=====================sm3 + cbc(des3_ede) ============================ PC1: //192.168.0.1 ip xfrm state add src 192.168.0.1 dst 192.168.0.2 proto esp spi 0x00000301 mode tunnel auth sm3 0x96358c90783bbfa3d7b196ceabe0536b enc sm4 0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965df ip xfrm state add src 192.168.0.2 dst 192.168.0.1 proto esp spi 0x00000302 mode tunnel auth sm3 0x99358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xffddb555acfd9d77b03ea3843f2653255afe8eb5573965df
ip xfrm policy add src 192.168.0.1 dst 192.168.0.2 dir out ptype main tmpl src 192.168.0.1 dst 192.168.0.2 proto esp mode tunnel ip xfrm policy add src 192.168.0.2 dst 192.168.0.1 dir in ptype main tmpl src 192.168.0.2 dst 192.168.0.1 proto esp mode tunnel
PC2:// 192.168.0.2 ip xfrm state add src 192.168.0.1 dst 192.168.0.2 proto esp spi 0x00000301 mode tunnel auth sm3 0x96358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965df ip xfrm state add src 192.168.0.2 dst 192.168.0.1 proto esp spi 0x00000302 mode tunnel auth sm3 0x99358c90783bbfa3d7b196ceabe0536b enc des3_ede 0xffddb555acfd9d77b03ea3843f2653255afe8eb5573965df
ip xfrm policy add src 192.168.0.1 dst 192.168.0.2 dir in ptype main tmpl src 192.168.0.1 dst 192.168.0.2 proto esp mode tunnel ip xfrm policy add src 192.168.0.2 dst 192.168.0.1 dir out ptype main tmpl src 192.168.0.2 dst 192.168.0.1 proto esp mode tunnel # 删除xfrm配置的命令 ip xfrm state deleteall ip xfrm policy deleteall
iperf3 -c 192.168.0.2 -u -i 10 -t 20 -b 300M -l 1024 # 查看配置 ip xfrm state ip xfrm policy
PC1: //192.168.0.1 ip xfrm state add src 192.168.0.1 dst 192.168.0.2 proto esp spi 0x00000301 mode tunnel auth sm3 0x96358c90783bbfa3d7b196ceabe0536b enc sm4 0xf6ddb555acfd9d77b03ea3843f265325 ip xfrm state add src 192.168.0.2 dst 192.168.0.1 proto esp spi 0x00000302 mode tunnel auth sm3 0x99358c90783bbfa3d7b196ceabe0536b enc sm4 0xffddb555acfd9d77b03ea3843f265325
ip xfrm policy add src 192.168.0.1 dst 192.168.0.2 dir out ptype main tmpl src 192.168.0.1 dst 192.168.0.2 proto esp mode tunnel ip xfrm policy add src 192.168.0.2 dst 192.168.0.1 dir in ptype main tmpl src 192.168.0.2 dst 192.168.0.1 proto esp mode tunnel
PC2:// 192.168.0.2 ip xfrm state add src 192.168.0.1 dst 192.168.0.2 proto esp spi 0x00000301 mode tunnel auth sm3 0x96358c90783bbfa3d7b196ceabe0536b enc sm4 0xf6ddb555acfd9d77b03ea3843f265325 ip xfrm state add src 192.168.0.2 dst 192.168.0.1 proto esp spi 0x00000302 mode tunnel auth sm3 0x99358c90783bbfa3d7b196ceabe0536b enc sm4 0xffddb555acfd9d77b03ea3843f265325
ip xfrm policy add src 192.168.0.1 dst 192.168.0.2 dir in ptype main tmpl src 192.168.0.1 dst 192.168.0.2 proto esp mode tunnel ip xfrm policy add src 192.168.0.2 dst 192.168.0.1 dir out ptype main tmpl src 192.168.0.2 dst 192.168.0.1 proto esp mode tunnel # 删除xfrm配置的命令 ip xfrm state deleteall ip xfrm policy deleteall