Topology

Untitled

Basic Configuration

FW1

R1-FG1101E # show vpn ipsec phase1-interface ToR2
config vpn ipsec phase1-interface
    edit "ToR2"
        set type dynamic
        set interface "port16"
        set peertype any
        set net-device disable
        set proposal aes128-sha256
        set **ip-fragmentation pre-encapsulation**
        set dpd on-idle
        set psksecret ENC ttVqkpX/2tOX2sIjIHjVVulGhE/F6wAy3C9+i7Kni9OiE6i8UWaPcuHTUJSElS4EDQMdnWDlo8pvrTWvKfly8SisLvAaPqZit3F0xVuR9Hv0ESir0ZdW+HrVonBr4uAWXgBKSWVHSVN1dm5EV2enmYrz0GN05DednWpe3lx9UWLw9rWcnQxLgUeF31G9kyQ9GGCF0A==
    next
end
R1-FG1101E # show vpn ipsec phase2-interface ToR2 
config vpn ipsec phase2-interface
    edit "ToR2"
        set phase1name "ToR2"
        set proposal **aes256-sha256**
    next
end

FW2

R2-FG1101E # show vpn ipsec phase1-interface ToR1
config vpn ipsec phase1-interface
    edit "ToR1"
        set interface "port16"
        set peertype any
        set net-device disable
        set exchange-interface-ip enable
        set proposal aes128-sha256
        set **ip-fragmentation pre-encapsulation**
        set dpd disable
        set remote-gw 100.0.0.2
        set psksecret ENC Lv4Etajj6H2abp3coiBKezA+1aP7epa+KIUb6TpVECqC/MO8vweHdqW4mTfE+PJnm3xmywcheaxr7r/jNRimIuRbripGvAdvk9V8ezgTsInYXXWmmt1+twvGPPxfCKUxGHHJHVgozsun3uH5TMDmMwmgRkWL0sq7YR+Zv5lyrDhi7XZcJdioL60aa3RCqNyzc+hZYw==
    next
end
R2-FG1101E # show vpn ipsec phase2-interface ToR1 
config vpn ipsec phase2-interface
    edit "ToR1"
        set phase1name "ToR1"
        set proposal **aes256-sha256**
        set auto-negotiate enable
        set src-subnet 10.1.87.0 255.255.255.0
        set dst-subnet 10.0.86.0 255.255.255.0
    next
end

Test Steps

  1. IPSec VPN隧道建立成功后,我们先来看下两端设备计算出的Tunnel SA/Tunnel Interface的MTU。
  1. 首先验证下在Tunnel MTU极限值的情况下,是否会产生分片。目前Tunnel Interface MTU为1438,也就是说被加密原始明文最大为1438 Bytes(不包含任何ESP封装)。我们使用PC1 Ping PC2来测试,datasize = 1438 - 20(Original IP Header) - 8(ICMP Header) = 1410

    [root@CentOS-1 ~]# ping 10.1.87.222  **-s 1410** -c 1 -M dont
    PING 10.1.87.222 (10.1.87.222) 1410(**1438**) bytes of data.
    1418 bytes from 10.1.87.222: icmp_seq=1 ttl=62 time=1.24 ms
    --- 10.1.87.222 ping statistics ---
    1 packets transmitted, 1 received, 0% packet loss, time 0ms
    rtt min/avg/max/mdev = 1.245/1.245/1.245/0.000 ms
    
  2. 关闭Router (R1-FG601E)的芯片加速功能,同时在Router上抓取4和6格式的ESP报文。