天天看點

Juniper_ipsec--Cli 基于政策的ipsec

基于政策的 SITE TO SITE IPSEC

基于政策的 IPSec 與基于路由的 ipsec 相比,無需建立 TUNNEL 接口,也不用建立到對端的路由,ipsec 是綁定到政策上的

在 CLI 管理方式中的相關配置

在 SRX210A 上的配置:

set security ike policy aike mode main

set security ike policy aike proposal-set standard

set security ike policy aike pre-shared-key ascii-text juniper

set security ike gateway gw1 ike-policy aike

set security ike gateway gw1 address 192.168.1.239

set security ike gateway gw1 external-interface ge-0/0/0.0

set security ipsec policy ap2 proposal-set standard

set security ipsec vpn vpn1 ike gateway gw1

set security ipsec vpn vpn1 ike ipsec-policy ap2

set security ipsec vpn vpn1 establish-tunnels immediately

set security policies from-zone trust to-zone untrust policy vpn-policy match source-address LanA

set security policies from-zone trust to-zone untrust policy vpn-policy match destination-address LanB

set security policies from-zone trust to-zone untrust policy vpn-policy match application any

set security policies from-zone trust to-zone untrust policy vpn-policy then permit tunnel ipsec-vpn vpn1

set security policies from-zone trust to-zone untrust policy vpn-policy then permit tunnel pair-policy vpn-policy

set security policies from-zone untrust to-zone trust policy vpn-policy match source-address LanB

set security policies from-zone untrust to-zone trust policy vpn-policy match destination-address LanA

set security policies from-zone untrust to-zone trust policy vpn-policy match application any

set security policies from-zone untrust to-zone trust policy vpn-policy then permit tunnel ipsec-vpn vpn1

set security policies from-zone untrust to-zone trust policy vpn-policy then permit tunnel pair-policy vpn-policy

set security zones security-zone trust address-book address LanA 172.16.1.0/24

set security zones security-zone untrust address-book address LanB 172.17.1.0/24

Juniper_ipsec--Cli 基于政策的ipsec

繼續閱讀