R3303-HP HSR6800 Routers Layer 3 - IP Services Configuration Guide

323
[Hub1-Tunnel1] vam client dvpn1hub1
[Hub1-Tunnel1] ip address 10.0.1.1 255.255.255.0
[Hub1-Tunnel1] source gigabitethernet 3/0/1
[Hub1-Tunnel1] ospf network-type p2mp
[Hub1-Tunnel1] ipsec profile vamp
[Hub1-Tunnel1] quit
5. Configure OSPF:
# Configure OSPF for the public network.
[Hub1] ospf 100
[Hub1-ospf-100] area 0
[Hub1-ospf-100-area-0.0.0.0] network 192.168.1.1 0.0.0.255
[Hub1-ospf-100-area-0.0.0.0] quit
# Configure OSPF for the private network.
[Hub1] ospf 200
[Hub1-ospf-200] area 0
[Hub1-ospf-200-area-0.0.0.0] network 10.0.1.1 0.0.0.255
Configuring Hub 2
1. Configure IP addresses for the interfaces. (Details not shown.)
2. Configure the VAM client:
<Hub2> system-view
# Create a VAM client named dvpn1hub2 for VPN 1.
[Hub2] vam client name dvpn1hub2
[Hub2-vam-client-name-dvpn1hub2] vpn 1
# Specify the IP addresses of the VAM servers and set the pre-shared key.
[Hub2-vam-client-name-dvpn1hub2] server primary ip-address 192.168.1.22
[Hub2-vam-client-name-dvpn1hub2] server secondary ip-address 192.168.1.33
[Hub2-vam-client-name-dvpn1hub2] pre-shared-key simple 123
# Create a local user named dvpn1hub2, setting the password as dvpn1hub2.
[Hub2-vam-client-name-dvpn1hub2] user dvpn1hub2 password simple dvpn1hub2
[Hub2-vam-client-name-dvpn1hub2] client enable
[Hub2-vam-client-name-dvpn1hub2] quit
3. Configure the IPsec profile:
# Configure the IPsec transform set.
[Hub2] ipsec transform-set vam
[Hub2-ipsec-transform-set-vam] encapsulation-mode tunnel
[Hub2-ipsec-transform-set-vam] transform esp
[Hub2-ipsec-transform-set-vam] esp encryption-algorithm des
[Hub2-ipsec-transform-set-vam] esp authentication-algorithm sha1
[Hub2-ipsec-transform-set-vam] quit
# Configure the IKE peer.
[Hub2] ike peer vam
[Hub2-ike-peer-vam] pre-shared-key abcde
[Hub2-ike-peer-vam] quit
# Configure the IPsec profile.
[Hub2] ipsec profile vamp