Configuration on the Hillstone Firewall
Prerequisites
The basic network configuration of the Hillstone firewall has been completed.
Procedure
- Log in to the configuration page.
A firewall running the 5.5R9 version is used as an example. The configuration pages may vary according to the firewall models and software versions.
- Complete basic settings.
- Configure a security zone.
Choose . Click New and set parameters, as shown in Figure 1.
- Configure a security policy.
Choose . Click New, choose Policy, and set parameters, as shown in Figure 2.
- Configure a basic route.
- Choose New. , and click
- In Destination Route, add a static route to the VPC of the Hillstone firewall.
- Set Next-hop to an interface of the Hillstone firewall.
- Set Gateway to the subnet gateway address for the private IP address of the Hillstone firewall's interface.
Figure 3 shows the key parameter settings.
- Click OK.
- Configure a security zone.
- Configure VPN connections.
- Choose IPsec VPN tab page, click New. . On the
- Click the plus sign (+) in the Peer Name drop-down list box to add peer information.
- Click the plus sign (+) in the Proposal1 drop-down list box to create a phase-1 proposal. Set parameters and click OK. Figure 4 shows the key parameter settings.
- Configure VPN peers. As the Huawei Cloud VPN gateway has two EIPs bound, you need to configure two peers.
Select the phase-1 proposal created in c from the Proposal1 drop-down list box. Click Advanced Configuration, toggle on NAT Traversal and DPD, and click OK.
Figure 5 Configuring VPN peers - Click the plus sign (+) in the P2 Proposal drop-down list box to create a phase-2 proposal. Set parameters and click OK. Figure 6 shows the key parameter settings.
- Configure VPN connection information. Select each of the VPN peers created in d from the Peer Name drop-down list box, select the phase-2 proposal created in e from the P2 Proposal drop-down list box, and click OK.
Figure 7 Configuring IPsec VPN
- Configure tunnel interfaces.
- Choose New, and choose Tunnel Interface. , click
- Configure two tunnel interfaces. Figure 8 shows the key parameter settings.
- Configure service routes.
- Choose New. , and click
- Configure static routes from the Hillstone firewall to the Huawei Cloud VPC.
In this example, the Hillstone firewall communicates with the Huawei Cloud VPC through two tunnels, and the Huawei Cloud VPC has two subnets. As such, you need to configure four static routes, as shown in Figure 9.
Static routes 3 and 4 have the same destination addresses as static routes 1 and 2, respectively, but have lower priorities. In this way, static routes 3 and 4 are inactive after being configured.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot