Method used to configure IPSec through an interface with a dynamic IP address on the AR

1

Huawei AR routers support IPSec networking where one side has a dynamic IP address and the other side has a fixed IP address.
There is no difference on the configuration method between different versions and models. For details about the configuration, see "Does the Interface with a Dynamic IP Address Support IPSec?" of "IPSec Configuration" in Configuration Guide - VPN.

Other related questions:
Can the interface on the AR be configured with IPSec when it dynamically obtains an IP address
The interface can be configured with IPSec when it dynamically obtains an IP address. When the local interface is configured with a dynamic IP address and the remote interface is configured with a fixed IP address, you can configure an IPSec policy template on the remote end to implement IPSec. The 3G interface is used as an example. IKE negotiation is used. The key configuration is as follows: Interface with a dynamic IP address # ike peer peer_3g_1 v1 pre-shared-key cipher %^%#JvZxR2g8c;a9~FPN~n'$7`DEV&=G(=Et02P/%\*!%^%# //Set the preshared key to huawei. remote-address 10.5.39.160 //Specify the fixed IP address for the remote end. # ipsec proposal ipsec //Use default security parameters. # ipsec policy ipsec 1 isakmp //Configure an IPSec policy. security acl 3000 ike-peer peer_3g_1 proposal ipsec # interface Cellular0/0/0 ipsec policy ipsec //Apply the IPSec policy to the 3G interface. Other configurations of the 3G interface are not mentioned. # acl 3000 //Configure an ACL. IPSec protects the packets matching the ACL. ... # Interface with a fixed IP address # ipsec proposal ipsec # ike peer peer_3g_2 v1 //The remote interface is configured with a dynamic IP address, so there is no need to specify an IP address for the remote interface. pre-shared-key cipher %^%#K{JG:rWVHPMnf;5\|,GW(Luq'qi8BT4nOj%5W5=)%^%# //Set the pre-shared key to huawei. # ipsec policy-template temp 1 //Configure an IPSec policy template. ike-peer peer_3g_2 proposal ipsec # ipsec policy ipsec 1 isakmp template temp //Bind the IPSec policy to the IPSec policy template. # interface GigabitEthernet 1/0/0 //The interface uses a fixed IP address. ipsec policy ipsec ip address 10.5.39.160 255.255.255.255 #

How do I check IP addresses that are dynamically obtained by an AR
On the AR, you can run the following command to check the IP address that is dynamically obtained. - If IP addresses are assigned based on the interface address pool, run the display ip pool interface interface-pool-name used command. If the IP addresses are assigned based on the global address pool, run the display ip pool name ip-pool-name used command. You can know the IP address assigned to each client based on the mapping between IP addresses and MAC addresses.

Method used to configure IPSec on the 3G interface of the AR
Huawei AR series routers can dynamically obtain IP addresses from a service provider to access public network using a 3G interface, and establish IPSec connections with the headquarters. This function applies to V200R002C00 and later versions and all models of the AR. For details, see Typical Configuration Examples.

Method used to configure two IP addresses for an interface on the USG firewall and set the primary IP address as the dynamic IP address allocated by the DHCP gateway
You can configure two IP addresses for an interface on the USG2000, USG5000, and USG6000 and set the primary IP address as the dynamic IP address allocated by the DHCP gateway as follows: Note: The SUB address can only be configured as a static IP address of the PC. [USG]interface GigabitEthernet0/0/1 [USG-GigabitEthernet0/0/1]ip address 192.168.2.1 255.255.255.0 [USG-GigabitEthernet0/0/1]ip address 192.168.1.1 255.255.255.0 sub [USG-GigabitEthernet0/0/1]quit [USG] dhcp server ip-pool 0 [USG-dhcp-0]network 192.168.2.0 mask 255.255.255.0 [USG-dhcp-0]dns-list 192.168.2.3 [USG-dhcp-0] quit IP addresses in network segment 192.168.2.0 can be dynamically allocated. IP addresses in network segment 192.168.1.0 are static IP addresses set on the PC.

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top