dns
2.2.2.2
dns 2.2.2.3
secondary
ip-pool
pooltest
wins
3.3.3.2
wins 3.3.3.3
secondary
#
interface
Ethernet1/0/0
ip address 60.1.2.1
255.255.255.0
ipsec policy policy1
#
ip route-static 10.1.1.0 255.255.255.0 60.1.2.2
#
return
5.8.6 Example for Establishing an SA Using Efficient VPN in
Network Mode
This topic describes an example for establishing an SA using Efficient VPN in network mode
in the actual networking.
Networking Requirements
As shown in
, an IPSec tunnel is established between RouterA and RouterB to protect
data flows that are transmitted between the subnet of PC A (10.1.1.0/24) and subnet of PC B
(10.1.2.0/24) and match the ACL. In network mode, the remote device does not apply for or an
IP address, and NAT and PAT are disabled on the remote device.
Figure 5-8
Networking for Establishing an SA Using Efficient VPN in Network Mode
Server
RouterA
Eth1/0/0
100.1.2.1/24
Eth1/0/0.1
99.1.1.1/24
Eth1/0/0.1
99.1.2.1/24
Remote
RouterB
PC A
PC B
10.1.1.2/24
10.1.2.2/24
Eth1/0/0
100.1.1.1/24
IPSec Tunnel
Internet
Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN
5 IPSec Configuration
Issue 01 (2012-04-20)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
340