請教SecPath 10F 防火牆配置VPN是哪裡出了問題?

火星人 @ 2014-03-04 , reply:0
←手機掃碼閱讀

請教SecPath 10F 防火牆配置VPN是哪裡出了問題?

Quidway]dis cur
#
sysname Quidway
#
dvpn service enable
#
ike local-name vpn.go-star.cn
#
firewall packet-filter enable
firewall packet-filter default permit
#
undo firewall statistic system enable
#
radius scheme system
#
domain system
#
local-user admin
password cipher X/V,H.U^EJ:V1.W&H]T'[!!!
service-type telnet terminal
level 3
service-type ftp
local-user vpnuser
password simple hlbwal
level 3
service-type ppp
#
ike proposal 1
encryption-algorithm 3des-cbc
dh group2
#
ike proposal 10
encryption-algorithm 3des-cbc
dh group2
#
ike peer peer-r3
pre-shared-key 123456
remote-name szsct
remote-address 192.168.10.1
#
ike peer sz1
exchange-mode aggressive
pre-shared-key 123456
remote-name szsct
remote-address 192.168.10.1
#
ike peer sz2
#
ipsec proposal 2
esp authentication-algorithm sha1
esp encryption-algorithm 3des
#
ipsec proposal proposal-r3
esp authentication-algorithm sha1
esp encryption-algorithm 3des
#
ipsec policy-template temp 1
ike-peer peer-r3
#
ipsec policy tor3policy 1 isakmp
security acl 3002
pfs dh-group2
ike-peer sz1
proposal 2
#
ipsec policy tor3policy 10 isakmp
security acl 3000
pfs dh-group2
ike-peer peer-r3
proposal proposal-r3
#
dhcp server ip-pool 1
network 192.168.1.0 mask 255.255.255.0
gateway-list 192.168.1.1
#
acl number 3000
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.26.0 0.0.1.25
5
rule 1 permit ip source 192.168.26.0 0.0.1.255 destination 192.168.1.0 0.0.0.25
5
acl number 3001
rule 0 permit ip
acl number 3002
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.26.0 0.0.1.25
5
acl number 3003
rule 0 deny ip source 192.168.0.0 0.0.255.255 destination 192.168.0.0 0.0.255.2
55
#
interface Dialer1
link-protocol ppp
#
interface Ethernet1/0
mtu 1200
tcp mss 1024
ip address 192.168.1.1 255.255.255.0
#
interface Ethernet2/0
speed 10
duplex half
promiscuous
mtu 1200
tcp mss 1200
ip address 192.168.26.56 255.255.254.0
nat outbound 3001
nat outbound 3000
ipsec policy tor3policy
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet1/0
set priority 85
#
firewall zone untrust
add interface Ethernet2/0
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
l2tp-group 1
undo tunnel authentication
allow l2tp virtual-template 1
#
FTP server enable
#
dhcp server forbidden-ip 192.168.1.1
dhcp server forbidden-ip 192.168.2.254
#
ip route-static 0.0.0.0 0.0.0.0 192.168.26.1 preference 60
#
firewall defend land
firewall defend smurf
firewall defend fraggle
firewall defend winnuke
firewall defend icmp-redirect
firewall defend icmp-unreachable
firewall defend source-route
firewall defend route-record
firewall defend tracert
firewall defend ping-of-death
firewall defend tcp-flag
firewall defend ip-fragment
firewall defend large-icmp
firewall defend teardrop
firewall defend ip-sweep
firewall defend port-scan
firewall defend arp-spoofing
firewall defend arp-flood
firewall defend frag-flood
firewall defend syn-flood enable
firewall defend udp-flood enable
firewall defend icmp-flood enable
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
#
return
《解決方案》

有知道的嗎?急~~~請指教一下.謝謝了!




[火星人 via ] 請教SecPath 10F 防火牆配置VPN是哪裡出了問題?已經有344次圍觀

http://www.coctec.com/docs/service/show-post-35498.html