l
Rule priority
: The value range is
1-32
.
Rule priority
must be unique for each rule.
l
Protocol number
: specifies the protocol used by a rule. Common protocol numbers include
1 (ICMP), 2 (IGMP), 6 (TCP), 17 (UDP), and 47 (GRE). If a rule is used to match a GRE
tunnel, the protocol number is 47, and the matching port is invalid.
l
DSCP
: specifies that a rule is matched using the DSCP. The value range is
0-63
.
l
Source IP
: The input format is
start IP address/mask bits
, for example
192.168.32.0/24
.
l
Destination IP
: The input format is
start IP address/mask bits
, for example
192.168.32.0/24
.
l
Source port
: The value range is
0-65535
.
l
Destination port
: The value range is
0-65535
.
Step 5
Click
Submit
.
----End
7.6 VPN
This section describes how to configure VPN connections, and use the data service encryption
function.
Procedure
Step 1
Choose
VPN
>
VPN
. The
VPN
interface is displayed.
Step 2
Click
New
The related parameters are as follows:
l
VPN connection
: If this parameter is set to
Enable
, the encryption rule is enabled.
l
VPN name
: indicates the name of an encryption rule. The name must be unique.
l
Remote IP address
address of the peer device on the
l
Key mode
: includes
Manual
and
Auto
modes.
If the
Manual
mode is used, the following parameters must be set:
–
Protocol
: includes
AH
and
ESP
protocols.
–
Manual authentication algorithm
: includes
hmac_md5
and
hmac-sha1
algorithms.
–
Manual authentication key
: If
Manual authentication algorithm
is
hmac_md5
,
Manual authentication key
must contain 16 characters; if
Manual authentication
algorithm
is
hmac-sha1
,
Manual authentication key
must contain 20 characters.
–
Manual encryption algorithm
: If
Protocol
is set to
ESP
, this parameter can be set to
3des-cbc
or
des-cbc
.
–
Manual encryption key
: required if
Protocol
is set to
ESP
.
If
Manual encryption algorithm
is
3des-cbc
,
Manual encryption key
must contain 24
characters. The 24 characters are divided into three groups, and must meet the following
requirements: the three groups must be different from each other; the characters in each
group must not be completely the same; each group must contain valid ASCII code; the
characters must not be only digits or letters.
EG860
User Guide
7 Reference
Issue 02 (2015-04-10)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
96