日志:
%Jan 18 16:58:00:000 2021 FW-1020 IKE/6/IKE_P1_SA_ESTABLISH_FAIL: -COntext=1; Failed to establish phase 1 in Aggressive mode IKE_P1_STATE_INIT state.
Reason: No acceptable transform.
SA information: Role: responder
Local IP: 58.16.134.46
Local ID type: Unknown
Local ID:
Local port: 500
Retransmissions: 0
Remote IP: 222.85.183.47 Remote ID type: FQDN
Remote ID: kxt1
Remote port: 5189
Recived retransmissions: 0
Inside VPN instance:
Outside VPN instance:
Initiator COOKIE: a79835c927b3a6e7
Responder COOKIE: e77c1d605fb70ac8
Connection ID: 3105
Tunnel ID: 4294967295
IKE profile name:
接口配置:
interface GigabitEthernet1/0/14 port link-mode route
description 出口2
ip address 58.16.134.46 255.255.255.252
ip last-hop hold
nat outbound 3999
nat server protocol tcp global current-interface 86 inside 192.168.1.210 80 rule ServerRule_88
nat server protocol tcp global current-interface 3366 inside 192.168.1.210 3366 rule ServerRule_89
F1020防火墙做的出口网关,开启日志一直有;求大神解释日志生成原因,谢谢,小弟敬上。
(0)
最佳答案
您好,请知:
%Jan 18 16:58:00:000 2021 FW-1020 IKE/6/IKE_P1_SA_ESTABLISH_FAIL: -COntext=1; Failed to establish phase 1 in Aggressive mode IKE_P1_STATE_INIT state.
从反馈的日志来看ipsec IKE野蛮模式建立失败的提示。
如果现场没有配置IPSEC VPN,可以在端口删除IPSEC VPN的应用。
另外如果想关闭日志的回显,以下是参考命令:
<H3C>u t m
<H3C>u t d
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明