tailieunhanh - netscreen concepts examples vpns phần 7

(với địa chỉ IP / mặt nạ mạng) hoặc không đánh số (không có địa chỉ IP / mặt nạ mạng) giao diện đường hầm trong một khu vực an ninh. Nếu giao diện đường hầm không đánh số, nó vay mượn địa chỉ IP từ giao diện của các vùng bảo mật mà bạn tạo ra nó. | Chapter 4 Policy-Based VPNs LAN-to-LAN VPNs CLI NetScreen A Interfaces - Security Zones 1. set interface ethernetl zone trust 2. set interface ethernetl ip 24 3. set interface ethernet3 zone untrust 4. set interface ethernet3 dhcp 5. set dhcp client server User 6. set user pmason password Nd4syst4 Addresses 7. set address trust trusted network 24 8. set address untrust mail server 32 Services 9. set service ident protocol tcp src-port 0-65535 dst-port 113-113 10. set group service remote_mail 11. set group service remote_mail add http 12. set group service remote_mail add ftp 13. set group service remote_mail add telnet 14. set group service remote_mail add ident 15. set group service remote_mail add mail 16. set group service remote_mail add pop3 NetScreen Concepts Examples - Volume 4 VPNs 152 Chapter 4 Policy-Based VPNs LAN-to-LAN VPNs VPN 17. Preshared Key set ike gateway to_mail ip aggressive outgoing-interface ethernet3 local-id pmason@ preshare h1p8A24nG5 proposal pre-g2-3des-sha set vpn branch_corp gateway to_mail sec-level compatible or Certificates set ike gateway to_mail ip aggressive outgoing-interface ethernet3 local-id pmason@ proposal rsa-g2-3des-sha set ike gateway to_mail cert peer-ca 16 set ike gateway to_mail cert peer-cert-type x509-sig set vpn branch_corp gateway to_mail sec-level compatible Route 18. set vrouter trust-vr route 0 interface ethernet36 7 Policies 19. set policy top from trust to untrust trusted network mail server remote_mail tunnel vpn branch_corp auth server Local user pmason 20. set policy top from untrust to trust mail server trusted network remote_mail tunnel vpn branch_corp 21. save 6. The number 1 is the CA ID number. To discover the CA s ID number use the following command get pki x509 list ca-cert. 7. The ISP provides the gateway IP address dynamically through DHCP. NetScreen Concepts Examples - Volume 4 VPNs 153 Chapter 4 .

TỪ KHÓA LIÊN QUAN