Configuration on the Hillstone Firewall
Prerequisites
The basic network configuration of the Hillstone firewall has been completed.
Procedure
- Log in to the configuration page.
A firewall running the 5.5R9 version is used as an example. The configuration pages may vary according to the firewall models and software versions.
- Complete basic settings.
- Configure a security zone.
Choose . Click New and set parameters, as shown in Figure 1.
- Configure a security policy.
Choose . Click New, choose Policy, and set parameters, as shown in Figure 2.
- Configure a basic route.
Choose . Click New and set parameters, as shown in Figure 3.
- Configure CIDR block information.
Choose . Click New, and configure CIDR block information of Huawei Cloud and the on-premises data center in sequence.
When configuring CIDR block information of the on-premises data center, exclude the gateway address of the downlink private network interface on the Hillstone firewall.
Figure 4 Configuring CIDR block information
- Configure a security zone.
- Configure VPN connections.
- Choose IPsec VPN tab page, click New. . On the
- Click the plus sign (+) in the Peer Name drop-down list box to add peer information.
- Click the plus sign (+) in the Proposal1 drop-down list box to create a phase-1 proposal. Set parameters and click OK. Figure 5 shows the key parameter settings.
- Configure VPN peers. As the Huawei Cloud VPN gateway has two EIPs bound, you need to configure two peers.
Select the phase-1 proposal created in c from the Proposal1 drop-down list box. Click Advanced Configuration, toggle on NAT Traversal and DPD, and click OK.Figure 6 Configuring VPN peers
- Click the plus sign (+) in the P2 Proposal drop-down list box to create a phase-2 proposal. Set parameters and click OK. Figure 7 shows the key parameter settings.
- Configure VPN connection information. Select each of the VPN peers created in d from the Peer Name drop-down list box, select the phase-2 proposal created in e from the P2 Proposal drop-down list box, select Manual for Proxy ID, configure Proxy ID List, and click OK. Figure 8 shows the key parameter settings.
- Configure VPN policies.
- Configure source network address translation (NAT) policies.
Choose . Click New, configure two source NAT policies, and set their priorities, as shown in Figure 9.
- Configure VPN security policies.
Choose . Click New and choose Policy. Configure two VPN security policies and set their priorities to be higher than that of the default security policy configured in b, as shown in Figure 10.
- Configure source network address translation (NAT) policies.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot