.H3C F100-S-G案例:点对点ipsec总部一台F100-S-G,分部一台F100-S-G。总部内网网段10.10.10.0/24,10.0.0.0/24两端外网口为固定地址F100-S-G-分部配置:#acl number 3001 用于匹配IPSEC 保护流 description Protect-Vpndata rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 10.10.10.0 0.0.0.255 rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 10.0.0.0 0.0.0.255 rule 10 permit ip source 192.168.2.0 0.0.0.255 destination 10.0.0.0 0.0.0.255 rule 15 permit ip source 192.168.2.0 0.0.0.255 de