data:image/s3,"s3://crabby-images/a14c8/a14c89950358099245c4ab250fb82bd7beb06ffd" alt=""
如图,
北京已通过MSR做为出口网关连接至互联网 (MSR810 基础配置可见视频https://www.bilibili.com/video/BV1C14y1N7zK/?spm_id_from=333.999.0.0)
青岛已通过OPNSense做为出口网关连接至互联网
现通过IPSEC VPN实现北京 10.1.1.0/24 内网 与 青岛 10.0.0.0/24 内网互通
…………………………………………………………………….
一、OPNsense配置
1、 VPN —> IPSEC —> Tunnel Setting[legacy]
点击右侧 ” + ” 添加第一阶段策略
data:image/s3,"s3://crabby-images/d8e13/d8e13147a8d956163fd98b7eb5856452a9339ed6" alt=""
…………………………………………………………………….
data:image/s3,"s3://crabby-images/80749/80749537e03c6135441dbc3a1167a8f34d8a5b1a" alt=""
…………………………………………………………………….
data:image/s3,"s3://crabby-images/ac3e0/ac3e0978e96a7b96e5f2db0560bf4bb905c017c6" alt=""
…………………………………………………………………….
2、点击右侧 第一阶段策略条目 右侧 ” + ” 添加第二阶段策略
data:image/s3,"s3://crabby-images/4d6a7/4d6a7932faf198d71e5131682e26a1a54028156f" alt=""
…………………………………………………………………….
data:image/s3,"s3://crabby-images/8b698/8b698528b35114a12232149cf33e400b07d09dbc" alt=""
…………………………………………………………………….
3、勾选启用阶段2策略,应用更改
data:image/s3,"s3://crabby-images/56552/565529337fa7b2875a13e058e8861fe455522691" alt=""
…………………………………………………………………….
4、防火墙策略放行IPSEC in 方向流量(点击 “+” 号添加策略)
data:image/s3,"s3://crabby-images/5d147/5d147a713662e751d9c3b79b7a3b09052e31c034" alt=""
…………………………………………………………………….
5、新建策略规则默认放行IPSEC in方向所有流量,直接保存/应用即可
data:image/s3,"s3://crabby-images/407e3/407e3fffd268e1925d8ca14c1d1125358498f7b5" alt=""
…………………………………………………………………….
二、H3C MSR配置
1、配置第一阶段IKE 密匙链
#
ike keychain k1
pre-shared-key address 0.0.0.0 0.0.0.0 key simple 123456
#
data:image/s3,"s3://crabby-images/18caa/18caae2dc58d6932cd2f4c025b1f5e1b691e52ec" alt=""
…………………………………………………………………….
2、创建第一阶段IKE提议
#
ike proposal 10
authentication-method pre-share
authentication-algorithm md5
encryption-algorithm 3des-cbc
dh group2
#
data:image/s3,"s3://crabby-images/0f5e3/0f5e3a661640da11104e755298150c3941debcf8" alt=""
…………………………………………………………………….
3、配置 IKE profile
#
ike profile ikepro
keychain k1
exchange-mode aggressive
local-identity fqdn beijing
match remote identity domain v4.rsrc.ink
match remote identity fqdn qingdao
match local address Dialer10
proposal 10
#
data:image/s3,"s3://crabby-images/5f652/5f6523c41957f4a7ecd82f6a185723eb083deb2c" alt=""
…………………………………………………………………….
4、变更ACL,rule 10 拒绝 10.1.1.0/24至 10.0.0.0/24 流量地址转换 IPSEC流量进行NAT豁免
acl 3001 为 北京内网用户访问互联网地址转换
#
acl number 3001 name s_nat
rule 10 deny ip source 10.1.1.0 0.0.0.255 destination 10.0.0.0 0.0.0.255
rule 20 permit ip
#
data:image/s3,"s3://crabby-images/a01b4/a01b49186d9bf0fc004240409c0e30dbaa9901ce" alt=""
…………………………………………………………………….
5、配置感兴趣流
#
acl number 3021 name ipsec
rule 10 permit ip source 10.1.1.0 0.0.0.255 destination 10.0.0.0 0.0.0.255 logging
#
data:image/s3,"s3://crabby-images/ce01c/ce01c99706156b279a704e028cdd9b32774b9de5" alt=""
…………………………………………………………………….
6、配置转换集
#
ipsec transform-set its
encapsulation-mode tunnel
protocol esp
esp encryption-algorithm aes-cbc-128
esp authentication-algorithm sha1
pfs dh-group2
#
data:image/s3,"s3://crabby-images/4360c/4360c76a674aab67e30e1c2d1b40ce32b8d00279" alt=""
…………………………………………………………………….
7、创建ipsec 策略
#
ipsec policy ip 10 isakmp
transform-set its
security acl 3021
remote-address v4.rsrc.ink
ike-profile ikepro
#
data:image/s3,"s3://crabby-images/60d41/60d41487bb969e947619b1726c78385a18565284" alt=""
…………………………………………………………………….
8、出接口调用IPSEC策略
#
interface Dialer10
ipsec apply policy ip
#
data:image/s3,"s3://crabby-images/9f43b/9f43b6fd0b8aec8a62cd9b98f3e004299b43abc1" alt=""
…………………………………………………………………….
三、验证测试
1、opnSense 查看IPSEC 状态
data:image/s3,"s3://crabby-images/85fd6/85fd612408f081e0d5740b6ee5db52a1ac73f502" alt=""
…………………………………………………………………….
2、opnSense 查看安全关联数据库
data:image/s3,"s3://crabby-images/aa261/aa2610c94a402ec689bc22fa0cdbaf3c86801a51" alt=""
…………………………………………………………………….
3、opnSense 查看这全策略数据库
data:image/s3,"s3://crabby-images/701c0/701c068871ef00e9a056c3e17b437abd18394bae" alt=""
…………………………………………………………………….
4、H3C MSR查看 IKE SA
data:image/s3,"s3://crabby-images/7cc37/7cc37b49be86b09e8c86d81de09631fe5893125a" alt=""
…………………………………………………………………….
5、H3C MSR 查看IPSEC SA
data:image/s3,"s3://crabby-images/580ab/580abdca3c2fca0d6e64a6cf3dfabb34d6fa9c15" alt=""
…………………………………………………………………….
6、H3C MSR查看 IPSEC 隧道状态
data:image/s3,"s3://crabby-images/8d2ed/8d2eddec52c183a5ee17b15a88f1ab8280437b65" alt=""
…………………………………………………………………….
7、青岛PC客户端 ping tracert 北京 客户端
data:image/s3,"s3://crabby-images/57758/57758e8b0057068c2ec9b12468cf855e9c227f9e" alt=""
…………………………………………………………………….
8、北京MSR ping tracert 青岛客户端
data:image/s3,"s3://crabby-images/110c7/110c786463e203b2d252eab048fabdad39508b1e" alt=""
…………………………………………………………………….