网络防御(7)

课堂实验

R1

[Huawei] int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 100.1.12.2 24

protocolAug 1 2023 10:24:09-08:00 Huawei gOlIFNET/4/LINK STATE(1)[4]:The1ineIp on the interface GigabitEthernet0/0/0 has entered the Up state.

[Huawei-GigabitEthernet0/0/0]a[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/]ip add 100.1.13.2 24

Aug l 2023 10:24:51-08:00 Huawei OlIENET/4/LINK STATE(1)[5]:The line protocolIP on the interface GigabitEthernet0/0/1 has entered the Up state

[Huawei-GigabitEthernet0/0/1]

R2

[Huawei] int g0/0/0

[Huawei-GigabitEthernet0/0/0] ip add 192.168.1.1 24

1 2023 10:18:43-08:00 Huawei OlIFNET/4/LINK STATE(1)[0]:The line protocolAugIP on the interface GigabitEthernet0/0/0 has entered the Up state.

[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 100.1.12.1 24

Aug1 2023 10:19:14-08:00 Huawei OlIFNET/4/INK STATE(1)[l:The line protocolIP on the interface GigabitEthernet0/0/1 has entered the Up state.

[Huawei-GigabitEthernet0/0/1]q

[Huawei]ip route-static 0.0.0.0 0 100.1.12.2

选参数

第一阶段

[Huawei]ike proposal 1

[Huawei-ike-proposal-1]encryption-algorithm ae

[Huawei-ike-proposal-1]encryption-algorithm aes-cbc-128

[Huawei-ike-proposal-1]authentication-algorithm sha1

[Huawei-ike-proposal-l]dh group2

[Huawei-ike-proposal-1]authentication-method pre-share

[Huawei-ike-proposal-1]sa duration

[Huawei]ike peer jjj
IKE peer is new, please indicate the mode to finish creatin(Error: This
[Huawei]ike peer jjj vl

[Huawei-ike-peer-jjj]pre-shared-key cipher keyl23

[Huawei-ike-peer-jjj]exchange-mode main

[Huawei-ike-peer-jjj]pee
[Huawei-ike-peer-jjj]rem
[Huawei-ike-peer-jjj]remote-address 100.1.13.1
[Huawei-ike-peer-jjj]ik
[Huawei-ike-peer-jjj]ike-proposal 1

第二阶段

[Huawei]ipsec profile

[Huawei-ipsec-proposal-jjj]encapsulation-mode tunnel

[Huawei-ipsec-proposal-jjj]esp encryption-algorithm aes-128

[Huawei-ipsec-proposal-jjj]esp authentication-algorithm shal

[Huawei]acl 3000

[Huawei-acl-adv-3000]rule permit ip source 192.168.1.0  0.0.0.255 destination 192.168.2.0 0.0.0.255

[Huawei-acl-adv-3000]

[Huawei]ipsec policy jjj 1 isakmp

[Huawei-ipsec-policy-isakmp-jjj-1]proposal jjj

[Huawei-ipsec-policy-isakmp-jjj-1]ike-peer jjj

[Huawei-ipsec-policy-isakmp-jjj-1]security acl 3000

[Huawei-ipsec-policy-isakmp-jjj-1]pfs dh-group2

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ipsec policy jjj

R3

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 192.168.2.1 24
Aug 1 2023 10:20:24-08:00 Huawei OlIFNET/4/LINK STATE(1)[0]:The line protocol
Ip on the interface GigabitEthernet0/0/1 has entered the Up state.

[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 100.1.13.1 24
Aug 1 2023 10:20:45-08:00 Huawei gOlIFNET/4/LINK STATE(1)[1:The line protocol
IP on the interface GigabitEthernet0/0/0 has entered the Up state.
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip ro
[Huawei]ip route-
[Huawei]ip route-static 0.0.0.0 0 100.1.13.2

第一阶段

[Huawei]ike proposal 1

[Huawei-ike-proposal-1]authentication-algorithm shal

[Huawei-ike-proposal-1]authentication-method pre-share

[Huawei-ike-proposal-1]encryption-algorithm aes-cbc-128

[Huawei-ike-proposal-1]dh group2

[Huawei-ike-proposal-1]q

[Huawei]ike peer jjj v1

[Huawei-ike-peer-jjj]pre-shared-key cipher key123

[Huawei-ike-peer-jjj]re-authentication

[Huawei-ike-peer-jjj]remote-address 100.1.12.1

[Huawei-ike-peer-jjj]ike-proposal 1

第二阶段

[Huawei-ike-proposal-1]authentication-algorithm shal

[Huawei-ike-proposal-1]authentication-method pre-share

[Huawei-ike-proposal-1]encryption-algorithm aes-cbc-128

[Huawei-ike-proposal-1]dh group2

[Huawei-ike-proposal-1]q

[Huawei]ike peer jjj v1

[Huawei-ike-peer-jjj]pre-shared-key cipher key123

[Huawei-ike-peer-jjj]remote-address 100.1.12.1

[Huawei-ike-peer-jjj]ike-proposal 1

[Huawei-ike-peer-jjj]q

[Huawei]ipsec proposal jjj

[Huawei-ipsec-proposal-jjj]encapsulation-mode tunnel

[Huawei-ipsec-proposal-jjj]esp authentication-algorithm shal

[Huawei-ipsec-proposal-jjj]esp encryption-algorithm aes-128

[Huawei-ipsec-proposal-jjj]q

[Huawei]acl 3000

[Huawei-acl-adv-3000]pr

[Huawei-acl-adv-3000]rule permit ip source 192.168 .2.0 0.0.0.255 destination192.
168.1.0 0.0.0.255

