Ò»¡¢ËµÃ÷

        IOSÖÕ¶Ë¿Éͨ¹ý×ÔÉíЯ´øCISCO¿Í»§¶Ë½øÐÐIPSEC VPN²¦ºÅ½ÓÈë

   

¶þ¡¢×éÍøÐèÇó

        ÈçͼËùʾ£¬Ä³¹«Ë¾ÄÚ²¿ÓÐһ̨OA·þÎñÆ÷£¬ÔÚÍâÒÆ¶¯°ì¹«µÄ¹¤×÷ÈËÔ±ÐèҪͨ¹ýppt   vpn,²¦Èëµ½¹«Ë¾ÄÚÍøÀ´¶ÔÄÚÍø·þOA·þÎñÆ÷½øÐзÃÎÊ.

        l2tp vpnÓë PPTP vpnÅäÖÃÏàͬ£¬ÂÔ¡£

   

Èý¡¢ÍøÂçÍØÆË

          

          

   

ËÄ¡¢ÅäÖÃÒªµã    

       1¡¢»ù±¾ÉÏÍøÅäÖÃ

       2¡¢ÅäÖÃÓû§

       3¡¢NGFWµÄIPSECÅäÖÃ

       4¡¢¶¨Òå²ßÂÔ

       5¡¢ÅäÖÃIOSÖÕ¶Ë

         

Îå¡¢ÅäÖò½Öè    

       ²½Öè1¡¢»ù±¾ÉÏÍøÅäÖà    

             ÅäÖÃÏêϸ¹ý³ÌÇë²ÎÕÕ ¡°Â·ÓÉģʽµäÐ͹¦ÄÜ>>µ¥ÏßÉÏÍø»ò¶àÁ´Â·ÉÏÍø¡°ÅäÖÃÕ½ڡ£

   

       ²½Öè2¡¢ÅäÖÃÓû§    

            1£©¶¨ÒåÓû§

²Ëµ¥£º¶ÔÏóÅäÖÃ--Óû§¶ÔÏ󣺵ã»÷¡°Ð½¨¡±     

            Ìí¼ÓÓû§Ãû£ºtest£¬ÃÜÂë abc123

                image.png    

    2£©¶¨ÒåÓû§×é

            ²Ëµ¥£º¶ÔÏóÅäÖÃ---Óû§·Ö×é¶ÔÏ󣬵ã»÷¡°Ð½¨¡±    

                image.png    

     Ìí¼ÓÓû§×é: apple,Ìí¼ÓtestÓû§µ½¸Ã×é¡£

                image.png

   

²½Öè3¡¢ÅäÖõØÖ·¶ÔÏó

   ÊÖ»ú²¦Èë·ÖÅäµÄipµØÖ·     

image.png    

    ¿É·ÃÎʵķþÎñÆ÷IPµØÖ·   192.168.1.0/24

image.png   

   

 ²½Öè4£ºIPSEC½×¶ÎÉ趨£¨ÎðÓÃweb½çÃæÉϵÄÅäÖÃÏòµ¼£¬ÇëÔÚCLIÃüÁîÐÐÏÂÅäÖã©

   

½×¶Î1

  RG-WALL #config vpn ipsec phase1-interface

  RG-WALL (phase1-interface) #edit iphone

  RG-WALL (iphone) # set type dynamic            //ÉèÖÃÀàÐÍ

  RG-WALL (iphone) # set interface wan1     //ÉèÖýӿÚ

  RG-WALL (iphone) # set dhgrp 2               //ÉèÖÃdh

  RG-WALL (iphone) # set peertype one

  RG-WALL (iphone) # set xauthtype auto

  RG-WALL (iphone) # set mode aggressive       //ÉèÖÃģʽ

  RG-WALL (iphone) # set mode-cfg enable

  RG-WALL (iphone) # set proposal aes256-md5 aes256-sha1    //ÉèÖÃËã·¨

  RG-WALL (iphone) # set peerid iphone                     //ÉèÖÃpeerid

  RG-WALL (iphone) # set authusrgrp apple               //ÉèÖÃÈÏÖ¤Óû§×é

  RG-WALL (iphone) # set ipv4-start-ip 192.168.4.100   //ÉèÖÿͻ§¶ËÆðʼIPµØÖ·

  RG-WALL (iphone) # set ipv4-end-ip 192.168.4.200   //ÉèÖÿͻ§¶Ë½áÊøIPµØÖ·

  RG-WALL (iphone) # set ipv4-netmask 255.255.255.0    //ÉèÖÃ×ÓÍøÑÚÂë

  RG-WALL (iphone) # set dns-mode auto             //Ï·¢·À»ðǽ×ÔÉíϵͳµÄDNS

  RG-WALL (iphone) # set psksecret abc123   //ÉèÖÃÔ¤¹²ÏíÃØÔ¿

  RG-WALL (iphone) # next

  RG-WALL (phase1-interface)#end

   

