外面电脑安装inode,设置好后可以连上l2tp vpn,但是结合ipsec 就提示IKE协商失败
防火墙配置: ike local-name huizhou
#
domain default enable system
#
domain system
authentication ppp local
access-limit disable
state active
idle-cut disable
self-service-url disable
ip pool 1 10.10.111.100 10.10.111.150
#
ike peer inode
exchange-mode aggressive
pre-shared-key cipher xz8n+yXxN+I=
id-type name
remote-name szkbpcb01
nat traversal
dpd 1
#
ipsec policy-template for_inode 1
ike-peer inode
proposal 1
#
ipsec policy inode 1 isakmp template for_inode
#
local-user l2tp
password cipher R7-C#Y\M+=OQ=^Q`MAF4<1!!
service-type ppp
#
l2tp-group 1
mandatory-chap
undo tunnel authentication
mandatory-lcp
allow l2tp virtual-template 1
#
interface Virtual-Template1
ppp authentication-mode chap domain system
ppp ipcp dns 8.8.8.8
remote address pool 1
ip address 10.10.111.1 255.255.255.0
#
interface GigabitEthernet0/3
port link-mode route
description this port is link to China Mobile's Fiber Converter
nat outbound 3003
ipsec policy inode
客户端inode拨号设置查看附加5个截图
出口防火墙U200-M担任LNS,外面PC用inode通过l2tp拨入
最佳答案
设备上dis ike sa的状态是什么 inode的报错
nat的acl先把1701的流量拒绝掉
(0)
[U200-M]dis ike sa total phase-1 SAs: 2 connection-id peer flag phase doi ---------------------------------------------------------- 43938 <unnamed> NONE 1 IPSEC
nat的acl先把1701的流量拒绝掉;ike的配置参数看着都正常
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
nat的acl先把1701的流量拒绝掉;ike的配置参数看着都正常