R7:
interface GigabitEthernet0/0/1
ip address 8.8.8.1 255.255.255.0
ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
acl number 3001
rule 1 deny ip source 8.8.8.0 0.0.0.255 destination 9.9.9.0 0.0.0.255 (把需要vpn的网段先在第一次进行过滤掉,路由出口过滤掉后再回内部再匹配vpn 3000的规则出去过行vpn访问北京)
rule 5 permit ip source 8.8.8.0 0.0.0.255
acl number 3000
rule 5 permit ip source 8.8.8.0 0.0.0.255 destination 9.9.9.0 0.0.0.255
ipsec proposal 10
ike proposal 10
ike local-name sz
ike peer sz v1
exchange-mode aggressive
pre-shared-key cipher admin
ike-proposal 10
local-id-type name
remote-name bj
nat traversal
remote-address 3.3.3.3
ipsec policy sz 1 isakmp
security acl 3000
ike-peer sz
proposal 10
出口调用:
interface Gigab
更多【网络-华为路由器即做ipsec vpn又能上互联网】相关视频教程:www.yxfzedu.com