½×¶Î2

   

RG-WALL #config vpn ipsec phase2-interface

RG-WALL (phase2-interface)#edit iphone

RG-WALL (iphone)#set keylife-type both

RG-WALL (iphone)#set phase1name iphone

RG-WALL (iphone)#set proposal aes256-md5 aes256-sha1

RG-WALL (iphone)#set pfs disable

RG-WALL (iphone)#next

RG-WALL (phase2-interface)#end

   

²½Öè5£ºÅäÖÃIPSEC·À»ðǽ²ßÂÔ

        ²Ëµ¥£º·À»ðǽ--²ßÂÔ--²ßÂÔ£¬µã»÷¡°Ð½¨¡±    

        ²ßÂÔÅäÖÃÈçÏ£º

           

       VPN=>LAN·½Ïò

            image.png    

            Ô´½Ó¿Ú/Çø£ºiphone

            Ô´µØÖ·£ºÑ¡ÔñÇ°Ãæ½¨Á¢µÄiphonepool

            Ä¿µÄ½Ó¿Ú/Çø£ºÑ¡Ôñinternal

            Ä¿µÄµØÖ·£ºserver(192.168.1.0/24)

            ·þÎñ£ºALL

            ÆäËûĬÈϼ´¿É

   

            LAN=>VPN ·½Ïò

            image.png    

            Ô´½Ó¿Ú/Çø£ºÑ¡Ôñinternal

            Ô´µØÖ·£ºserver(192.168.1.0/24)

            Ä¿µÄ½Ó¿Ú/Çø£ºiphone

            Ä¿µÄµØÖ·£ºÑ¡ÔñÇ°Ãæ½¨Á¢µÄiphonepool

            ·þÎñ£ºALL

            ÆäËûĬÈϼ´¿É

     ²½Öè6¡¢ÅäÖ÷ÓÉ

   

image.png    

   

Ä¿±êIP£º¿Í»§¶Ë»ñÈ¡µ½µÄµØÖ·£¨¼´iphonepool£©

É豸£ºÑ¡Ôñiphone½Ó¿Ú

ÆäËûĬÈÏ    

        

   Îå¡¢Öն˽ÓÈë

Ê×ÏÈÕÒµ½ÊÖ»úµÄ¡°ÉèÖá±Í¼±ê¡£µã»÷´ò¿ª£¬ÔÚÉèÖÃÁбíÀïÕÒµ½¡°Í¨Óá±£¬µã»÷½øÈ룬ÈçͼËùʾ

²½ÖèÔĶÁ    

È»ºóÔÚͨÓÃÑ¡ÏîÀïÕÒµ½¡°VPN¡±£¬µã»÷½øÈëÅäÖýçÃæ£¬ÈçͼËùʾ

²½ÖèÔĶÁ    

ÔÚ VPN ÅäÖýçÃæÀµã»÷¡°Ìí¼ÓVPNÅäÖá±£¬ÈçͼËùʾ

×¢£ºÔÚÕâÀï¿ÉÒÔÌí¼Ó¶à¸öVPNÁ¬½ÓÉèÖÃ

²½ÖèÔĶÁ    

ÔÚVPNÏêϸÅäÖýçÃæÖÐ

   

1.Ê×ÏÈÑ¡ÔñIPSECЭÒ飬

2.È»ºóÔÚÃèÊöÖÐËæÒâÊäÈëÒ»¸öÃû³Æ£ºÈçipsec1

3.ÌîдVPN·þÎñÆ÷µØÖ·£¬¼´·À»ðǽwan1¿ÚµØÖ·

4.ÊäÈëÕË»§£¬¼´VPNÁ¬½ÓµÄÓû§Ãû

5.ÊäÈëÃÜÂ룬¼´ÎªVPNÁ¬½ÓµÄÑéÖ¤ÃÜÂë

6.Ⱥ×éÃû³Æ£ºÌîд֮ǰÉèÖõÄpeerid£ºiphone

7.ÃØÔ¿£ºÌîдԤ¹²ÏíÃØÔ¿£ºabc123

8.ÆäËü±£³ÖĬÈÏÉèÖò»±ä£¬×îºóµã»÷ÓÒÉϽǵġ°´æ´¢¡±¡£

ÅäÖÃÍê³ÉÁËVPNÉèÖÃÒԺ󣬵ã»÷VPNÅäÖÃÉÏ·½µÄ VPN ¿ª¹Ø£¬´ò¿ª¼´¿É½øÐÐ VPN Á¬½Ó