]discurrent-configuration

[V200R003C00]

#

snmp-agentlocal-engineid800007DB00

snmp-agent

*

c1ocktimezoneChina-Standard-Timeminus08:00:00

#

portallocal-server1oadflash:/portaIpage.zip

#

dr0pi1lega1-macalarm

#

w1anac-globa1carrieridotheracid0

#

setcpu-usagethresho1d80restore75

#

aaa

authentication-schemedefault

authorization-schemedefault

accounting-schemedefau1t

domaindefault

domaindefault_admin

1oca1—useradminpasswordcipher%$%$K8m.Nt84DZ)e#

<0'8bmE3Uw}%$%$

loca1-useradminservice-typehttp

#

firewa11zoneLocal

priority15

#

interfaceGigabitEthernetO/O/0

ipaddress12.12.12.2255.255.255.0

#

interfaceGigabitEthernet0/0/l

ipaddress23.23.23.2255.255.255.0

#

interfaceNULL0

#

interfaceL0opBack1

ipaddress2.2.2.2255.255.255.255

#

ospf1router-id2.2.2.2

area0.0.0.0

network12.12.12.00.0.0.255

network23.23.23.00.0.0.255

#

user-interfacecon0

authentication-modepassword

user-interfacevty04

user-interfacevty1620

*

wlanac

3.2测试结果

POping23.23.23.3

Ping23.23.23.3:32databytes.PressCtrl_Ctobreak

Requesttimeout!

From23.23.23.3:bytes=32seq=2ttl=253time=16ms

From23.23.23.3:bytes=32seq=3ttl=253time=16ms

From23.23.23.3:bytes=32seq=4ttl=253time=31ms

From23.23.23.3:bytes=32seq=5ttl=253time=15ms

23.23.23.3pingstatistics

5packet(s)transmitted

4packet(s)received

20.00%packetloss

round-tripmin/avg/max=0/19/31ms

POping10.1.1.1

Ping10.1.1.1:32databytestPressCtrl_Ctobreak.

Requesttimeout!

From10.1.1.1:bytes=32seq=2ttl=126time=15ms

From10.1.1.1:bytes=32seq=3ttl=126time=15ms

From10.1.1.1:bytes=32seq=4ttl=126time=16ms

From10.1.1.1:bytes=32seq=5tt1=126time=16ms

4.lpsecoverGre

4.1实验配置

4.1.1配置思绪

1.配置物理接口的IP地址及ospf配置,保证ISP路由可达。

2.配置IPSec安全建议,定义IPSec的保护方法。

3.配置IKE对等体,定义对等体间IKE协商时的属性。

4.配置安全框架,并引用安全建议和IKE对等体。

5.配置GRETunne1接口。

6.配置IPSecTunne1接口,将IPSecTunne1的源接口配置为GRE

Tunnel接口,在IPSecTunnel接口上应用安全框架,使接口具有IPSec

的保护功能。

7.配置Tunnel接口的转发路由。

8.配置nat

4.1.2配置文档

Center配置为例:

[Huawei]discurrent-configuration

[V200R003C00]

#

snmp-agentlocal-engineid800007DBOO

snmp-agent

#

clocktimezoneChina-Standard-Timeminus08:00:00

#

portai1ocal-serverloadflash:/porta1page.zip

#

dropi11egal-macalarm

#

wlanac-giobalcarrieridotheracid0

#

setcpu-usagethreshoId80restore75

*

ac1number2023

rule5permit

#

iPsecproposal1

espauthentication-algorithmsha2-256

espencryption-algorithmaes-128

#

ikeproposa12

encryption-algorithmaes-cbc-128

#

ikepeerar3v1

Pre-shared-keycipher%$%$□'Vj70TpB0@>_K8vu71Oz.2n%$%$

ike-proposal2

#

ipsecprofile123

ike-peerar3

proposal1

*

aaa

authentication-schemedefault

authorization-schemedefault

accounting-schemedefau1t

domaindefault

domaindefault_admin

loca1—useradminpasswordcipher%$%$K8m.Nt84Dz}e#<0'8bm

E3Uw}%$%$

loca1-useradminservice-typehttp

#

firewa11zoneLocal

priority15

#

interfaceGigabitEthernet0/0/0

ipaddress10.0.0.254255.255.255.0

#

interfaceGigabitEthernetO/0/I

ipaddress12.12.12.1255.255.255.0

natoutbound2023

#

I*T'T'IpT—3”。式TJds。

£乙1!J。4doesdT

""891*Z6Tuoiieur4Sap

0/0/0TQuuniGojnos

ossdT{ooo4ojd-yeuunq.

,,,

0・GSZ'SSZ・qq乙TC89T36ISSajpppdT

T/O/OT9uunlaoejJaiui

#

€・£1・£乙・£Zuoi;euT^sep

I*7,I*2T*31enznos

aj6yooo]ojd-feuun]

0'GCZ'GGZ'GG乙I*Z-89T-Z6IssejppedT

0/0/OT9uunj,a□Bjja

#

SGZ・GS乙・GG乙・SG乙T'T-T-IssaJpppdT

TMOBgd00rl9ORJJ34UT

#

0mnN30BJJ94UT

area0.0.0.0

network12.12.12.00.0.0.255

#

iproute-static0.0.0.00.0.0.012.12.12.2

iproute-static10.1.1.0255.255.255.0TunnelO/0/0

#

user-interfacecon0

authentication-modepassword

user-interfacevty04

user-interfacevty1620

#

wlanac

#

Return

ISP配置:

[Huawei]discurrent_configuration

[V20ORO03C00]

#

snmp-agent10cal-engineid800007DB00

snmp-agent

#

clocktimezoneChina-Standard-Timeminus08:00:00

*

porta11ocal-server1oadflash:/portalpage.zip

*

dropi1legal-macalarm

#

wlanac-globa1carrieridotheracid0

#

setcpu-usagethresho1d80restore75

#

aaa

authentication-schemedefault

authorization-schemedefault

accounting-schemedefault

SGZ'GG乙.qq乙・GGZZ•乙•乙•乙sssjppedx

-[XoegcJooqaoejje4ui

#

0r1rlf)N㊀oeJ工㊀”I

#

0PS乙・GSZ・GSZ乙•£乙•£1•£?ssajppedx

T/0/049UJaq[且]jqpgTOeoejJ。4UT

#

0・GGZ・GG乙’GSO3,21*31*2TssaJppBdi

0/0/04as&qi且1Tqe6ipeoejje4uT

#

GTA;TJOTjd

TP□oqeuozTT^^eJTj

甘

dq.q.qedAq._eoTAjesuTuipeJ9sn_(p□oy

$%$%{Mfi£3

wq8、0>#o{ZQ081N,UI8M$%$%JaqdioPJOMSsedujuipBSn-xeooT

uTiupp_4InejepuTBuiop

4Tnej9pUTPUIOP

ospf1router-id2.2.2.2

area0.0.0.0

network12.12.12.00.0.0.255

netwo

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论