
country CN
state jiangsu
organization huawei
organization-unit info
common-name helloa
#
pki realm testa
ca id ca_root
enrollment-url http://10.137.145.158:8080/certsrv/mscep/mscep.dll ra
entity routera
fingerprint sha1 7a34d94624b1c1bcbf6d763c4a67035d5b578eaf
certificate-check none
#
return
Configuration file of RouterB
#
router id 3.3.3.3
#
acl number 3000
rule 5 permit ip source 2.2.2.1 0 destination 1.1.1.1 0
rule 10 permit ip source 11.1.1.1 0 destination 10.1.1.1 0
#
ipsec proposal routerb
esp authentication-algorithm sha1
esp encryption-algorithm 3des
#
ike proposal 1
encryption-algorithm 3des-cbc
authentication-method rsa-signature
#
ike peer routerb v2
ike-proposal 1
local-address 2.2.2.1
remote-address 1.1.1.1
pki realm testb
#
ipsec policy routerb 1 isakmp
security acl 3000
ike-peer routerb
proposal routerb
#
interface Ethernet2/0/0
ip address 11.1.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 2.2.2.1 255.255.255.0
ipsec policy routerb
#
ospf 1
area 0.0.0.0
network 2.2.2.0 0.0.0.255
network 11.1.1.0 0.0.0.255
#
pki entity routerb
country CN
state jiangsu
organization huawei
organization-unit marketing
common-name hellob
#
pki realm testb
ca id ca_root
enrollment-url http://10.137.145.158:8080/certsrv/mscep/mscep.dll ra
entity routerb
fingerprint sha1 7a34d94624b1c1bcbf6d763c4a67035d5b578eaf
certificate-check none
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
261