1. 东海:
    2. ipsec transform-set csvpn
    3. esp encryption-algorithm 3des-cbc
    4. esp authentication-algorithm md5
    5. ike proposal 1
    6. encryption-algorithm 3des-cbc
    7. dh group2
    8. authentication-algorithm md5
    9. ike keychain csvpn
    10. pre-shared-key hostname CS key sim Admin@1234
    11. ike profile csvpn
    12. keychain csvpn
    13. exchange-mode aggressive
    14. local-identity fqdn dh
    15. match remote identity fqdn CS
    16. proposal 1
    17. ipsec policy-template temp 12
    18. transform-set csvpn
    19. ike-profile csvpn
    20. sa duration time-based 3600
    21. ipsec policy policy1 50 isakmp template temp
    22. 长沙:
    23. acl number 3000
    24. description nat
    25. rule 10 deny ip source 192.168.110.0 0.0.0.255 destination 10.10.100.0 0.0.0.255
    26. rule 20 deny ip source 192.168.110.0 0.0.0.255 destination 192.168.45.0 0.0.0.255
    27. acl number 3001
    28. description peer_dh
    29. rule 10 permit ip source 192.168.110.0 0.0.0.255 destination 192.168.45.0 0.0.0.255
    30. rule 20 permit ip source 192.168.110.0 0.0.0.255 destination 10.10.100.0 0.0.0.255
    31. #
    32. ike proposal 1
    33. encryption-algorithm 3des-cbc
    34. dh group2
    35. authentication-algorithm md5
    36. ike keychain dhvpn
    37. match local address Dialer0
    38. pre-shared-key address 183.63.71.66 255.255.255.255 key sim Admin@1234
    39. pre-shared-key hostname dh key sim Admin@1234
    40. ike profile dhvpn
    41. keychain dhvpn
    42. exchange-mode aggressive
    43. local-identity fqdn CS
    44. match remote identity fqdn dh
    45. proposal 1
    46. ipsec policy policy1 10 isakmp
    47. transform-set dhvpn
    48. security acl 3001
    49. remote-address 183.63.71.66
    50. ike-profile dhvpn
    51. sa duration time-based 3600
    52. ipsec transform-set dhvpn
    53. esp encryption-algorithm 3des-cbc
    54. esp authentication-algorithm md5