现场总部对分支的主模式ipsec,配置完成后发现一阶段起不来,查看ike sa状态为Unknown
dis ike sa
Connection-ID Local Remote Flag DOI
------------------------------------------------------------------------------------
4 10.xxx.xxx.2 10.xxx.xxx.254/500 Unknown IPsec
收集debug
总部:
*Jun 9 10:50:39:660 2025 IDC_5G_RT IKE/7/ERROR: vrf = 0, local = 10.xxx.xxx.254, remote = 10.xxx.xxx.2/500
No acceptable transform.
*Jun 9 10:50:39:660 2025 IDC_5G_RT IKE/7/ERROR: vrf = 0, local = 10.xxx.xxx.254, remote = 10.xxx.xxx.2/500
Failed to parse the IKE SA payload.
*Jun 9 10:50:39:660 2025 IDC_5G_RT IKE/7/ERROR: vrf = 0, local = 10.xxx.xxx.254, remote = 10.xxx.xxx.2/500
Failed to negotiate IKE SA.
IKE SA state changed from IKE_P1_STATE_INIT to IKE_P1_STATE_SEND1.
分支:*Jun 9 10:50:39:660 2025 IDC_5G_RT IKE/7/ERROR: vrf = 0, local = 10.xxx.xxx.254, remote = 10.xxx.xxx.2/500
No acceptable transform.
*Jun 9 10:50:39:660 2025 IDC_5G_RT IKE/7/ERROR: vrf = 0, local = 10.xxx.xxx.254, remote = 10.xxx.xxx.2/500
Failed to parse the IKE SA payload.
*Jun 9 10:50:39:660 2025 IDC_5G_RT IKE/7/PACKET: vrf = 0,local = 10.xxx.xxx.254, remote = 10.xxx.xxx.2/500
Construct notification packet: NO_PROPOSAL_CHOSEN.
确认两端配置:
总部:
ike proposal 1
encryption-algorithm 3des-cbc
authentication-algorithm md5
分支:
ike proposal 100
authentication-method rsa-signature
encryption-algorithm 3des-cbc
authentication-algorithm md5
两边删除authentication-method rsa-signature恢复缺省配置后解决
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作