USG ipsec VPN 配置
Jul142018
acl number 3000
rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 172.16.1.0 0.0.0.255
#
ike proposal 10
encryption-algorithm 3des-cbc
dh group1
#
ike peer outside
pre-shared-key 123456
ike-proposal 10
remote-address 1.1.1.1
#
ipsec proposal oklab
esp authentication-algorithm md5
esp encryption-algorithm 3des
#
ipsec policy oklabmap 10 isakmp
security acl 3000
ike-peer outside
proposal oklab
local-address 2.2.2.2
interface gigabitEthernet0/0/0
ipsec policy oklabmap
nat-policy interzone trust untrust outbound
policy 0
action no-nat
policy source 192.168.1.0 0.0.0.255
policy destination 172.16.1.0 0.0.0.255