[Huawei-acl-adv-3000]q

[Huawei]ipsec policy jjj 1 isakmp

[Huawei-ipsec-policy-isakmp-jjj-1]proposal jjj

[Huawei-ipsec-policy-isakmp-jjj-1]ike-peer jjj

[Huawei-ipsec-policy-isakmp-jjj-1]security acl 3000

[Huawei-ipsec-policy-isakmp-jjj-1]pfs dh-group2

[Huawei-ipsec-policy-isakmp-jjj-1]q

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ipsec policy jjj

PC1:

 PC2

测试:

 

 

本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如若转载,请注明出处:http://www.hqwc.cn/news/58329.html

如若内容造成侵权/违法违规/事实不符,请联系编程知识网进行投诉反馈email:809451989@qq.com,一经查实,立即删除!

相关文章

python中文官网下载安装,python官方中文文档下载

大家好,小编来为大家解答以下问题,python官网下载步骤图解,python官方中文文档下载,现在让我们一起来看看吧! python官网网址 python官方网站 python官网网址中文。像我们想要抓住一门好的编程语言,如何开始…

vue 路由页面跳转

从index.vue跳转到data.vue index.vue <el-table-column label"客户数" align"center" :show-overflow-tooltip"true"><template slot-scope"scope"><router-link :to"/system/enterprise-data/index/ scope.ro…

如何解决 Elasticsearch 查询缓慢的问题以获得更好的用户体验

作者&#xff1a;Philipp Kahr Elasticsearch Service 用户的重要注意事项&#xff1a;目前&#xff0c;本文中描述的 Kibana 设置更改仅限于 Cloud 控制台&#xff0c;如果没有我们支持团队的手动干预&#xff0c;则无法进行配置。 我们的工程团队正在努力消除对这些设置的限制…

flutter:二维码生成与读取

前言 这csdn真的是服了&#xff0c;图片里有个二维码就直接变成违规图片了。至于效果的话&#xff0c;自己运行一下看看吧。 生成 flutter中生成二维码可以使用 qr_flutter。 官方文档 https://pub-web.flutter-io.cn/packages/qr_flutter 安装 flutter pub add qr_flutt…

源码分析——ConcurrentHashMap源码+底层数据结构分析

文章目录 1. ConcurrentHashMap 1.71. 存储结构2. 初始化3. put4. 扩容 rehash5. get 2. ConcurrentHashMap 1.81. 存储结构2. 初始化 initTable3. put4. get 3. 总结 1. ConcurrentHashMap 1.7 1. 存储结构 Java 7 中 ConcurrentHashMap 的存储结构如上图&#xff0c;Concurr…

git的日常使用

加入忽略列表&#xff1a;在.gitignore中加入忽略的文件&#xff0c;build/ 表示build文件夹下&#xff0c;*.jar 表示以jar结尾的&#xff0c;用换行符隔开将另一个分支合并到当前分支&#xff1a;git merge xxx冲突出现&#xff0c;可以看看这里&#xff1a;详解Git合并冲突—…

台式机显卡电源线怎么拔?

搞AI的设计到很多图形计算&#xff0c;那必不可少的就要和硬件打交道了。 显卡有2端&#xff0c;一端是插到主板上&#xff0c;另一端是接通在电源上&#xff0c;接通电源的有2端&#xff0c;一端是电源&#xff0c;另一端是显卡。其中显卡这端很难拔。 根据我百度后&#xff0…

git clean 命令

git clean -n //显示要删除的文件&#xff0c;clean的演习&#xff0c;告诉哪些文件删除&#xff0c;只是一个提醒。 git clean -dn //显示要删除的文件和目录 git clean -f //删除未追踪的文件 git clean -dff //删除未追踪的目录 git clean -df //清除所有未跟踪文件&#xf…

Fabric

Fabric Fabric.js是一个非常好用的Javascript HTML5 canvas库&#xff0c;封装了canvas原生较为复杂的api&#xff0c;在canvas元素的顶部提供交互式对象模型&#xff0c;用于实现图片的变形旋转拖拉拽等功能。 在线demo: 官网链接 下载 npm install fabric --save或 yarn …

模块化原理:source-map

1. webpack打包基本配置 1.安装webpack与webpack-cli npm i webpack webpack-cli 2.配置 "build":"webpack" 3. 新建webpack.config.js const path require(path); module.exports {// mode: "development",// 默认production&#xff08;什么…

微信小程序的项目解构

视频链接 黑马程序员前端微信小程序开发教程&#xff0c;微信小程序从基础到发布全流程_企业级商城实战(含uni-app项目多端部署)_哔哩哔哩_bilibili 接口文档 https://www.escook.cn/docs-uni-shop/mds/1.start.html 1&#xff1a;微信小程序宿主环境 1&#xff1a;常见的宿…

鉴源实验室丨汽车网络安全攻击实例解析(二)

作者 | 田铮 上海控安可信软件创新研究院项目经理 来源 | 鉴源实验室 社群 | 添加微信号“TICPShanghai”加入“上海控安51fusa安全社区” 引言&#xff1a;汽车信息安全事件频发使得汽车行业安全态势愈发紧张。这些汽车网络安全攻击事件&#xff0c;轻则给企业产品发布及产品…