Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- HUB
- config system interface
- edit "wan1"
- set vdom "root"
- set ip 192.168.1.201 255.255.255.0
- set allowaccess ping
- next
- edit "internal2"
- set vdom "root"
- set ip 192.168.2.201 255.255.255.0
- set allowaccess ping
- next
- edit "lo.BGP"
- set vdom "root"
- set ip 172.16.32.254 255.255.255.255
- set allowaccess ping
- next
- edit "lo.HC"
- set vdom "root"
- set ip 10.10.100.1 255.255.255.0
- set allowaccess ping
- set type loopback
- next
- end
- config vpn ipsec phase1-interface
- edit "ISP1"
- set type dynamic
- set interface "wan1"
- set ike-version 2
- set peertype any
- set net-device disable
- set exchange-ip-addr4 172.16.32.254
- set proposal aes256-sha256
- set add-route disable
- set dpd on-idle
- set dhgrp 21
- set auto-discovery-sender enable
- set network-overlay enable
- set network-id 1
- set psksecret ENC sSsg8ojzOY6Tl4YtCfLs/uuALOV9r/ZQ3WC047vpuFdhi8Ou230UfwfeUw+LRAMrWzlobOpcEzJHxSMgn8y/fsyzcBoxct1Cvib3PZ9KH8qRdRcOMcvWxZZvmRoLhUDSa5TyrL16Lyd/EnJ6NVNR6pcPF8J7LFI41kjR+Cg4rOZyPl6autXb7o2GvqNut82iULZWL1lmMjY3dkVA
- set dpd-retryinterval 5
- next
- edit "ISP2"
- set type dynamic
- set interface "internal2"
- set ike-version 2
- set peertype any
- set net-device disable
- set exchange-ip-addr4 172.16.32.254
- set proposal aes256-sha256
- set add-route disable
- set dpd on-idle
- set dhgrp 21
- set auto-discovery-sender enable
- set network-overlay enable
- set network-id 2
- set psksecret ENC 8Nt7m6hCNAUKdUdvXpYBWJiKFj5buf6tCfdZh0IuVtvOpge2jzkOvpDfOnb0Az5/1K8b9b7UzhZ/U7o+PQjYpi5npYq0wPvDJ8dRM3cMgFccgcJlc6fDsCFmd7z3wofc7bziAc7EYy/wDwfMn10siPOUdb3nxZjcDB42EGdIznZfZbayPNxaKsMrvXNcnMwGiyjVEVlmMjY3dkVA
- set dpd-retryinterval 5
- next
- end
- config vpn ipsec phase2-interface
- edit "ISP1"
- set phase1name "ISP1"
- set proposal aes256-sha256
- set dhgrp 21
- set keepalive enable
- next
- edit "ISP2"
- set phase1name "ISP2"
- set proposal aes256-sha256
- set dhgrp 21
- set keepalive enable
- next
- end
- config router bgp
- set as 65001
- set router-id 172.16.32.254
- set recursive-next-hop enable
- set recursive-inherit-priority enable
- config neighbor-group
- edit "SPOKES"
- set capability-graceful-restart enable
- set soft-reconfiguration enable
- set remote-as 65001
- set update-source "lo.BGP"
- set route-reflector-client enable
- next
- end
- config neighbor-range
- edit 0
- set prefix 172.16.32.0 255.255.255.0
- set neighbor-group "SPOKES"
- next
- end
- config network
- edit 0
- set prefix 10.10.100.0 255.255.255.0
- next
- edit 0
- set prefix 172.16.32.0 255.255.255.0
- next
- end
- end
- config system sdwan
- set status enable
- config zone
- edit "ADVPN"
- next
- end
- config members
- edit 0
- set interface "ISP1"
- set zone "ADVPN"
- next
- edit 0
- set interface "ISP2"
- set zone "ADVPN"
- next
- end
- edit "EMB_1"
- set detect-mode remote
- set probe-timeout 60000
- set recoverytime 1
- set sla-id-redistribute 1
- set members 1 2
- config sla
- edit 0
- set link-cost-factor packet-loss
- set packetloss-threshold 1
- set priority-in-sla 10
- set priority-out-sla 25
- next
- end
- next
- end
- end
- config firewall policy
- edit 0
- set name "ADVPN 2 LO"
- set srcintf "ADVPN"
- set dstintf "lo.HC" "lo.BGP"
- set action accept
- set srcaddr "all"
- set dstaddr "all"
- set schedule "always"
- set service "BGP" "PING"
- set logtraffic all
- next
- edit 0
- set name "ADVPN 2 ADVPN"
- set srcintf "ADVPN"
- set dstintf "ADVPN"
- set action accept
- set srcaddr "all"
- set dstaddr "all"
- set schedule "always"
- set service "ALL"
- set logtraffic all
- next
- end
- SPOKE
- config system interface
- edit "wan1"
- set vdom "root"
- set ip 192.168.1.200 255.255.255.0
- set allowaccess ping
- next
- edit "internal2"
- set vdom "root"
- set ip 192.168.2.200 255.255.255.0
