1. [Huawei]display current-configuration configuration
    2. [V300R019C10SPC200]
    3. #
    4. authentication-profile name default_authen_profile
    5. authentication-profile name dot1x_authen_profile
    6. authentication-profile name dot1xmac_authen_profile
    7. authentication-profile name mac_authen_profile
    8. authentication-profile name multi_authen_profile
    9. authentication-profile name portal_authen_profile
    10. #
    11. ikev2 prf aes-xcbc-128 compatible
    12. #
    13. dhcp enable
    14. #
    15. ip vpn-instance test
    16. ipv4-family
    17. route-distinguisher 10:10
    18. vpn-target 10:10 export-extcommunity
    19. vpn-target 10:10 import-extcommunity
    20. #
    21. radius-server template default
    22. #
    23. pki realm default
    24. #
    25. ssl policy default_policy type server
    26. pki-realm default
    27. version tls1.2
    28. ciphersuite rsa_aes_128_cbc_sha rsa_aes_128_sha256 rsa_aes_256_sha256 ecdhe_rsa_aes128_gcm_sha256 ecdhe_rsa_aes256_gcm_sha384
    29. #
    30. acl number 2000
    31. rule 0 permit source 20.2.2.0 0.0.0.255
    32. acl number 2001
    33. rule 0 permit vpn-instance test source 30.1.1.0 0.0.0.255
    34. #
    35. acl number 3000
    36. rule 5 permit ip source 88.88.88.88 0 destination 33.33.33.33 0
    37. #
    38. ipsec proposal ADWAN-TS
    39. esp authentication-algorithm sha1
    40. esp encryption-algorithm aes-128
    41. ipsec proposal cpe
    42. esp authentication-algorithm sha1
    43. esp encryption-algorithm aes-128
    44. #
    45. ike proposal default
    46. encryption-algorithm des
    47. dh group1
    48. authentication-algorithm sha1
    49. authentication-method pre-share
    50. integrity-algorithm hmac-sha2-256
    51. prf hmac-sha2-256
    52. ike proposal 1
    53. encryption-algorithm des
    54. dh group1
    55. authentication-algorithm sha1
    56. authentication-method pre-share
    57. integrity-algorithm hmac-sha1-96
    58. prf hmac-sha1
    59. #
    60. ike peer vpe
    61. undo version 2
    62. pre-shared-key cipher %^%#C3pfP{nrQTsi]mV"V"W<~_,UFL)t"8FHnxXS[JI;%^%#
    63. ike-proposal 1
    64. remote-address 172.171.9.7
    65. rsa encryption-padding oaep
    66. rsa signature-padding pss
    67. ikev2 authentication sign-hash sha2-256
    68. #
    69. ipsec policy cpe 1 isakmp
    70. security acl 3000
    71. ike-peer vpe
    72. proposal ADWAN-TS
    73. route inject dynamic
    74. #
    75. free-rule-template name default_free_rule
    76. #
    77. portal-access-profile name portal_access_profile
    78. #
    79. ip pool cpe
    80. vpn-instance test
    81. gateway-list 10.1.1.1
    82. network 10.1.1.0 mask 255.255.255.0
    83. lease unlimited
    84. dns-list 114.114.114.114
    85. #
    86. aaa
    87. authentication-scheme default
    88. authentication-mode local
    89. authentication-scheme radius
    90. authentication-mode radius
    91. authorization-scheme default
    92. authorization-mode local
    93. accounting-scheme default
    94. accounting-mode none
    95. local-aaa-user password policy administrator
    96. domain default
    97. authentication-scheme default
    98. accounting-scheme default
    99. domain default_admin
    100. authentication-scheme default
    101. accounting-scheme default
    102. local-user admin password irreversible-cipher $1a$dnb4I=3Xj6$4J'MG1`WP8Qx{I,N}=AWH:r@#@L!VS7#!yY`+5vA$
    103. local-user admin privilege level 15
    104. local-user admin service-type terminal http
    105. local-user fnii2019 password irreversible-cipher $1a$9t(<DJjE9>$kSlFVmC:fK,63g!n`k<D_YZ%CAWo2-4DB|WzB<XG$
    106. local-user fnii2019 privilege level 15
    107. local-user fnii2019 service-type ssh
    108. #
    109. web
    110. #
    111. firewall zone Local
    112. #
    113. nat address-group 0 22.22.22.22 22.22.22.22
    114. nat address-group 1 66.66.66.66 66.66.66.66
    115. #
    116. bridge-domain 10
    117. vxlan vni 100
    118. #
    119. bgp 100
    120. router-id 88.88.88.88
    121. #
    122. ipv4-family unicast
    123. undo synchronization
    124. network 22.22.22.22 255.255.255.255
    125. network 32.0.0.0 255.255.255.0
    126. #
    127. ipv4-family vpnv4
    128. policy vpn-target
    129. #
    130. ipv4-family vpn-instance test
    131. network 10.1.1.0 255.255.255.0
    132. network 66.66.66.66 255.255.255.255
    133. peer 192.168.10.9 as-number 100
    134. peer 192.168.10.9 connect-interface Vbdif10
    135. #
    136. snmp-agent local-engineid 800007DB0328DEE5262179
    137. snmp-agent trap enable
    138. #
    139. ssh user fnii2019 authentication-type password
    140. stelnet server enable
    141. telnet server enable
    142. ssh server hmac sha2_256_96 sha1_96
    143. #
    144. http secure-server ssl-policy default_policy
    145. http secure-server enable
    146. http server permit interface GigabitEthernet0/0/0
    147. #
    148. ip route-static 0.0.0.0 0.0.0.0 vpn-instance test
    149. ip route-static 152.152.152.152 255.255.255.255 100.10.1.2
    150. #
    151. fib regularly-refresh disable
    152. #
    153. nqa test-instance admin icmp
    154. test-type icmpjitter
    155. destination-address ipv4 33.33.33.33
    156. source-address ipv4 88.88.88.88
    157. frequency 30
    158. probe-count 10
    159. start now
    160. #
    161. user-interface con 0
    162. authentication-mode password
    163. set authentication password cipher %^%#KB%R7rqQ_5\,]tSW^/c&r|X\D78iY#8Chj;}#l+(!RVz$J6G3Dh=tz.5z:[X%^%#
    164. user-interface vty 0 4
    165. authentication-mode aaa
    166. user privilege level 3
    167. idle-timeout 0 0
    168. #
    169. wlan ac
    170. traffic-profile name default
    171. security-profile name default
    172. security-profile name default-wds
    173. security wpa2 psk pass-phrase %^%#rOJvPw&N8Bx6FT4WPmE0=>,A=TnWOD`@$PID0BET%^%# aes
    174. ssid-profile name default
    175. vap-profile name default
    176. wds-profile name default
    177. regulatory-domain-profile name default
    178. air-scan-profile name default
    179. rrm-profile name default
    180. radio-2g-profile name default
    181. radio-5g-profile name default
    182. wids-spoof-profile name default
    183. wids-profile name default
    184. ap-system-profile name default
    185. port-link-profile name default
    186. wired-port-profile name default
    187. ap-group name default
    188. #
    189. dot1x-access-profile name dot1x_access_profile
    190. #
    191. mac-access-profile name mac_access_profile
    192. #
    193. ops
    194. #
    195. autostart
    196. #
    197. secelog
    198. #
    199. ms-channel
    200. #
    201. return