组网图如下:
现场反馈,总部和多分支建立ipsec vpn,总部重启后,与部分分支之间ipsec vpn建立不起来。
查看display ike sa和display ipsec sa,分支有
<A局点_FW>dis ike sa
Connection-ID Remote Flag DOI
------------------------------------------------------------------
6 10.10.10.10 RD
IPsec Flags: RD--READY RL--REPLACED FD-FADING RK-REKEY
总部上ike sa和ipsec sa都是空的。
查看总部上的debug信息,第一阶段的debug报文即有如下报错
*Oct 31 16:03:55:253 2018 A局点_FW IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. Request time out
*Oct 31 16:03:57:454 2018 A局点_FW IPSEC/7/EVENT: Found block-flow node.
*Oct 31 16:03:57:454 2018 A局点_FW IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Oct 31 16:03:57:454 2018 A局点_FW IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. Request time out
*Oct 31 16:03:59:655 2018 A局点_FW IPSEC/7/EVENT: Found block-flow node.
*Oct 31 16:03:59:655 2018 A局点_FW IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Oct 31 16:03:59:655 2018 A局点_FW IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. Request time out
*Oct 31 16:04:01:856 2018 A局点_FW IPSEC/7/EVENT: Found block-flow node.
*Oct 31 16:04:01:856 2018 A局点_FW IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Oct 31 16:04:01:856 2018 A局点_FW IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. Request time out
*Oct 31 16:04:04:057 2018 A局点_FW IPSEC/7/EVENT: Found block-flow node.
*Oct 31 16:04:04:057 2018 A局点_FW IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Oct 31 16:04:04:057 2018 A局点_FW IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel.
报文丢弃的原因是没有可用的ipsec隧道。
检查总部配置,发现总部配置ike profile配置指定的对端地址是全零,怀疑是匹配的时候,感兴趣流匹配异常造成。
ike profile 3
keychain 3
exchange-mode aggressive
local-identity fqdn zongbu
match remote identity fqdn shiyan
match remote identity address 0.0.0.0 0.0.0.0
proposal 1
删掉match remote identity address 0.0.0.0 0.0.0.0
并添加指定本地地址的配置local-identity address 10.10.10.10解决。
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作