Got it

IPSec VPN

Created: Aug 7, 2021 14:06:15Latest reply: Aug 10, 2021 22:07:20 326 7 2 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello


I am just starting to work with Huawei equipment, I do not understand everything yet.


The AR6120 router uses an Internet connection via PPPOE connection.

Several vpn tunnels were set up between the AR6120 router (local network 10.36.0.0/16) and several remote sites. Several questions arose in the work of the tunnels:


1. Access from a remote site to the network for AR is, ping passes freely. But there is no site from the AR 6120 network to the network.

Tracing shows that the packet does not go to the VPN network, but goes directly to the provider's network. Tried setting up static routes, no result. Tell me how to get the package to go the right way?


2. The speed of copying files over the VPN network does not exceed 2 Mb / s, while the speed of Internet channels is more than 200 megabits. The processor load on the router when copying files increases by 4%, the peak load is 15%. I cannot find the reason for such poor performance. I have not experienced a similar effect with equipment from another manufacturer. Has anyone encountered a similar problem?

VPN configuration below: 

[Huawei] acl number 3001

[Huawei-acl-adv-3002] rule permit ip source 10.36.0.0 0.0.255.255 destination 10.77.0.0 0.0.255.255

[Huawei-acl-adv-3002] quit

[Huawei] acl number 3002

[Huawei-acl-adv-3003] rule permit ip source 10.36.0.0 0.0.255.255 destination 10.78.0.0 0.0.255.255

[Huawei-acl-adv-3003] quit

[Huawei] acl number 3003

[Huawei-acl-adv-3003] rule permit ip source 10.36.0.0 0.0.255.255 destination 10.66.0.0 0.0.255.255

[Huawei-acl-adv-3003] quit

[Huawei] acl number 3004

[Huawei-acl-adv-3003] rule permit ip source 10.36.0.0 0.0.255.255 destination 10.54.0.0 0.0.255.255

[Huawei-acl-adv-3003] quit

[Huawei] acl number 3005

[Huawei-acl-adv-3003] rule permit ip source 10.36.0.0 0.0.255.255 destination 10.116.0.0 0.0.255.255

[Huawei-acl-adv-3003] quit

[Huawei] acl number 3006

[Huawei-acl-adv-3003] rule permit ip source 10.36.0.0 0.0.255.255 destination 192.168.100.0 0.0.0.255

[Huawei-acl-adv-3003] quit

[Huawei] acl number 3007

[Huawei-acl-adv-3003] rule permit ip source 10.36.0.0 0.0.255.255 destination 10.222.0.0 0.0.255.255

[Huawei-acl-adv-3003] quit

 

 

[Huawei] ipsec proposal tran1

[Huawei-ipsec-proposal-tran1] esp authentication-algorithm sha2-256

[Huawei-ipsec-proposal-tran1] esp encryption-algorithm aes-256

[Huawei-ipsec-proposal-tran1] quit

[Huawei] ike proposal 5

[Huawei-ike-proposal-5] encryption-algorithm aes-256

[Huawei-ike-proposal-5] authentication-algorithm sha2-256

[Huawei-ike-proposal-5] dh group14

[Huawei-ike-proposal-5] quit

 

[Huawei] ike peer MSK01

[Huawei-ike-peer-rut1] version 2

[Huawei-ike-peer-rut1] ike-proposal 5

[Huawei-ike-peer-rut1] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut1] remote-address 93.90.220.50

[Huawei-ike-peer-rut1] quit

[Huawei] ike peer SPB01

[Huawei-ike-peer-rut2] version 2

[Huawei-ike-peer-rut2] ike-proposal 5

[Huawei-ike-peer-rut2] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut2] remote-address 78.155.214.159

[Huawei-ike-peer-rut2] quit

[Huawei] ike peer EKT01

[Huawei-ike-peer-rut2] version 2

[Huawei-ike-peer-rut2] ike-proposal 5

[Huawei-ike-peer-rut2] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut2] remote-address 188.170.96.27

[Huawei-ike-peer-rut2] quit

[Huawei] ike peer KZNW01

[Huawei-ike-peer-rut2] version 2

[Huawei-ike-peer-rut2] ike-proposal 5

[Huawei-ike-peer-rut2] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut2] remote-address 213.159.206.154

[Huawei-ike-peer-rut2] quit

[Huawei] ike peer KZNV01

[Huawei-ike-peer-rut2] version 2

[Huawei-ike-peer-rut2] ike-proposal 5

[Huawei-ike-peer-rut2] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut2] remote-address 213.159.206.143

[Huawei-ike-peer-rut2] quit

[Huawei] ike peer QAZ01

[Huawei-ike-peer-rut2] version 2

[Huawei-ike-peer-rut2] ike-proposal 5

[Huawei-ike-peer-rut2] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut2] remote-address 185.102.72.161

[Huawei-ike-peer-rut2] quit

[Huawei] ike peer NSK01

[Huawei-ike-peer-rut2] version 2

[Huawei-ike-peer-rut2] ike-proposal 5

[Huawei-ike-peer-rut2] pre-shared-key cipher XXXXXXXXXXXXXXX

[Huawei-ike-peer-rut2] remote-address 188.254.16.120

[Huawei-ike-peer-rut2] quit

 

