<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>All_about_network &#187; IPSec</title>
	<atom:link href="http://www.kuncar.net/blog/tag/ipsec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kuncar.net/blog</link>
	<description></description>
	<lastBuildDate>Wed, 12 May 2010 00:09:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>IPSec general principles overwiev</title>
		<link>http://www.kuncar.net/blog/ipsec-general-principles-overwiev/2009/</link>
		<comments>http://www.kuncar.net/blog/ipsec-general-principles-overwiev/2009/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 15:10:39 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security Links]]></category>
		<category><![CDATA[IPSec]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=336</guid>
		<description><![CDATA[Hi this article is an output of my long &#8211; term digging around security stuff (and by that I mean especially a lot of IPSec things). After months I kept returning for some resources I cannot find anymore I decided to write quick but (hopefully) comprehensive overview of this technology and most if the things [...]]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/ipsec-general-principles-overwiev/2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>l2tp over IPSec scenario</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/</link>
		<comments>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/#comments</comments>
		<pubDate>Sat, 09 May 2009 23:59:14 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security Links]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[L2tp]]></category>
		<category><![CDATA[vrp 3.40]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77</guid>
		<description><![CDATA[So this is the long promised scenario that can be used with windows XP (even though it is not really user friendly). If you need a &#8220;PC-client &#8211; VPN-concentrator&#8221; scenario. Huawei does offer only one-way ticket for you and it is l2tp over IPSec. Unless you want to use some MPLS over IPSec which is [...]]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Some GRE/IPSec and basic QoS scenarios on AR 19-X and VRP 5.20 Part II.</title>
		<link>http://www.kuncar.net/blog/some-greipsec-and-basic-qos-scenarios-on-ar-19-x-and-vrp-520-part-ii/2009/</link>
		<comments>http://www.kuncar.net/blog/some-greipsec-and-basic-qos-scenarios-on-ar-19-x-and-vrp-520-part-ii/2009/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 16:51:17 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[adsl]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[marking]]></category>
		<category><![CDATA[pppoe]]></category>
		<category><![CDATA[QoS]]></category>
		<category><![CDATA[shaping]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=52</guid>
		<description><![CDATA[<img class="alignleft size-thumbnail wp-image-118" title="Huawei Logo" src="http://www.kuncar.net/blog/wp-content/uploads/2009/03/huawei_logo_001-150x150.jpg" alt="Huawei Logo" width="120" height="120" />

So after previous post the whole setup should be working. But there are some things to be done yet. The heading says that the missing part is the QoS. So let's have a closer look.

Step one is easy - just create some ACLs to match the traffic in our case it is goes like this:
#
acl number 3001 name black
rule]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/some-greipsec-and-basic-qos-scenarios-on-ar-19-x-and-vrp-520-part-ii/2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Troubleshooting IPSec on Huawei routers</title>
		<link>http://www.kuncar.net/blog/troubleshooting-ipsec-on-huawei-routers/2009/</link>
		<comments>http://www.kuncar.net/blog/troubleshooting-ipsec-on-huawei-routers/2009/#comments</comments>
		<pubDate>Sun, 11 Jan 2009 00:23:07 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[ike]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[troubleshooting]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=62</guid>
		<description><![CDATA[<img class="alignleft size-thumbnail wp-image-118" title="Huawei Logo" src="http://www.kuncar.net/blog/wp-content/uploads/2009/03/huawei_logo_001-150x150.jpg" alt="Huawei Logo" width="120" height="120" />Ok so in my previous posts I described the most common config of IPsec with IKE. For troubleshooting this config there are few simple things one should check for basic troubleshoot.

No. 1 Check display IKE sa command in user view

Output of this command should show you two IKE entries. It is necessary to be two because if there is]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/troubleshooting-ipsec-on-huawei-routers/2009/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Some GRE/IPSec and basic QoS scenarios on AR 19-X and VRP 5.20 Part I.</title>
		<link>http://www.kuncar.net/blog/some-gre-ipsec-and-basic-qos-ar-19-x-and-vrp-520-part-i/2008/</link>
		<comments>http://www.kuncar.net/blog/some-gre-ipsec-and-basic-qos-ar-19-x-and-vrp-520-part-i/2008/#comments</comments>
		<pubDate>Thu, 25 Dec 2008 02:21:29 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[adsl]]></category>
		<category><![CDATA[AR-19-1X]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[GRE]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[pap]]></category>
		<category><![CDATA[pppoe]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[VRP-5.20]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=44</guid>
		<description><![CDATA[<img class="alignright size-thumbnail wp-image-118" title="Huawei Logo" src="http://www.kuncar.net/blog/wp-content/uploads/2009/03/huawei_logo_001-150x150.jpg" alt="Huawei Logo" width="120" height="120" /> As I promised there goes some stuff I was having fun with lately. Followingscenario is from real life and includes some interesting combinations of features.

The problem is stated as follows:
<ol>
	<li>AR 19-X is a CPE that is connected to ADSL (SHDSL) line of ISP</li>
	<li>You need to use GRE tunnel for transporting L3 multicast (especially for OSPF) and IPSec for</li></ol>]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/some-gre-ipsec-and-basic-qos-ar-19-x-and-vrp-520-part-i/2008/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>IPSec troubles Part II</title>
		<link>http://www.kuncar.net/blog/ipsec-troubles-part-ii/2008/</link>
		<comments>http://www.kuncar.net/blog/ipsec-troubles-part-ii/2008/#comments</comments>
		<pubDate>Mon, 02 Jun 2008 20:47:28 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[L2tp]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=9</guid>
		<description><![CDATA[<img class="alignleft size-thumbnail wp-image-118" title="Huawei Logo" src="http://www.kuncar.net/blog/wp-content/uploads/2009/03/huawei_logo_001-150x150.jpg" alt="Huawei Logo" width="120" height="120" />Ok so from the previous post is clear how to make one tunnel using IPSec, IKE and isakmp.

So what if the situation is that you need multiple tunnels on one ip interface.

There is a limitation of one IPSec policy being applied on particular interface at one time so it is impossible to use more various policies. But there is a workaround -]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/ipsec-troubles-part-ii/2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPSec troubles part I</title>
		<link>http://www.kuncar.net/blog/ipsec-troubles-part-i/2008/</link>
		<comments>http://www.kuncar.net/blog/ipsec-troubles-part-i/2008/#comments</comments>
		<pubDate>Wed, 14 May 2008 18:09:06 +0000</pubDate>
		<dc:creator>tnk</dc:creator>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[IPSec]]></category>

		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=7</guid>
		<description><![CDATA[So I am playing with IPsec Tunnels on Huawei's AR28-31 it is really interesting in may ways.

I have two basic scenarios:
<ol>
	<li> tunnel between two peers that are stable (two routers)</li>
	<li> tunnel utilizing the "client-server" where only router has a stable public IP and clients are some PC's</li>
</ol>
Of course I do realize that in IPSec there are no  clients and server but just a peers on the same level, but I]]></description>
		<wfw:commentRss>http://www.kuncar.net/blog/ipsec-troubles-part-i/2008/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
