Ipsec configuration examples, Network requirements, Configuring device a – H3C Technologies H3C SecPath F1000-E User Manual

Page 205

Advertising
background image

193

IPsec configuration examples

Manual mode IPsec tunnel for IPv4 packets configuration
example in the Web interface

Network requirements

As shown in

Figure 120

, configure an IPsec tunnel between Device A and Device B to protect traffic

between subnet 10.1.1.0/24 and subnet 10.1.2.0/24. Configure the tunnel to use the security protocol

ESP, the encryption algorithm DES, and the authentication algorithm SHA-1. Enable IPsec RRI on Device
A and specify the next hop as 2.2.2.2.

Figure 120 Network diagram

Configuring Device A

# Assign IP addresses for the interfaces and then add them to target zones. (Details not shown.)
# Define ACL 3101 to permit packets from subnet 10.1.1.0/24 to subnet 10.1.2.0/24.
Select Firewall > ACL from the navigation tree, click Add, and then perform the configurations shown

in

Figure 121

.

Figure 121 Create ACL 3101

Enter 3101 as the ACL number.

Select the match order of Config.

Click Apply.

Advertising