- set allowaccess ping
- next
- edit "lo.BGP"
- set vdom "root"
- set ip 172.16.32.1 255.255.255.255
- set allowaccess ping
- next
- end
- config vpn ipsec phase1-interface
- edit "ISP1"
- set interface "wan1"
- set ike-version 2
- set peertype any
- set net-device enable
- set exchange-ip-addr4 172.16.32.1
- set proposal aes256-sha256
- set add-route disable
- set dhgrp 21
- set idle-timeout enable
- set idle-timeoutinterval 5
- set auto-discovery-receiver enable
- set network-overlay enable
- set network-id 1
- set remote-gw 192.168.1.201
- set psksecret ENC hSmPpgQ4VZq7nJh3EtLTsHuKUZkjtPNnXXl0w+DpSZgSABOmWWOJNDtG1s8rlwLYT+PuGT8AOX4qRcKqrlN582yhaEDLjJHwp2aIPthN+REwbQLkC4pjFgroTXNVnhBrppzyQP7SILmdWTDjUHc0nqfhczJ2f1AyLtCDFat3nJtKROvjggorrQdZrFp4dAVB8c8wqVlmMjY3dkVA
- set dpd-retryinterval 5
- next
- edit "ISP2"
- set interface "internal2"
- set ike-version 2
- set peertype any
- set net-device enable
- set exchange-ip-addr4 172.16.32.1
- set proposal aes256-sha256
- set add-route disable
- set dhgrp 21
- set idle-timeout enable
- set idle-timeoutinterval 5
- set auto-discovery-receiver enable
- set network-overlay enable
- set network-id 2
- set remote-gw 192.168.2.201
- set psksecret ENC d52XDkkYdMPaJce1gs/IaZ6NnDgOsJtGAaiQHy6ZvYas+19Zp3ivt9omAWTDhcBP3FbJYEzYJm75h1JwwfLPpHXxYfUJt/nS+a72Sv8F9PUvSrrWghB7XRdzT1iZC0OWC1C9we0kLO9e5UHISpYRF3c/EsRD6T0uw/KXBu4OwSt0/8drCiIjWfSpulceR3XPCHk3P1lmMjY3dkVA
- set dpd-retryinterval 5
- next
- end
- config vpn ipsec phase2-interface
- edit "ISP1"
- set phase1name "ISP1"
- set proposal aes256-sha256
- set dhgrp 21
- set auto-negotiate enable
- next
- edit "ISP2"
- set phase1name "ISP2"
- set proposal aes256-sha256
- set dhgrp 21
- set auto-negotiate enable
- next
- end
- config router bgp
- set as 65001
- set router-id 172.16.32.1
- set recursive-next-hop enable
- config neighbor
- edit "172.16.32.254"
- set advertisement-interval 5
- set capability-graceful-restart enable
- set soft-reconfiguration enable
- set interface "lo.BGP"
- set remote-as 65001
- set update-source "lo.BGP"
- next
- end
- config network
- edit 0
- set prefix 100.100.100.0 255.255.255.0
- next
- edit 0
- set prefix 10.10.1.0 255.255.255.0
- next
- end
- end
- config system sdwan
- set status enable
- config zone
- edit "ADVPN"
- set advpn-select enable
- set advpn-health-check "HUB_HC"
- next
- end
- config members
- edit 0
- set interface "ISP1"
- set zone "ADVPN"
- set cost 100
- set transport-group 1
- next
- edit 0
- set interface "ISP2"
- set zone "ADVPN"
- set transport-group 2
- next
- end
- config health-check
- edit "HUB_HC"
- set server "10.10.100.1"
- set update-static-route disable
- set embed-measured-health enable
- set source 172.16.32.1
- set members 1 2
- config sla
- edit 0
- set link-cost-factor packet-loss
- set packetloss-threshold 1
- next
- end
- next
- end
- config service
- edit 0
- set name "ADVPN20"
- set mode sla
- set shortcut-priority enable
- set dst "all"
- set src "all"
- config sla
- edit "HUB_HC"
- set id 1
- next
- end
- set priority-members 1 2
- next
- end
- end
- config firewall policy
- edit 0
- set name "ADVPN INBOUND"
- set srcintf "internal1"
- set dstintf "ADVPN"
- set action accept
- set srcaddr "all"
- set dstaddr "all"
- set schedule "always"
- set service "ALL"
- set logtraffic all
- next
- edit 0
- set name "ADVPN OUTBOUND"
- set srcintf "ADVPN"
- set dstintf "internal1"
- set action accept
- set srcaddr "all"
- set dstaddr "all"
- set schedule "always"
- set service "ALL"
- set logtraffic all
- next
- edit 0
- set name "ADVPN HC"
- set srcintf "ADVPN"
- set dstintf "lo.BGP"
- set action accept
- set srcaddr "all"
- set dstaddr "all"
- set schedule "always"
- set service "PING"
- set logtraffic all
- next
- end
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement