spi1-console.txt

来自「ipsec vpn」· 文本 代码 · 共 60 行

TXT
60
字号
west:~# TZ=GMT export TZwest:~# ipsec spi --clearwest:~# ipsec eroute --clearwest:~# enckey=0x4043434545464649494a4a4c4c4f4f515152525454575758west:~# inspi=0x01000583west:~# outspi=$inspiwest:~# eastip=192.1.2.23west:~# westip=192.1.2.45west:~# source=192.0.2.0/24west:~# dst=192.0.1.0/24west:~# ipsec spi --af inet --edst $eastip  --spi $outspi --proto esp --src $westip --esp 3des --enckey $enckey west:~# ipsec spi --af inet --edst $eastip  --spi $outspi --proto tun --src $westip --dst $eastip --ip4west:~# ipsec spigrp inet $eastip $outspi tun inet $eastip $outspi esp west:~# ipsec eroute --add --eraf inet --src $source --dst $dst --said tun$inspi@$eastipwest:~# ipsec spi --af inet --edst $westip --spi $inspi  --proto esp --src $eastip --esp 3des --enckey $enckey west:~# ipsec spi --af inet --edst $westip --spi $inspi  --proto tun --src $eastip --dst $westip --ip4west:~# ipsec spigrp inet $westip $inspi tun inet $westip $inspi esp west:~# route add -net 192.0.1.0 netmask 255.255.255.0 gw 192.1.2.45 dev ipsec0SIOCADDRT: Network is unreachablewest:~# ipsec tncfg --attach --virtual ipsec0 --physical eth1west:~# ifconfig ipsec0 inet 192.1.2.45 netmask 0xffffff00 broadcast 192.1.2.255 upwest:~# arp -s 192.0.1.1  10:00:00:ab:cd:01west:~# arp -s 192.1.2.23 10:00:00:64:64:23west:~# arp -s 192.1.2.254 10:00:00:64:64:23west:~# ipsec lookwest NOW192.0.2.0/24       -> 192.0.1.0/24       => tun0x1000583@192.1.2.23 esp0x1000583@192.1.2.23  (0)ipsec0->eth1 mtu=16260(1500)->1500esp0x1000583@192.1.2.23 ESP_3DES: dir=out src=192.1.2.45 iv_bits=64bits iv=0xDEADF00DDEADF00D eklen=192 life(c,s,h)= natencap=none natsport=0 natdport=0 refcount=4 ref=2esp0x1000583@192.1.2.45 ESP_3DES: dir=in  src=192.1.2.23 iv_bits=64bits iv=0xDEADF00DDEADF00D eklen=192 life(c,s,h)= natencap=none natsport=0 natdport=0 refcount=4 ref=7tun0x1000583@192.1.2.23 IPIP: dir=out src=192.1.2.45 life(c,s,h)= natencap=none natsport=0 natdport=0 refcount=4 ref=3tun0x1000583@192.1.2.45 IPIP: dir=in  src=192.1.2.23 life(c,s,h)= natencap=none natsport=0 natdport=0 refcount=4 ref=8Destination     Gateway         Genmask         Flags   MSS Window  irtt Ifacewest:~# ipsec klipsdebug --all 

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?