Juniper SSGϵÁÐ VPNÅäÖÃÏêϸÉèÖÃͼÐνçÃæÒªµã ÏÂÔØ±¾ÎÄ

Juniper SSGϵÁÐ VPNÅäÖÃÏêϸÉèÖÃͼÐνçÃæ

±¾´ÎÅäÖÃʹÓõÄÊÇSSG140ºÍSSG20À´×öÕ¾µãµ½Õ¾µãµÄ»ùÓÚ·ÓɵÄVPN£¨Á½¶ËµØÖ·¶¼Îª¾²Ì¬IPµØÖ·£©¡£ ÏÂͼÊÇÍØÆËͼ£ºÎÒÃÇÊÇÔÚ¹«Ë¾ÄÚ²¿×öÅäÖã¬ËùÒÔ°ÑÍâÍø¿ÚÖ±½ÓÁ¬½Ó£¬ÎÒÃÇÔÚʵÑéÖÐÓÃip1.1.1.2À´´úÌæÍ¼ÖеÄ2.2.2.2,ÕâÑùÈ·±£Â·ÓÉûÓÐÎÊÌ⣬ģÄâÏÂͼµÄ»·¾³

Ê×ÏÈÎÒÃÇ˵һÏÂÅäÖõÄ˼·£º

ÅäÖûùÓÚ·ÓɵÄÕ¾µãµ½Õ¾µãVPN£º1. Ϊ°ó¶¨µ½°²È«Çø¶ÎºÍͨµÀ½Ó¿ÚµÄÎïÀí½Ó¿Ú·ÖÅä IP µØÖ·¡£

2. ÅäÖà VPN ͨµÀ£¬ÔÚ Untrust Çø¶ÎÄÚÖ¸¶¨ÆäÍâÏò½Ó¿Ú£¬½«Æä°ó¶¨µ½Í¨µÀ½Ó¿Ú£¬²¢ÅäÖÃÆä´úÀí ID¡£

3. ÔÚ Trust ºÍ Untrust Çø¶ÎµÄͨѶ²¾ÖÐÊäÈë±¾µØ¼°Ô¶³Ì¶ËµãµÄ IP µØÖ·¡£

4. ÊäÈëͨÏò trust-vr ÖÐÍⲿ·ÓÉÆ÷µÄȱʡ·ÓÉ¡¢Í¨¹ýͨµÀ½Ó¿ÚͨÏòÄ¿±êµÄ·ÓÉÒÔ¼°Í¨ÏòÄ¿±êµÄ Null ·ÓÉ¡£Îª Null ·ÓÉ·ÖÅä½Ï¸ßµÄ¶ÈÁ¿ ( Ô¶ÀëÁã)£¬ÒÔ±ãÆä³ÉΪͨÏòÄ¿±êµÄÏÂÒ»¸ö¿Éѡ·ÓÉ¡£½Ó×Å£¬Èç¹ûͨµÀ½Ó¿ÚµÄ״̬±äΪ¡°Öжϡ±£¬ÇÒÒýÓøýӿڵÄ·ÓɱäΪ·Ç»î¶¯£¬Ôò°²È«É豸»áʹÓà Null ·ÓÉ ( ¼´ÊµÖÊÉ϶ªÆúÁË·¢Ë͸øËüµÄÈκÎÐÅÏ¢Á÷)£¬¶ø²»Ê¹ÓÃȱʡ·ÓÉ ( ¼´×ª·¢Î´¼ÓÃܵÄÐÅÏ¢Á÷)¡£

5. Ϊÿ¸öÕ¾µã¼äͨ¹ýµÄ VPN Á÷Á¿ÉèÖòßÂÔ¡£ ÒÔÏÂÅäÖÃΪSSG140·À»ðǽ ³õʼ»¯·À»ðǽ

Juniper ·À»ðǽ³ö³§Ê±¿Éͨ¹ýȱʡÉèÖõÄIP µØÖ·Ê¹ÓÃTelnet »òÕßWeb ·½Ê½¹ÜÀí¡£È±Ê¡ IP µØÖ·Îª£º192.168.1.1/255.255.255.0¡£¿ÉÒÔÖ±½Óͨ¹ýWEBÀ´½øÐÐÅäÖ㬵«ÈÝÒ×·¢Éú´íÎ󣬽¨ÒéʹÓÃÉ豸×Ô´øµÄÅäÖÃÏßÁ¬½Ó¼ÆËã»úµÄCOM¿Ú²ÉÓ󬼶ÖÕ¶ËÀ´ÐÐÅäÖá£

1¡¢ÎÒÃÇÏÈÅäÖýӿÚeth0/0°ó¶¨µ½trust°²È«Çø¶Î£¬²¢ÉèÖÃIPΪ192.168.1.3/24£¬Í¨¹ýconsole¿ÚÀ´ÅäÖ㺣¨ÏÈÅäÖÃSSG140£¬µÇ¼µÄÓû§ÃûºÍÃÜÂëΪĬÈÏÃÜÂ룺¾ùΪnetscreen£© SSG140-> unset interface ethernet0/0 ip

SSG140-> set interface ethernet0/0 zone trust

SSG140-> set interface ethernet0/0 ip 192.168.1.3/24 SSG140-> set interface ethernet0/0 manage web

SSG140-> save

Save System Configuration ...

½ÓÏÂÀ´ÎÒÃǾͿÉÒÔÓÃWEBÀ´¹ÜÀíÉ豸£¬ÍƼöʹÓÃIEä¯ÀÀÆ÷£º

ÔÚIEä¯ÀÀÆ÷µØÖ·À¸ÀïÊäÈëhttp://192.168.1.3 Óû§ÃûºÍÃÜÂë¾ùΪ:netscreen 2¡¢ÅäÖÃÆäËü°²È«Çø¶Î²¢ÅäÖõØÖ· ¶¨ÒåÄÚÍø½Ó¿Ú

Network > Interfaces > Edit ( ¶ÔÓÚ ethernet0/1): Ð޸ĺìÏß²¿·Ö£¬È»ºóµ¥»÷

Apply:

A£® Zone Name:ÕâÊǶ¨ÒåÄÚ²¿LANµÄIP£¬ËùÒÔÓ¦¸ÃÔÚTrust°²È«Çø¶Î B£® Static IP :ÎÒÃÇ×öµÄÊǾ²Ì¬IPµØÖ·µÄʵÑ飨¹ÜÀíµØÖ·Ó¦ºÍÄÚÍø½Ó¿ÚµØÖ·ÔÚÍ¬Ò»Íø¶Î£© C£® Management Services:´ò¿ªÏàÓ¦µÄ¹ÜÀí·þÎñ£¬ÒÔ·½±ãÔ¶³Ì¹ÜÀí¡£ D£® Other services:ÔÊÐíping £¬·½±ã²âÊÔºÍά»¤¡£ ¶¨ÒåÍâÍø½Ó¿Ú£º

Network > Interfaces > Edit ( ¶ÔÓÚ ethernet0/3): Ð޸ĺìÏß²¿·Ö£¬È»ºóµ¥»÷ Apply:

A.Zone Name:ÕâÊǶ¨ÒåÍⲿ½Ó¿Ú£¬ËùÒÔÓ¦¸ÃÔÚUntrust°²È«Çø¶Î

B.Static IP :ÎÒÃÇ×öµÄÊǾ²Ì¬IPµØÖ·µÄʵÑ飨¹ÜÀíµØÖ·Ó¦ºÍÄÚÍø½Ó¿ÚµØÖ·ÔÚÍ¬Ò»Íø¶Î£© C.Management Services:¸ù¾ÝÐèÒª´ò¿ªÏàÓ¦µÄ¹ÜÀí·þÎñ£¬ÒÔ·½±ãÔ¶³Ì¹ÜÀí¡£ D.Other services:ÔÊÐíping £¬·½±ã²âÊÔºÍά»¤¡£

¶¨ÒåͨµÀ½Ó¿Ú£º

Network > Interfaces > New Tunnel IF:Ð޸ĺìÏß²¿·Ö£¬È»ºóµ¥»÷ OK:

A£® Zone(VR):ͨµÀ½Ó¿Ú°ó¶¨µ½UntrustÇø¶Î B£® Unnumbered:Ñ¡Ôñ°ó¶¨µÄ½Ó¿Ú ¶¨ÒåÄÚ²¿LANµØÖ·±¡£º£¨·½±ãÔÚ²ßÂÔÀïÒýÓã©

Objects > Addresses > List > New:£¬Ð޸ĺìÏß²¿·Ö£¬È»ºóµ¥»÷ OK:

A£® Address Name: ½¨Á¢Ò»¸ö±êʶÉí·ÝµÄÃû³Æ B£® IP Adress/Netmask:ÊäÈëIPµØÖ·ºÍ×ÓÍøÑÚÂ룬24λ±íʾһ¸öÍø¶Î C£® Zone:Ñ¡ÔñÏàÓ¦µÄÇø¶Î ¶¨Òå¶Ô¶ËLANµØÖ·±¡£º

Objects > Addresses > List > New:£¬Ð޸ĺìÏß²¿·Ö£¬È»ºóµ¥»÷ OK

A£® Address Name: ½¨Á¢Ò»¸ö±êʶÉí·ÝµÄÃû³Æ B£® IP Adress/Netmask:ÊäÈë¶Ô¶ËIPµØÖ·ºÍ×ÓÍøÑÚÂ룬24λ±íʾһ¸öÍø¶Î C£® Ñ¡ÔñÏàÓ¦µÄÇø¶Î VPNÅäÖãº

µÚÒ»½×¶Î£ºVPNs > AutoKey Advanced > Gateway > New: Ð޸ĺìÏß²¿·Ö£¬: Ô¤¹²ÏíÃÜԿΪ£º123456