华为 AR 路由器原生 IPsec VPN 接入指南 (推荐)
本教程适用于合作公司在办公室主路由器(华为 AR 系列企业路由器,如 AR650、AR1200、AR2200、AR3200 系列)上配置原生 IKEv2 IPsec VPN 专线接入。
配置完成后:
- 全内网统一生效:办公室内任意电脑、手机(插网线或连 Wi-Fi),访问快手、创梦天地等特殊业务网站全自动走奥诚云信专线 IP(
220.248.113.34); - 日常办公无感知走本地宽带:员工访问百度、微信、腾讯会议依然走本地高速宽带;
- 💥 硬件级断网保护 (Kill Switch):专线故障时自动丢弃特殊业务请求,绝不回退本地宽带。
接入核心参数
在开始配置前,请向管理员获取分配给贵司的专属对接参数(以 tenant-001 为例):
| 参数项 | 参数值 | 说明 |
|---|---|---|
| 专线网关地址 (Remote Gateway) | 220.248.113.34 (或 shvpn.chengyo.top) | 端口 UDP 500 / 4500 |
| VPN 协议类型 | 原生 IPsec VPN (IKEv2) | 隧道模式 (Tunnel Mode) |
| 对端身份标识 (Remote ID) | shvpn.chengyo.top | 我方服务端标识 |
| 本地身份标识 (Local ID) | 联系管理员获取(如 tenant-001) | 贵司路由器租户标识 |
| 预共享密钥 (PSK) | 联系管理员获取专属密码 | 身份验证密钥 |
| IKE 提议 (Phase 1) | AES-256 / SHA-256 / DH Group 14 (MODP2048) | 兼容 DH 5 / DH 2 |
| IPsec 提议 (Phase 2) | AES-256 / SHA-256 | 支持 ESP 封装 |
| 隧道虚拟互联地址 (贵司) | 10.250.1.2/30 | 贵司分配的隧道 IP |
| DPD 存活检测 | 开启,间隔 30 秒 | 快速感知链路状态 |
| 固定出口 IP | 220.248.113.34 | 上海联通固定公网 IP |
华为 AR 命令行 (CLI) 极速粘贴配置
通过 SSH 或 Console 登录华为 AR 路由器,复制以下经过严格验证的命令粘贴执行:
system-view
# 1. 配置 IKEv2 提议与 Peer
ike proposal 1
encryption-algorithm aes-cbc-256
integrity-algorithm hmac-sha2-256
dh group14
prf hmac-sha2-256
quit
ike peer PEER_CHENGYO v2
pre-shared-key cipher ChengYoTenant001SecureKey2026_Rx9
ike-proposal 1
remote-id-type fqdn
remote-id shvpn.chengyo.top
local-id-type fqdn
local-id tenant-001
remote-address 220.248.113.34
dpd type periodic
dpd interval 30
dpd timeout 120
nat-traversal
quit
# 2. 配置 IPsec 安全提议与 Profile
ipsec proposal PROP_CHENGYO
esp encryption-algorithm aes-256
esp authentication-algorithm sha2-256
quit
ipsec profile PROF_CHENGYO
ike-peer PEER_CHENGYO
proposal PROP_CHENGYO
quit
# 3. 创建 Route-based 虚接口 (Tunnel 0/0/1)
interface Tunnel 0/0/1
description ChengYo_Native_IPsec_Tunnel
ip address 10.250.1.2 255.255.255.252
tunnel-protocol ipsec
source GigabitEthernet0/0/1
destination 220.248.113.34
ipsec profile PROF_CHENGYO
tcp adjust-mss 1380
quit
# 4. 定义特殊业务目标 IP ACL
acl number 3000
description Match_ChengYo_Special_Sites
rule 5 permit ip destination 104.218.235.243 0
rule 10 permit ip destination 103.102.202.0 0.0.0.255
rule 15 permit ip destination 103.107.216.0 0.0.3.255
rule 20 permit ip destination 111.13.141.0 0.0.0.255
quit
# 5. 配置 MQC 流策略定向重定向至专线
traffic classifier TC_SPECIAL operator or
if-match acl 3000
quit
traffic behavior TB_SPECIAL
redirect interface Tunnel 0/0/1
quit
traffic policy TP_CHENGYO
classifier TC_SPECIAL behavior TB_SPECIAL
quit
# 挂载至内网 LAN 口 (例如 GigabitEthernet0/0/2)
interface GigabitEthernet0/0/2
traffic-policy TP_CHENGYO inbound
quit
# 6. 【Kill Switch 物理 WAN 出口阻断】
acl number 3001
description Kill_Switch_Block_WAN
rule 5 deny ip destination 104.218.235.243 0
rule 10 deny ip destination 103.102.202.0 0.0.0.255
rule 15 deny ip destination 103.107.216.0 0.0.3.255
rule 20 deny ip destination 111.13.141.0 0.0.0.255
rule 999 permit ip
quit
interface GigabitEthernet0/0/1
traffic-filter outbound acl 3001
quit
return
save
y
状态检查命令
# 检查 IKE SA 建立状态
display ike sa
# 检查 IPsec SA 简报与流量统计
display ipsec sa brief
display interface Tunnel 0/0/1