• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

某局点 MSR IPSEC VPN对接锐捷不成功

  • 0关注
  • 0收藏 241浏览
粉丝:17人 关注:4人

组网及说明

无特殊组网,IPSEC VPN两端点分别是H3C MSR和锐捷路由器。

告警信息

*Jul 13 23:04:20:886 2023 H3C IKE/7/EVENT: Phase1 process started.

*Jul 13 23:04:20:886 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received ISAKMP Key Exchange Payload.

*Jul 13 23:04:20:886 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received ISAKMP Nonce Payload.

*Jul 13 23:04:20:886 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received ISAKMP NAT-D Payload.

*Jul 13 23:04:20:886 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received ISAKMP NAT-D Payload.

*Jul 13 23:04:20:886 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Process KE payload.

*Jul 13 23:04:20:887 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Process NONCE payload.

*Jul 13 23:04:20:896 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received 2 NAT-D payload.

*Jul 13 23:04:20:896 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Local ID type: IPV4_ADDR (1).

*Jul 13 23:04:20:896 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Local ID value: A.B.40.4.

*Jul 13 23:04:20:896 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Construct ID payload.

*Jul 13 23:04:20:896 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

HASH:

 e14005b5 840fcd91 c6098928 168f6ea9

*Jul 13 23:04:20:896 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Construct authentication by pre-shared-key.

*Jul 13 23:04:20:897 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Construct INITIAL-CONTACT payload.

*Jul 13 23:04:20:897 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Encrypt the packet.

*Jul 13 23:04:20:897 2023 H3C IKE/7/EVENT: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

IKE SA state changed from IKE_P1_STATE_SEND3 to IKE_P1_STATE_SEND5.

*Jul 13 23:04:20:897 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Sending packet to M.N.0.14 remote port 500, local port 500, out-interface 0.

*Jul 13 23:04:20:897 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

 

  I-COOKIE: f6a8da06b5f8f214

  R-COOKIE: 00015017ba001cf6

  next payload: ID

  version: ISAKMP Version 1.0

  exchange mode: Main

  flags: ENCRYPT

  message ID: 0

  length: 92

*Jul 13 23:04:20:897 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Sending an IPv4 packet.

*Jul 13 23:04:20:897 2023 H3C IKE/7/EVENT: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Send udp packet by socket 41 SrcPort 500 ifIndex 0.

*Jul 13 23:04:20:897 2023 H3C IKE/7/EVENT: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Sent data to socket successfully.

 

*Jul 13 23:04:20:924 2023 H3C IKE/7/EVENT: Received packet successfully.

*Jul 13 23:04:20:924 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received packet from M.N.0.14 source port 500 destination port 500.

*Jul 13 23:04:20:925 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

 

  I-COOKIE: f6a8da06b5f8f214

  R-COOKIE: 00015017ba001cf6

  next payload: HASH

  version: ISAKMP Version 1.0

  exchange mode: Info

  flags: ENCRYPT

  message ID: b25c1d33

  length: 76

*Jul 13 23:04:20:925 2023 H3C IKE/7/EVENT: IKE thread 2784412960 processes a job.

*Jul 13 23:04:20:925 2023 H3C IKE/7/EVENT: Info packet process started.

*Jul 13 23:04:20:925 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Decrypt the packet.

*Jul 13 23:04:20:925 2023 H3C IKE/7/PACKET: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Received ISAKMP Hash Payload.

*Jul 13 23:04:20:925 2023 H3C IKE/7/ERROR: 2th byte of the structure ISAKMP Hash Payload must be 0.

*Jul 13 23:04:20:926 2023 H3C IKE/7/ERROR: vrf = 0, local = A.B.40.4, remote = M.N.0.14/500

Failed to parse informational exchange packet. Reason INVALID_PAYLOAD_TYPE.

问题描述

对端锐捷配置

crypto isakmp mode-detect

cryoto isakmp policy 10

encryption sm4

authentication pre-share

hash md5

!

crypto isakmp key 7 ***** address 0.0.0.0 0.0.0.0

crypto ipsec transform-set AA_IPSEC_TS esp-sm4 esp-sha-hmac

crypto dynamic-map AA_DM 20

set transform-set AA_IPSEC_TS

reverse-route  tag 30

!

crypto map AA_CP 20 ipsec-isakmp dynamic AA_DM

客户提供能正常建立的迈普设备配置:

crypto ike key *** address 192.168.0.22 (CMCC)   /   M.N.0.14 (CTCC)
crypto ike proposal GM
encryption sm4
integrity md5
exit
crypto ipsec proposal GM
esp sm4-old sha1
exit

现场参考迈普设备输出了以下我司配置:

#
ipsec policy SIM1(Cellular1/1) 65535 isakmp
 transform-set GM 
 security acl name GM 
 local-address A.B.40.4
 remote-address M.N.0.14
 description GM
 ike-profile GM
#
ike profile GM
 keychain GM
 match remote identity address M.N.0.14 255.255.255.255
 proposal 65535 
#
ike proposal 65535
#
ike keychain GM
 pre-shared-key address M.N.0.14 255.255.255.255 key cipher $c$3$3Xv9W4/Ro37qzSffiHs8LBt5BvIAgkxJCTgqYd7CXQ==
#

但ipsec始终无法建立,debug ike all 显示错误信息如上

过程分析

依次核对IKE和IPSEC的各配置模块。

1、ike keychain已配置且指定锐捷设备IP;

2、ike profile 已指定对端锐捷设备特征为IP地址;

3、ike proposal 在锐捷设备中未找到明确对应,但迈普设备在proposal中指定了加密算法SM4,而我司缺省的加密算法不是SM4;

解决方法

ike propose 65535下配置加密算法为SM4

该案例对您是否有帮助:

您的评价:1

若您有关于案例的建议,请反馈:

0 个评论

该案例暂时没有网友评论

编辑评论

举报

×

侵犯我的权益 >
对根叔知了社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔知了社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作