Documente Academic
Documente Profesional
Documente Cultură
If you want to recall how to configure GRE, just look at GRE on Huawei routers.
Today, Im going to put them together and try to configure GRE over IPSec.
Based on the topology below, configure IP adresses and OSPF protocol to ensure connectivity
between all routers (omitted here).
[labnario_1]interface Tunnel0/0/0
[labnario_1-Tunnel0/0/0] ip address 10.0.0.1 255.255.255.0
[labnario_1-Tunnel0/0/0] tunnel-protocol gre
[labnario_1-Tunnel0/0/0] source 150.0.0.1
[labnario_1-Tunnel0/0/0] destination 160.0.0.1
[labnario_3]interface Tunnel0/0/0
[labnario_3-Tunnel0/0/0] ip address 10.0.0.2 255.255.255.0
[labnario_3-Tunnel0/0/0] tunnel-protocol gre
[labnario_3-Tunnel0/0/0] source 160.0.0.1
[labnario_3-Tunnel0/0/0] destination 150.0.0.1
Use ping command to check if the tunnel interface has been set up:
[labnario_3]ping 150.0.0.1
PING 150.0.0.1: 56 data bytes, press CTRL_C to break
Request time out
Reply from 150.0.0.1: bytes=56 Sequence=2 ttl=254 time=50 ms
Reply from 150.0.0.1: bytes=56 Sequence=3 ttl=254 time=30 ms
Reply from 150.0.0.1: bytes=56 Sequence=4 ttl=254 time=30 ms
Reply from 150.0.0.1: bytes=56 Sequence=5 ttl=254 time=40 ms
[labnario_1]acl 3500
[labnario_1-acl-adv-3500]rule permit gre source 150.0.0.1 0 destination 160.0.0.1 0
<labnario_1>dis ike sa
Conn-ID Peer VPN Flag(s) Phase
---------------------------------------------------------------
11 160.0.0.1 0 RD|ST 2
10 160.0.0.1 0 RD|ST 1
Flag Description:
RD--READY ST--STAYALIVE RL--REPLACED FD--FADING TO--TIMEOUT
HRT--HEARTBEAT LKG--LAST KNOWN GOOD SEQ NO. BCK--BACKED UP
<labnario_1>dis ipsec sa
===============================
Interface: GigabitEthernet0/0/0
Path MTU: 1500
===============================
-----------------------------
IPSec policy name: "labnario"
Sequence number : 1
Acl Group : 3500
Acl rule : 5
Mode : ISAKMP
-----------------------------
Connection ID : 11
Encapsulation mode: Tunnel
Tunnel local : 150.0.0.1
Tunnel remote : 160.0.0.1
Flow source : 150.0.0.1/255.255.255.255 47/0
Flow destination : 160.0.0.1/255.255.255.255 47/0
Qos pre-classify : Disable
Lets verify whether traffic between hosts, passing through tunnel interface, is encrypted by
IPSec (use ping between PC1 and PC2):