air1996
新新人类
帖子
2
精华
0
无忧币 16
积分 10
阅读权限 20
|
发表于:2008-5-7 22:42
标题:IPSEC中 ACL 设置疑问: ~~~ 求助
<上一帖 |
下一帖>
公司总部: 固定ip:222.166.233.87 内网 192.168.10.0/24
两个分部都是adsl拨号上网 总部与分部通过IPSEC 联接
branch_01 : 内网 192.168.20.0/24 branch_02: 内网 192.168.30.0/24
我想问一下,下面配置中, acl number 3000 中 permit 与 acl number 3001 deny 该如何理解
#
sysname zb
#
clock timezone gmt+08:004 add 08:00:00
#
cpu-usage cycle 1min
#
ike local-name center
#
connection-limit disable
connection-limit default action deny
connection-limit default amount upper-limit 50 lower-limit 20
#
web set-package force flash:/http.zip
#
radius scheme system
#
domain system
#
local-user admin
password simple 123456
service-type telnet terminal
level 3
#
ike peer 1
exchange-mode aggressive
pre-shared-key Huawei
id-type name
remote-name branch_01
nat traversal
#
ike peer 2
exchange-mode aggressive
pre-shared-key Huawei
id-type name
remote-name branch_02
nat traversal
#
ipsec proposal 1
#
ipsec policy 1 1 isakmp
security acl 3000
ike-peer 1
proposal sys
#
ipsec policy 1 2 isakmp
security acl 3000
ike-peer 2
proposal 1
#
dhcp server ip-pool 10
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.1
dns-list 222.98.100.88 222.117.114.23
#
acl number 3000
rule 0 permit ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
rule 1 permit ip source 192.168.10.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
rule 2 deny ip
acl number 3001
rule 0 deny ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
rule 1 deny ip source 192.168.10.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
rule 2 permit ip source 192.168.0.0 0.0.255.255
rule 3 deny ip
#
interface Ethernet1/0
ip address 192.168.10.1 255.255.255.0
#
interface Ethernet1/1
#
interface Ethernet1/2
#
interface Ethernet1/3
#
interface Ethernet1/4
#
interface Ethernet2/0
ip address dhcp-alloc
#
interface Ethernet3/0
ip address 222.166.233.87 255.255.255.252
nat outbound 3001
ipsec policy 1
#
interface NULL0
#
FTP server enable
#
ip route-static 0.0.0.0 0.0.0.0 222.166.233.86 preference 60
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
#
return
[ 本帖最后由 air1996 于 2008-5-8 19:54 编辑 ]
|
 千里之外,传递你对震灾人民的关怀 |
|