[Huawei] ipsec policy slcloud01 10 isakmp

[Huawei-ipsec-policy-isakmp-policy1-10] ike-peer MSK01

[Huawei-ipsec-policy-isakmp-policy1-10] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-10] security acl 3001

[Huawei-ipsec-policy-isakmp-policy1-10] quit

[Huawei] ipsec policy slcloud01 11 isakmp

[Huawei-ipsec-policy-isakmp-policy1-11] ike-peer SPB01

[Huawei-ipsec-policy-isakmp-policy1-11] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-11] security acl 3002

[Huawei-ipsec-policy-isakmp-policy1-11] quit

[Huawei] ipsec policy slcloud01 12 isakmp

[Huawei-ipsec-policy-isakmp-policy1-11] ike-peer EKT01

[Huawei-ipsec-policy-isakmp-policy1-11] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-11] security acl 3003

[Huawei-ipsec-policy-isakmp-policy1-11] quit

[Huawei] ipsec policy slcloud01 13 isakmp

[Huawei-ipsec-policy-isakmp-policy1-11] ike-peer KZNW01

[Huawei-ipsec-policy-isakmp-policy1-11] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-11] security acl 3005

[Huawei-ipsec-policy-isakmp-policy1-11] quit

[Huawei] ipsec policy slcloud01 14 isakmp

[Huawei-ipsec-policy-isakmp-policy1-11] ike-peer KZNV01

[Huawei-ipsec-policy-isakmp-policy1-11] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-11] security acl 3006

[Huawei-ipsec-policy-isakmp-policy1-11] quit

[Huawei] ipsec policy slcloud01 15 isakmp

[Huawei-ipsec-policy-isakmp-policy1-11] ike-peer QAZ01

[Huawei-ipsec-policy-isakmp-policy1-11] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-11] security acl 3007

[Huawei-ipsec-policy-isakmp-policy1-11] quit

[Huawei] ipsec policy slcloud01 16 isakmp

[Huawei-ipsec-policy-isakmp-policy1-11] ike-peer NSK01

[Huawei-ipsec-policy-isakmp-policy1-11] proposal tran1

[Huawei-ipsec-policy-isakmp-policy1-11] security acl 3004

[Huawei-ipsec-policy-isakmp-policy1-11] quit

 

[Huawei] interface Dialer2

[Huawei-GigabitEthernet0/0/1] ipsec policy slcloud01

[Huawei-GigabitEthernet0/0/1] quit


Featured Answers

Recommended answer

DDSN
Admin Created Aug 7, 2021 14:47:10

Hi user_4331755,
The VPN tunnel technology is to encapsulate VPN messages into a tunnel through a protocol and then establish a dedicated data transmission channel in the public network to forward the message through the public network. For example, IPSec VPN encapsulates IPSec packets into IP packets and then forwards them through physical links. So the data packet is forwarded through the ISP network.
The CPU usage of the router is affected in many ways, and the CPU usage of 70% or below can be called normal. Regarding the high CPU usage of AR routers, you can refer to the following link:
https://support.huawei.com/enterprise/en/doc/EDOC1000079719/25a892b3?idPath=24030814|21432787|7923148|252010531
View more
  • x
  • convention:

All Answers
Dear friend!
Please rest assured that we'll be back with an answer shortly.
View more
  • x
  • convention:

DDSN
DDSN Admin Created Aug 7, 2021 14:47:10

Hi user_4331755,
The VPN tunnel technology is to encapsulate VPN messages into a tunnel through a protocol and then establish a dedicated data transmission channel in the public network to forward the message through the public network. For example, IPSec VPN encapsulates IPSec packets into IP packets and then forwards them through physical links. So the data packet is forwarded through the ISP network.
The CPU usage of the router is affected in many ways, and the CPU usage of 70% or below can be called normal. Regarding the high CPU usage of AR routers, you can refer to the following link:
https://support.huawei.com/enterprise/en/doc/EDOC1000079719/25a892b3?idPath=24030814|21432787|7923148|252010531
View more
  • x
  • convention:

Hello

Perhaps I put it incorrectly.
Processor in general not loaded, the maximum processor load was 15%, usually it is kept at 10%. I was worried about the slow speed of copying files over the VPN.
On the equipment of another manufacturer with the same vpn - tunnel parameters, the copying speed was several times higher.
Are there any recommendations for optimal vpn configuration?

The main problem for me is the inaccessibility of resources of remote sites via vpn. Those. the network behind AR 6120 is available to remote sites, but on the contrary, it is not.
View more
  • x
  • convention:

Good answer
View more
  • x
  • convention:

DDSN
DDSN Admin Created Aug 9, 2021 00:42:40

Hi user_4331755,
The following link provides many IPSec VPN configuration examples. You can select an IPSec VPN configuration example based on your scenario.
https://support.huawei.com/hedex/hdx.do?docid=EDOC1100087043&id=EN-US_TASK_0176374694&lang=en
View more
  • x
  • convention:

andersoncf1
andersoncf1 MVE Author Created Aug 9, 2021 16:58:34

Good answer from DDSN IPSec VPN-4078441-1
View more
  • x
  • convention:

Hello

Thank you for the instructions. I tried different options for configuring the vpn - tunnel, the problem still remains - packets from the AR6120 network do not go to the branch network. Packets (for example, ping) pass from the branch to the AR6120 network without problems.
I already broke my head, what could be the problem.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.