跳到主要内容

华为 AR 路由器原生 IPsec VPN 接入指南 (推荐)

本教程适用于合作公司在办公室主路由器(华为 AR 系列企业路由器,如 AR650、AR1200、AR2200、AR3200 系列)上配置原生 IKEv2 IPsec VPN 专线接入。

配置完成后:

  • 全内网统一生效:办公室内任意电脑、手机(插网线或连 Wi-Fi),访问快手、创梦天地等特殊业务网站全自动走奥诚云信专线 IP(220.248.113.34);
  • 日常办公无感知走本地宽带:员工访问百度、微信、腾讯会议依然走本地高速宽带;
  • 💥 硬件级断网保护 (Kill Switch):专线故障时自动丢弃特殊业务请求,绝不回退本地宽带。

接入核心参数​

在开始配置前,请向管理员获取分配给贵司的专属对接参数(以 tenant-001 为例):

参数项参数值说明
专线网关地址 (Remote Gateway)220.248.113.34 (或 shvpn.chengyo.top)端口 UDP 500 / 4500
VPN 协议类型原生 IPsec VPN (IKEv2)隧道模式 (Tunnel Mode)
对端身份标识 (Remote ID)shvpn.chengyo.top我方服务端标识
本地身份标识 (Local ID)联系管理员获取(如 tenant-001)贵司路由器租户标识
预共享密钥 (PSK)联系管理员获取专属密码身份验证密钥
IKE 提议 (Phase 1)AES-256 / SHA-256 / DH Group 14 (MODP2048)兼容 DH 5 / DH 2
IPsec 提议 (Phase 2)AES-256 / SHA-256支持 ESP 封装
隧道虚拟互联地址 (贵司)10.250.1.2/30贵司分配的隧道 IP
DPD 存活检测开启,间隔 30 秒快速感知链路状态
固定出口 IP220.248.113.34上海联通固定公网 IP

华为 AR 命令行 (CLI) 极速粘贴配置​

通过 SSH 或 Console 登录华为 AR 路由器,复制以下经过严格验证的命令粘贴执行:

system-view

# 1. 配置 IKEv2 提议与 Peer
ike proposal 1
encryption-algorithm aes-cbc-256
integrity-algorithm hmac-sha2-256
dh group14
prf hmac-sha2-256
quit

ike peer PEER_CHENGYO v2
pre-shared-key cipher ChengYoTenant001SecureKey2026_Rx9
ike-proposal 1
remote-id-type fqdn
remote-id shvpn.chengyo.top
local-id-type fqdn
local-id tenant-001
remote-address 220.248.113.34
dpd type periodic
dpd interval 30
dpd timeout 120
nat-traversal
quit

# 2. 配置 IPsec 安全提议与 Profile
ipsec proposal PROP_CHENGYO
esp encryption-algorithm aes-256
esp authentication-algorithm sha2-256
quit

ipsec profile PROF_CHENGYO
ike-peer PEER_CHENGYO
proposal PROP_CHENGYO
quit

# 3. 创建 Route-based 虚接口 (Tunnel 0/0/1)
interface Tunnel 0/0/1
description ChengYo_Native_IPsec_Tunnel
ip address 10.250.1.2 255.255.255.252
tunnel-protocol ipsec
source GigabitEthernet0/0/1
destination 220.248.113.34
ipsec profile PROF_CHENGYO
tcp adjust-mss 1380
quit

# 4. 定义特殊业务目标 IP ACL
acl number 3000
description Match_ChengYo_Special_Sites
rule 5 permit ip destination 104.218.235.243 0
rule 10 permit ip destination 103.102.202.0 0.0.0.255
rule 15 permit ip destination 103.107.216.0 0.0.3.255
rule 20 permit ip destination 111.13.141.0 0.0.0.255
quit

# 5. 配置 MQC 流策略定向重定向至专线
traffic classifier TC_SPECIAL operator or
if-match acl 3000
quit

traffic behavior TB_SPECIAL
redirect interface Tunnel 0/0/1
quit

traffic policy TP_CHENGYO
classifier TC_SPECIAL behavior TB_SPECIAL
quit

# 挂载至内网 LAN 口 (例如 GigabitEthernet0/0/2)
interface GigabitEthernet0/0/2
traffic-policy TP_CHENGYO inbound
quit

# 6. 【Kill Switch 物理 WAN 出口阻断】
acl number 3001
description Kill_Switch_Block_WAN
rule 5 deny ip destination 104.218.235.243 0
rule 10 deny ip destination 103.102.202.0 0.0.0.255
rule 15 deny ip destination 103.107.216.0 0.0.3.255
rule 20 deny ip destination 111.13.141.0 0.0.0.255
rule 999 permit ip
quit

interface GigabitEthernet0/0/1
traffic-filter outbound acl 3001
quit

return
save
y

状态检查命令​

# 检查 IKE SA 建立状态
display ike sa

# 检查 IPsec SA 简报与流量统计
display ipsec sa brief
display interface Tunnel 0/0/1