!
! Century Systems NXR-530 Series ver 21.11.9D (build 2/11:40 14 06 2022)
!
hostname NXR_B
telnet-server enable
telnet-server ip forbidden-access-wan
telnet-server ipv6 forbidden-access-wan
http-server enable
http-server ip forbidden-access-wan
http-server ipv6 forbidden-access-wan
no rest http enable
no rest https enable
!
!
!
!
!
ipv6 forwarding
fast-forwarding enable
!
!
!
!
!
ipsec rsa-sig-key length 1024
!
l2tp udp source-port 40001
!
!
ipsec local policy 1
 address ip
 self-identity fqdn NXRB
!
!
ipsec isakmp policy 1
 description NXR_A
 authentication rsa-sig [NXR_AのRSA公開鍵情報]
 hash sha256
 encryption aes128
 group 5
 lifetime 86400
 isakmp-mode main
 remote address ip 203.0.113.1
 remote identity fqdn NXRA
 local policy 1
!
!
ipsec tunnel policy 1
 description NXR_A
 set transform esp-aes128 esp-sha256-hmac
 set pfs group5
 set key-exchange isakmp 1
 set sa lifetime 28800
 match address IPsec_ACL
!
!
interface ethernet 0
 ip address 192.168.20.1/24
!
interface ethernet 1
 ip address 203.0.113.5/30
 ipsec policy 1
!
interface ethernet 2
 no ip address
!
dns
 service enable
!
!
syslog
 local enable
 exit-syslog
!
!
!
system led ext 0 signal-level mobile 0
!
!
!
!
!
!
!
ip route 203.0.113.1/32 203.0.113.6
!
!
!
ipsec access-list IPsec_ACL ip 192.168.20.0/24 192.168.10.0/24
!
!
!
end