Configuration on the AR Router
Prerequisites
- The uplink public network interface GE0/0/8 of the AR router has been configured. Assume that the public IP address of the interface is 1.1.1.1.
- The downlink private network interface GE0/0/1 of the AR router has been configured. Assume that the private IP address of the interface is 172.16.0.1.
Procedure
- Log in to the web system of the AR router.
An AR651 running V300R019C13SPC200 is used as an example. The web system may vary according to the device model and software version.
- Complete basic settings.
Choose IPv4 Static Route area, configure static routes to the active EIP and active EIP 2 of the VPN gateway, and click Add, as shown in Figure 1.
. In the - Configure tunnel interfaces.
- Choose .
- Configure two tunnel interfaces and click Add.
Figure 2 shows the key parameter settings.
- Configure VPN connections.
- Choose .
- Configure the IKE and IPsec policies for the two tunnels, as shown in Figure 3 and Figure 4.
- When IKEv1 is used for IPsec negotiation, if the traffic hard lifetime is set to 0 on either device, both the local and remote devices disable the traffic timeout function.
- When IKEv2 is used for IPsec negotiation, if the traffic hard lifetime is set to 0 on a device, this device disables the traffic timeout function.
- Configure BGP.
- Choose .
- Toggle on Enable BGP, set AS Number to the BGP ASN of the AR router, set Router ID to the gateway address of the downlink private network interface on the AR router, and click Apply.
- Configure BGP peers, as shown in Figure 5.
- In the Route Import Configuration area, set Protocol type to Direct.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot