***之IPsec(中)

          IPSec 是安全聯網的長期方向。它通過端對端的安全性來提供主動的保護以防止 專用網絡與 Internet 的***。在通信中,只有發送方和接收方纔是唯一必須瞭解 IPSec 保護的計算機。在 Windows XP 和 Windows Server 2003 家族中,IPSec 提供了一種能力,以保護工作組、局域網計算機、域 客戶端和服務器、分支機構(物理上爲遠程機構)、Extranet 以及漫遊客戶端之間的通信。

 

 

IPSec案例:(2

F2:

<F2>dis cu

#

 sysname F2

#

 firewall packet-filter enable

 firewall packet-filter default permit

#

 insulate

#

 firewall statistic system enable

#

radius scheme system

 server-type extended

#

domain system

#

local-user admin

 password cipher .]@USE=B,53Q=^Q`MAF4<1!!

 service-type telnet terminal

 level 3

 service-type ftp

local-user user1

 password simple 123

 service-type telnet

 level 3

#                                         

ike peer f1                               

 pre-shared-key 123456                    

 remote-address 192.168.10.200            

 local-address 192.168.20.200             

#                                         

ipsec proposal tran1                      

#                                         

ipsec policy policy10 20 isakmp           

 security acl 3000                        

 ike-peer f1                              

 proposal tran1                           

#                                         

acl number 3000                           

 rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255

 rule 1 deny ip                           

#                                         

interface Aux0                            

 async mode flow                          

#                                         

interface Ethernet0/0                     

 ip address 192.168.100.42 255.255.255.0  

#                                         

interface Ethernet0/1                     

 ip address 192.168.20.200 255.255.255.0  

 ipsec policy policy10                    

#                                         

interface Ethernet0/2                     

#                                         

interface Ethernet0/3                     

#                                         

interface Ethernet0/4                     

 ip address 192.168.2.1 255.255.255.0     

#                                         

interface Encrypt1/0                      

#                                         

interface NULL0                           

#                                         

firewall zone local                       

 set priority 100                         

#                                         

firewall zone trust                       

 add interface Ethernet0/0                

 add interface Ethernet0/1                

 add interface Ethernet0/4                

 set priority 85                          

#                                         

firewall zone untrust                     

 set priority 5                           

#                                         

firewall zone DMZ                         

 set priority 50                          

#                                         

firewall interzone local trust            

#                                         

firewall interzone local untrust          

#                                         

firewall interzone local DMZ              

#                                         

firewall interzone trust untrust          

#                                         

firewall interzone trust DMZ              

#                                         

firewall interzone DMZ untrust            

#                                         

 FTP server enable                        

#                                         

 ip route-static 0.0.0.0 0.0.0.0 192.168.20.1 preference 60

#                                         

user-interface con 0                      

user-interface aux 0                      

user-interface vty 0 4                    

 authentication-mode scheme               

#                                         

return                                    

F4:

[F4]dis cu

#

 sysname F4

#

 firewall packet-filter enable

 firewall packet-filter default permit

#

 insulate

#

 firewall statistic system enable

#

radius scheme system

 server-type extended

#

domain system

#

local-user admin

 password cipher .]@USE=B,53Q=^Q`MAF4<1!!

 service-type telnet terminal

 level 3

 service-type ftp

local-user user1

 password simple 123

 service-type telnet

 level 3

#                                         

ike peer route                            

 pre-shared-key 123456                    

 remote-address 192.168.10.200            

 local-address 192.168.30.200             

#                                         

ipsec proposal tran1                      

#                                         

ipsec policy policy10 20 isakmp           

 security acl 3000                        

 ike-peer route                           

 proposal tran1                           

#                                         

acl number 3000                           

 rule 0 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.1.0 0.0.0.255

 rule 1 deny ip                           

#                                         

interface Aux0                            

 async mode flow                          

#                                         

interface Ethernet0/0                     

 ip address 192.168.100.44 255.255.255.0  

#                                         

interface Ethernet0/1                     

 ip address 192.168.30.200 255.255.255.0  

 ipsec policy policy10                    

#                                         

interface Ethernet0/2                     

 ip address 192.168.3.1 255.255.255.0     

#                                         

interface Ethernet0/3                     

#                                         

interface Ethernet0/4                     

#                                         

interface Encrypt1/0                      

#                                         

interface NULL0                           

#                                         

firewall zone local                       

 set priority 100                         

#                                         

firewall zone trust                       

 add interface Ethernet0/0                

 add interface Ethernet0/1                

 add interface Ethernet0/2                

 set priority 85                          

#                                         

firewall zone untrust                     

 set priority 5                           

#                                         

firewall zone DMZ                         

 set priority 50                          

#                                         

firewall interzone local trust            

#                                         

firewall interzone local untrust          

#                                         

firewall interzone local DMZ              

#                                         

firewall interzone trust untrust          

#                                         

firewall interzone trust DMZ              

#                                         

firewall interzone DMZ untrust            

#                                         

 FTP server enable                        

#                                         

 ip route-static 0.0.0.0 0.0.0.0 192.168.30.1 preference 60

#                                         

user-interface con 0                      

user-interface aux 0                      

user-interface vty 0 4                    

 authentication-mode scheme               

#                                         

return                                 

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章