发布时间: 2024-5-14 文章作者: myluzh 分类名称: RouterOS 朗读文章
# home1_ros配置 /ip/ipsec/proposal add name="proposal1" auth-algorithms=sha256 enc-algorithms=aes-256-cbc lifetime=30m pfs-group=modp2048 # home2_ros配置 /ip/ipsec/proposal add name="proposal1" auth-algorithms=sha256 enc-algorithms=aes-256-cbc lifetime=30m pfs-group=modp20482、两台设备新建相同的配置文件(Profiles)
# home1_ros配置 /ip/ipsec/profile add name="profile1" hash-algorithm=sha256 enc-algorithm=aes-256 dh-group=modp2048 lifetime=1d proposal-check=obey nat-traversal=yes dpd-interval=2m dpd-maximum-failures=5 # home2_ros配置 /ip/ipsec/profile add name="profile1" hash-algorithm=sha256 enc-algorithm=aes-256 dh-group=modp2048 lifetime=1d proposal-check=obey nat-traversal=yes dpd-interval=2m dpd-maximum-failures=53、两台设备分别配置对端(Peer)
# home1_ros配置 /ip/ipsec/peer add name="home2" address=home_2.itho.cn profile=profile1 exchange-mode=ike2 send-initial-contact=yes # home2_ros配置 /ip/ipsec/peer add name="home1" address=home_1.itho.cn profile=profile1 exchange-mode=ike2 send-initial-contact=yes3、两台设备分别配置预共享密钥(Identities)
# home1_ros配置,peer选择对端home2 /ip/ipsec/identity peer=home2 auth-method=pre-shared-key secret="testtest01!" generate-policy=no # home2_ros配置,peer选择对端home1 /ip/ipsec/identity peer=home1 auth-method=pre-shared-key secret="testtest01!" generate-policy=no5、查看ipsec的连接状态是否为established
[admin@HomeROS_1] > /ip/ipsec/active-peers print Flags: R - RESPONDER Columns: ID, STATE, UPTIME, PH2-TOTAL, REMOTE-ADDRESS # ID STATE UPTIME PH2-TOTAL REMOTE-ADDRESS 0 R 125.107.234.139 established 5m40s 1 125.107.234.1396、配置感兴趣流量(Policies)
# home1_ros配置 /ip/ipsec/policy add peer=home2 tunnel=yes src-address=172.16.0.0/16 dst-address=172.17.0.0/16 protocol=all action=encrypt level=require ipsec-protocols=esp proposal=proposal1 # home2_ros配置 /ip/ipsec/policy add peer=home1 tunnel=yes src-address=172.17.0.0/16 dst-address=172.16.0.0/16 protocol=all action=encrypt level=require ipsec-protocols=esp proposal=proposal17、配置NAT规则
# home1_ros配置 /ip/firewall/nat add place-before=0 comment=ipsec chain=srcnat action=accept src-address=172.16.0.0/16 dst-address=172.17.0.0/16 # home2_ros配置 /ip/firewall/nat add place-before=0 comment=ipsec chain=srcnat action=accept src-address=172.17.0.0/16 dst-address=172.16.0.0/168、测试内网ipsec是否互通
# home1_ros ping对端172.17.1.1 测试 [admin@HomeROS_1] > ping src-address=172.16.1.1 172.17.1.1 SEQ HOST SIZE TTL TIME STATUS 0 172.17.1.1 56 64 4ms320us # home2_ros ping对端172.16.1.1 测试 [admin@HomeROS_2] > ping src-address=172.17.1.1 172.16.1.1 SEQ HOST SIZE TTL TIME STATUS 0 172.16.1.1 56 64 4ms873us
标签: routeros ros pppoe ipsec ddns
发表评论