R3166-R3206-HP High-End Firewalls VPN Configuration Guide-6PW101
52
• Select ESP as the security protocol.
• Select SHA1 as the ESP authentication algorithm.
• Select DES as the ESP encryption algorithm.
• Click Apply.
# Configure the IKE peer.
• Select VPN > IKE > Peer from the navigation tree and then click Add.
• Type peer as the peer name.
• Select Main as the negotiation mode.
• Select IP Address as the local ID type.
• Type 2.2.3.1 as the IP address of the remote gateway.
• Select Pre-Shared Key and type abcde as the pre-shared key.
• Click Apply.
# Configure an IPsec policy.
• Select VPN > IPSec > Policy from the navigation tree and then click Add.
• Type map1 as the policy name.
• Type 10 as the sequence number.
• Select the IKE peer of peer.
• Select the IPsec proposal of tran1 and click <<.
• Type 3101 as the ACL.
• Cl
ick Apply.
# Apply the IPsec policy.
• Select VPN > IPSec > IPSec Application from the navigation tree, and then click the icon of
interface GigabitEthernet 0/1.
• Select the policy of map1.
• Click Apply.
2.
Configure Firewall B
# Define an ACL to permit traffic from subnet 10.1.2.0/24 to subnet 10.1.1.0/24.
• Select Firewall > ACL from the navigation tree, and then click Add.
• Type 3101 as the ACL number.
• Select the match order of Config.
• Click Apply.
• From the ACL list, select ACL 3101 and click the corresponding icon. Then, click Add to enter the
ACL rule configuration page.
• Select Permit from the Operation drop-down box.
• Select the Source IP Address check box and type 10.1.2.0 and 0.0.0.255 respectively in the
following text boxes.
• Select the Destination IP Address check box and type 10.1.1.0 and 0.0.0.255 respectively in the
following text boxes.
• Click Apply.
• From the rule list of ACL 3101, click Add.