BTS3902E use IPSec transmission, 你会做这个方案了吗?
|
我前几天刚成功做方案和数据配置, 给大家分享一下。 小站用IPSec传输, 这个方案为了减少成本, 但是信息安全和传输质量不能保证。 各位大神对这种传输的信息安全, 传输质量有什么看法? 1. In Small Cell Project, the FTTH transmission is use to connect Small Cell BTS3902E to RNC.
1. Network topology In Small Cell Project, the FTTH transmission is use to connect Small Cell BTS3902E to RNC. Network topology as below:
1.1 License requirementNodeB integrated IPSec(Per NodeB)1.2 Data Planning
1.3 Data configurationScript on RNC same with normal site.
Script on nodeB side: Need to add more script for IPSec:
//Configure security data in secure networking scenarios. IPSec
ADD ACL: ACLID=3000; ADD ACLRULE: ACLID=3000, RULEID=1, PT=IP, SIP="10.12.190.197", SWC="0.0.0.255", DIP="10.12.73.137", DWC="0.0.0.255", MDSCP=NO; Rule for RNC ADD ACLRULE: ACLID=3000, RULEID=2, PT=IP, SIP="10.12.190.196", SWC="0.0.0.0", DIP="10.12.1.1", DWC="0.0.0.255", MDSCP=NO; Rule for M2000 server ADD ACLRULE: ACLID=3000, RULEID=3, PT=IP, SIP="10.12.190.197", SWC="0.0.0.255", DIP="10.12.1.132", DWC="0.0.0.0", MDSCP=NO; Rule for IPCLK server 1 ADD ACLRULE: ACLID=3000, RULEID=4, PT=IP, SIP="10.12.190.197", SWC="0.0.0.255", DIP="10.12.1.133", DWC="0.0.0.0", MDSCP=NO; Rule for IPCLK server 2
SET IKECFG: IKELNM="vmsadmin"; ADD IKEPROPOSAL: PROPID=1, ENCALG=DES, AUTHALG=SHA1, AUTHMETH=PRE_SHARED_KEY, DHGRP=DH_GROUP2; //ADD IKEPEER: PEERNAME="1",PROPID=1,IKEVERSION=IKE_V2,IDTYPE=IP,REMOTEIP="101.99.17.114",REMOTENAME="segw",PKEY="vmsadmin",DPD=PERIODIC,REDUNDANCYFLAG=NONE,IPSECPREFRGSW=OFF; // Configure with NAT ADD IKEPEER: PEERNAME="1",PROPID=1,IKEVERSION=IKE_V2,IDTYPE=FQDN,REMOTEIP="101.99.17.114",REMOTENAME="SeGW",PKEY="vmsadmin",DPD=PERIODIC,NATTRAV=ENABLE,REDUNDANCYFLAG=NONE,IPSECPREFRGSW=OFF;
ADD IPSECPROPOSAL: PROPNAME="1",TRANMODE=ESP,ESPAUTHALG=MD5,ESPENCALG=DES; ADD IPSECPOLICY: SPGN="1",SPSN=1,ACLID=3000,PROPNAME="1",PEERNAME="1",LTCFG=LOCAL; ADD IPSECBIND: PT=ETH,PN=1,SPGN="1";
本帖最后由 ruanhuian 于 2016-01-19 12:51 编辑 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||

Favorite (0)