Open zxwing opened 7 years ago
Automation cases created. Total 38 cases for the parameters. Here is the link of cases https://github.com/zstackio/zstack-woodpecker/tree/master/integrationtest/vm/virtualrouter/ipsec
根据https://github.com/zstackio/issues/issues/2558中@HeathHose 的调查结果,ikdDhGroup的取值范围应该与pfs对应的,故应该修改为如下值。
ikeDhGroup IKE dh group(Diffie Hellman Groups),整形值,可选值为2,5,14,,15,16,17,18,19,20,21,22,23,24,25,26,默认为2
描述
创建IPsec site-to-site VPN链接
site-to-site VPN用于连接两个私有网络,上图中192.168.1.0/24和92.168.3.0/24是两个私有网络,他们通过64.49.246.101和198.61.180.101两个公网IP连接。
API
org.zstack.ipsec.APICreateIPsecConnectionMsg
举例(Example)
返回结果:
参数(Parameters)
IPsec site-to-site用于连接本地网络和远端网络,在下面的描述中,我们将用户在ZStack创建的相关网络资源称为本地网络资源,将要链接的网络及相关资源称为远端网络资源。
psk
和certs
两种方式。1.8版本只支持psk模式psk
psk
,该字段为一个用作密码的字符串10.10.0.0/24
md5
,sha1
,sha256
,sha384
,sha512
sha1
3des
,aes-128
,aes-192
,aes-256
; NOTE:如果网络服务提供者为Vyos,则aes-192算法不支持aes-128
md5
,sha1
,sha256
,sha384
,sha512
sha
3des
,aes-128
,aes-192
,aes-256
;NOTE:如果网络服务提供者为Vyos,则aes-192算法不支持aes-128
dh-group2
,dh-group5
,dh-group14
,dh-group15
,dh-group16
,dh-group17
,dh-group18
,dh-group19
,dh-group20
,dh-group21
,dh-group22
,dh-group23
,dh-group24
,dh-group25
,dh-group26
,或不设置tunnel
和transport
。1.8只支持tunnel
tunnel
esp
,ah
, 1.8只支持esp
esp
备注
Feature_link
Configure a Site-to-site VPN using the Vyatta Network Appliance AH and ESP protocols