F1000-E-SI 防火墙,V5版本。物理接口绑定的有VPN实例,配置GRE接口后,tunnel接口也绑定的有VPN实例,但是tunnel接口状态一直显示为DOWN。
我在模拟器上用V7的防火请配置GRE,发现物理接口绑定VPN实例后,GRE就起不来了。
难道防火墙配置GRE的时候跟接口是否绑定VPN还有关系么?请各大神解答。
interface GigabitEthernet0/8
port link-mode route
nat outbound 3000 address-group 1 vpn-instance cucc
combo enable
fiber duplex full
speed 1000
ip binding vpn-instance cucc
ip address 61.163.101.226 255.255.255.248
ipsec policy shimingzhi
interface Tunnel0
ip binding vpn-instance cucc
ip address 192.168.250.178 255.255.255.252
source 61.163.101.226
destination 115.182.16.100
keepalive 10 3
zone name Untrust_cucc id 5
priority 6
import interface GigabitEthernet0/8
import interface Tunnel0
interzone source Local destination Untrust_cucc
rule 1 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
interzone source Untrust_cucc destination Local
rule 2 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
ip route-static vpn-instance cucc 10.10.10.1 255.255.255.255 Tunnel0 192.168.250.177
debug信息:
*Apr 26 19:42:10:838 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel1 can't come up because:
*Apr 26 19:42:10:839 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel source address is not a loopback address
*Apr 26 19:42:10:840 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
No keepalive response received
*Apr 26 19:42:15:839 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel1 can't come up because:
*Apr 26 19:42:15:840 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel source address is not a loopback address
*Apr 26 19:42:15:840 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
No keepalive response received
*Apr 26 19:42:17:838 2018 XQ6F-A04-F1000 GRE/7/debug:
Tunnel1 packet: The source is not local, so keepalive packet won't be sent out.
*Apr 26 19:42:20:838 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel1 can't come up because:
*Apr 26 19:42:20:839 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel source address is not a loopback address
*Apr 26 19:42:20:840 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
No keepalive response received
*Apr 26 19:42:25:839 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel1 can't come up because:
*Apr 26 19:42:25:840 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel source address is not a loopback address
*Apr 26 19:42:25:840 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
No keepalive response received
*Apr 26 19:42:27:839 2018 XQ6F-A04-F1000 GRE/7/debug:
Tunnel1 packet: The source is not local, so keepalive packet won't be sent out.
*Apr 26 19:42:30:839 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel1 can't come up because:
*Apr 26 19:42:30:839 2018 XQ6F-A04-F1000 TUNNEL/7/debug:
Tunnel source address is not a loopback address
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论