诊断信息如下:
<H3C FW>debugging ike all
This command is CPU intensive and might affect ongoing services. Are you sure you want to continue? [Y/N]:Y
<H3C FW>debugging ipse
<H3C FW>debugging ipsec all
This command is CPU intensive and might affect ongoing services. Are you sure you want to continue? [Y/N]:Y
<H3C FW>t d
The current terminal is enabled to display debugging logs.
<H3C FW>t m
The current terminal is enabled to display logs.
<H3C FW>*Feb 18 15:23:39:711 2025 H3C FW IKE/7/EVENT: -COntext=1; Received packet successfully.
*Feb 18 15:23:39:743 2025 H3C FW IPSEC/7/PACKET: -COntext=1;
--- Received IPsec(ESP) packet: packet length : 47 ---
*Feb 18 15:23:39:743 2025 H3C FW IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is memory alloc failed.
*Feb 18 15:23:40:025 2025 H3C FW IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 655370.
*Feb 18 15:23:40:025 2025 H3C FW IPSEC/7/PACKET: -COntext=1;
Alloc IPsec cache: Global fs seq : 320934, Private index : 0, Private seq : 0.
*Feb 18 15:23:40:025 2025 H3C FW IPSEC/7/PACKET: -COntext=1;
Alloc IPsec cache: Global fs seq : 320934, Private index : 0, Private seq : 0.
*Feb 18 15:23:40:025 2025 H3C FW IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 655370.
(0)
最佳答案
您好,以下是排查要点,请参考:
1、检查下两端的路由是否可达。
2、检查两端IPSEC VPN的加密算法、认证算法、认证密钥是否一致。
3、检查两端IPSEC VPN的模式是否一致。
4、检查两端IPSEC VPN的指向是否已正确。
5、检查两端IPSEC VPN的感兴趣数据流是否已正确指定了源和目的。
6、检查两端是否有安全策略或ACL的拦截
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论