sslvpn具体排查思路,通过debug sllvpn all 的日志发现都是ssl协商报文,未发现客户端与网关交互日志,但是设备tcping与sslvpn设备可以互通,请问具体排查思路是什么?
*Oct 17 13:34:57:263 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: SSLv3/TLS write certificate.
*Oct 17 13:34:57:263 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Send: TLS 1.2Handshake [length 0004].
*Oct 17 13:34:57:263 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
16 03 03 00 04
*Oct 17 13:34:57:263 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Send: TLS 1.2 [length 0004], message type: ServerHelloDone.
*Oct 17 13:34:57:263 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
0e 00 00 00
*Oct 17 13:34:57:264 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: SSLv3/TLS write server done.
*Oct 17 13:34:57:264 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: error in SSLv3/TLS write server done.
*Oct 17 13:34:57:306 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Receive: TLS 1.2Handshake [length 0106].
*Oct 17 13:34:57:306 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
16 03 03 01 06
*Oct 17 13:34:57:306 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: SSLv3/TLS write server done.
*Oct 17 13:34:57:306 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Receive: TLS 1.2 [length 0106], message type: ClientKeyExchange.
*Oct 17 13:34:57:306 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
10 00 01 02 01 00 66 1b 9a ac
32 32 2d c3 16 d6 cf e5 f7 9f
7f 84 ce 33 e9 65 1e f2 10 f5
ec 5a 65 38 84 c8 95 0b fc 9e
95 58 88 5b 21 7c d3 1f 25 da
50 09 da ac 24 5d 6a 5d fc b9
a1 53 5b a1 7c 06 72 a0 c8 17
0a c4 eb 07 0d 69 8e c6 ca 20
a1 c9 66 78 e4 10 38 2a 3a 8d
b2 7d 2d 11 bb 11 58 5a 29 d2
31 2b 65 ac 84 8a 28 40 7b 96
38 f4 14 b8 46 01 d6 b2 40 b9
f6 c6 b6 91 52 ce 0e cd f6 a0
0e e2 c3 de ec 63 84 a5 75 ab
98 bb e6 fc 98 f9 b5 92 54 42
1c bf ba 28 c8 ad 6e e3 a8 93
79 11 ee 1b 81 8d 9b 1d a7 66
65 4e 8b d7 00 8d d3 a8 c2 49
23 77 a5 7d 35 c2 04 5d 61 66
b9 4a f1 3d 0d 59 6e c0 5d 6f
f3 de bb 6f 66 40 f5 40 49 f0
24 4f 4c 27 9f 11 0b 30 6e c0
84 c3 8c 1c 13 8a d7 04 50 cc
0c 65 c5 4a 54 6f a8 d0 0d 9d
47 28 5a 89 3f 70 70 35 63 a4
d5 a2 08 1f b6 5c 6b cf 14 2d
02 74
*Oct 17 13:34:57:307 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Receive: TLS 1.2ChangeCipherSpec [length 0001].
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
14 03 03 00 01
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: SSLv3/TLS read client key exchange.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Receive: TLS 1.2Handshake [length 0040].
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
16 03 03 00 40
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: SSLv3/TLS read change cipher spec.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer sent 40 cipher suites:
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 1: ECDHE-RSA-AES256-GCM-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 2: ECDHE-ECDSA-AES256-GCM-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 3: ECDHE-RSA-AES256-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 4: ECDHE-ECDSA-AES256-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 5: ECDHE-RSA-AES256-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 6: ECDHE-ECDSA-AES256-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 7: DHE-DSS-AES256-GCM-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 8: DHE-RSA-AES256-GCM-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 9: DHE-RSA-AES256-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 10: DHE-DSS-AES256-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 11: DHE-RSA-AES256-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 12: DHE-DSS-AES256-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 13: AES256-GCM-SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 14: AES256-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 15: AES256-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 16: ECDHE-RSA-AES128-GCM-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 17: ECDHE-ECDSA-AES128-GCM-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 18: ECDHE-RSA-AES128-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 19: ECDHE-ECDSA-AES128-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 20: ECDHE-RSA-AES128-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 21: ECDHE-ECDSA-AES128-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 22: DHE-DSS-AES128-GCM-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 23: DHE-RSA-AES128-GCM-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 24: DHE-RSA-AES128-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 25: DHE-DSS-AES128-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 26: DHE-RSA-AES128-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 27: DHE-DSS-AES128-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 28: SM2-SM4-SM3
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 29: AES128-GCM-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 30: AES128-SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 31: AES128-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 32: ECDHE-RSA-RC4-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 33: ECDHE-ECDSA-RC4-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 34: RC4-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 35: RC4-MD5
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 36: ECDHE-RSA-DES-CBC3-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 37: ECDHE-ECDSA-DES-CBC3-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 38: DHE-RSA-DES-CBC3-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 39: DHE-DSS-DES-CBC3-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Peer cipher suite 40: DES-CBC3-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device has 5 cipher suites:
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device cipher suite 1: TLS_AES_128_GCM_SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device cipher suite 2: TLS_AES_256_GCM_SHA384
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device cipher suite 3: TLS_CHACHA20_POLY1305_SHA256
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device cipher suite 4: AES128-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device cipher suite 5: AES256-SHA
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Chosen cipher suite is AES256-SHA.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device certificate subject = '/CN=HTTPS-Self-Signed-Certificate-fb3841a2b9931ec0'.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device certificate issuer = '/CN=HTTPS-Self-Signed-Certificate-fb3841a2b9931ec0'.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Device public key length is 2048 bits.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Receive: TLS 1.2 [length 0010], message type: Finished.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
14 00 00 0c a8 9f 36 75 3a 85
04 c3 ce 30 30 54
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_INFO: -COntext=1; SSL_accept: SSLv3/TLS read finished.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Send: TLS 1.2Handshake [length 00aa].
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
16 03 03 00 aa
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_DEBUG_KSSL_HANDSHAKE: -COntext=1; Send: TLS 1.2 [length 00aa], message type: NewSessionTicket.
*Oct 17 13:34:57:308 2024 ***.***-jiaxing-2 SSLVPNK/7/SSLVPN_KSSL_PACKET: -COntext=1;
04 00 00 a6 00 00 0e 10 00 a0
01 19 57 94 a6 a4 5d 52 46 7a
f5 c0 77 ce 81 46 67 05 b9 44
03 e9 3f d9 99 8b 9d ff 21 8a
62 fd df b8 3e 48 43 a2 65 55
40 ef c9 a8 d5 28 b9 20 a4 89
32 71 a5 8f 58 87 22 8f 01 4a
ae a1 f1 ca 8f 28 d4 72 2f 61
f3 77 8a a3 36 36 15 0e cb b4
1e 60 81 ef a6 fb ef 6a 3c 12
48 71 fb 21 92 bc f3 d8 c4 7e
df 56 f1 7e 35 16 90 87 ad 00
4e 21 d3 c1 f1 a8 a5 00 18 72
7e 0b 51 4c 0b 4b a8 cf c9 06
49 5b 5a 93 13 57 00 a2 1e 58
ea c0 0a 14 69 7e c1 fb a5 78
f2 ae b7 cc 45 b4 79 4f 9d 3b
(0)
最佳答案
检查下配置和软件版本以及inode版本配套等细节吧
(0)
配置是参考另外一个局点的,没问题的另外一个局点已经测试过的
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
那就400热线定位具体问题吧