东海:ipsec transform-set csvpn esp encryption-algorithm 3des-cbc esp authentication-algorithm md5 ike proposal 1 encryption-algorithm 3des-cbc dh group2 authentication-algorithm md5ike keychain csvpn pre-shared-key hostname CS key sim Admin@1234ike profile csvpn keychain csvpn exchange-mode aggressive local-identity fqdn dh match remote identity fqdn CS proposal 1 ipsec policy-template temp 12 transform-set csvpn ike-profile csvpn sa duration time-based 3600ipsec policy policy1 50 isakmp template temp长沙:acl number 3000 description nat rule 10 deny ip source 192.168.110.0 0.0.0.255 destination 10.10.100.0 0.0.0.255 rule 20 deny ip source 192.168.110.0 0.0.0.255 destination 192.168.45.0 0.0.0.255acl number 3001 description peer_dh rule 10 permit ip source 192.168.110.0 0.0.0.255 destination 192.168.45.0 0.0.0.255 rule 20 permit ip source 192.168.110.0 0.0.0.255 destination 10.10.100.0 0.0.0.255#ike proposal 1 encryption-algorithm 3des-cbc dh group2 authentication-algorithm md5ike keychain dhvpn match local address Dialer0 pre-shared-key address 183.63.71.66 255.255.255.255 key sim Admin@1234 pre-shared-key hostname dh key sim Admin@1234ike profile dhvpn keychain dhvpn exchange-mode aggressive local-identity fqdn CS match remote identity fqdn dh proposal 1 ipsec policy policy1 10 isakmp transform-set dhvpn security acl 3001 remote-address 183.63.71.66 ike-profile dhvpn sa duration time-based 3600ipsec transform-set dhvpn esp encryption-algorithm 3des-cbc esp authentication-algorithm md5