阿里雲端配置網絡
一、在阿里雲控制檯專有網絡VPC界面找到IPSec鏈接菜單;
ide
二、建立IPsec鏈接,輸入須要填寫的信息;阿里雲
三、配置完成後,能夠看到已經建立了一條IPSec隧道條目,點擊下載對端配置,而後根據對端配置配置對端的設備;spa
四、找到路由表,添加對應的路由條目。3d
思科路由器端orm
一、根據下載的配置,調整爲對應路由器端配置;blog
注意:阿里雲底層ipsec用的strongswan和思科ikev2不兼容,有bug。所以建議採用ikev1,但ikev1建議只寫1條感興趣流。ip
配置樣本:md5
{路由
"LocalSubnet": "10.1.5.0/24",
"RemoteSubnet": "172.16.0.0/24",
"IpsecConfig": {
"IpsecPfs": "group2",
"IpsecEncAlg": "aes",
"IpsecAuthAlg": "sha1",
"IpsecLifetime": 86400
},
"Local": "12.7.10.17",
"Remote": "13.22.15.3",
"IkeConfig": {
"IkeAuthAlg": "md5",
"LocalId": "12.7.10.17",
"IkeEncAlg": "aes",
"IkeVersion": "ikev1",
"IkeMode": "main",
"IkeLifetime": 86400,
"RemoteId": "13.22.15.3",
"Psk": "8r6znxxxxxxyi",
"IkePfs": "group2"
}
}
二、ikev1版配置參考:
crypto isakmp policy 1
encr aes
authentication pre-share
hash md5
group 2
lifetime 86400
crypto isakmp key 8rXXXXX8mii address 13.22.15.3
ip access ex ZX
per ip 10.1.5.0 0.0.0.255 172.16.0.0 0.0.0.255
crypto ipsec transform-set ZX esp-aes esp-sha-hmac
mode tunnel
crypto map ZX 10 ipsec-isakmp
set peer 13.22.15.3
set transform-set ZX
match address ZX
interface G0/1
crypto map ZX
三、配置完成後,使用流量觸發隧道創建。
排錯命令
show crypto isa sa
show crypto ips sa peer 13.22.15.3