Verifying the configuration – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 863

Advertising
background image

842

6.

Apply the IPsec policy to VLAN-interface 1:

a.

From the navigation tree, select VPN > IPSec.
The IPSec Application page appears.

b.

Click the icon for interface Vlan-interface1.

c.

Select policy map1.

d.

Click Apply.

7.

Configure a static route to Host 1:

a.

From the navigation tree, select Network > IPv4 Routing.

b.

Click Add.

c.

Enter 10.1.1.0 as the destination IP address.

d.

Enter 255.255.255.0 as the mask.

e.

Enter 1.1.1.1 as the next hop.

f.

Click Apply.

Verifying the configuration

After you complete the configuration, a packet destined to subnet 10.1.2.0/24 or 10.1.1.0/24 from AC 1
or AC 2 triggers IKE negotiation.
AC 1 is configured with IKE proposal 10, which uses the authentication algorithm of MD5. AC 2 uses the

default IKE proposal, which uses the default authentication algorithm of SHA. Because AC 2 has no

proposal matching proposal 10 of AC 1, the two devices use the default IKE proposal. The two devices

do not need to have the same ISAKMP SA lifetime, and they will negotiate one instead.

无法显示链接的图像。该文
件可能已被移动、重命名或
删除。请验证该链接是否指
向正确的文件和位置。

Advertising