基于政策的 SITE TO SITE IPSEC
基于政策的 IPSec 與基于路由的 ipsec 相比,無需建立 TUNNEL 接口,也不用建立到對端的路由,ipsec 是綁定到政策上的
在 CLI 管理方式中的相關配置
在 SRX210A 上的配置:
set security ike policy aike mode main
set security ike policy aike proposal-set standard
set security ike policy aike pre-shared-key ascii-text juniper
set security ike gateway gw1 ike-policy aike
set security ike gateway gw1 address 192.168.1.239
set security ike gateway gw1 external-interface ge-0/0/0.0
set security ipsec policy ap2 proposal-set standard
set security ipsec vpn vpn1 ike gateway gw1
set security ipsec vpn vpn1 ike ipsec-policy ap2
set security ipsec vpn vpn1 establish-tunnels immediately
set security policies from-zone trust to-zone untrust policy vpn-policy match source-address LanA
set security policies from-zone trust to-zone untrust policy vpn-policy match destination-address LanB
set security policies from-zone trust to-zone untrust policy vpn-policy match application any
set security policies from-zone trust to-zone untrust policy vpn-policy then permit tunnel ipsec-vpn vpn1
set security policies from-zone trust to-zone untrust policy vpn-policy then permit tunnel pair-policy vpn-policy
set security policies from-zone untrust to-zone trust policy vpn-policy match source-address LanB
set security policies from-zone untrust to-zone trust policy vpn-policy match destination-address LanA
set security policies from-zone untrust to-zone trust policy vpn-policy match application any
set security policies from-zone untrust to-zone trust policy vpn-policy then permit tunnel ipsec-vpn vpn1
set security policies from-zone untrust to-zone trust policy vpn-policy then permit tunnel pair-policy vpn-policy
set security zones security-zone trust address-book address LanA 172.16.1.0/24
set security zones security-zone untrust address-book address LanB 172.17.1.0/24
