描述:
AB两地ipsecVPN组网,
A分支配置:核心交换机,防火墙板卡,VPN设备
组网方式:网关全在核心交换机中,核心交换机与防火墙通过虚拟内联口做三层路由,防火墙配置为单臂路由。核心配置策略路由将流量强制送往防火墙板卡。
B分支配置:核心交换机,VPN设备
问题:
两端配置了IPSEC后查看ike sa是RD状态正常建立的,但是目前只能在A分支可以ping同B分支,B分支却不能ping通A分支,在分支B中tracert路由路径发现在A分支核心交换机接VPN设备的端口IP地址就断了。
VPN debug信息:
021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: PACKET encapsulation successfully. /报文封装成功。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET:——Sent IPSEC PACKET, pkt len: 40——
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Attent to match Mqc(0), ifIndex为3,digest为0,没有结果。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Attent to match Mqc(1), ifIndex为3,digest为0,没有结果。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Last dest lip is NULL。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: src IP = 172.16.6.2, dst IP = 192.168.10.2, SPI = 1458266211。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Alloc IPSEC cache: Global fs seq: 0, Private index: 0, Private seq: 1。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/EVENT:新增IP快速转发表项。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: ESP auth algorithm: MD5, ESP encp algorithm: DES-CBC。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: PACKET将被发送到CCF进行同步加密。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Outbound IPSEC ESP processing: Encryption succeeded, anti-replay SN is 158。
*Nov 30 15:58:21:655 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: PACKET encapsulation successfully. /报文封装成功。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET:——Sent IPSEC PACKET, pkt len: 40——
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Attent to match Mqc(0), ifIndex为3,digest为0,没有结果。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Attent to match Mqc(1), ifIndex为3,digest为0,没有结果。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Last dest lip is NULL。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: src IP = 172.16.6.2, dst IP = 192.168.10.2, SPI = 1458266211。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Alloc IPSEC cache: Global fs seq: 0, Private index: 0, Private seq: 1。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/EVENT:新增IP快速转发表项。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: ESP auth algorithm: MD5, ESP encp algorithm: DES-CBC。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET:报文将发送到CCF进行同步加密。
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Outbound IPSEC ESP processing: Encryption succeeded, anti-replay SN is 159
*Nov 30 15:58:26:628 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: PACKET encapsulation successfully. /报文封装成功。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET:——Sent IPSEC PACKET, pkt len: 40——
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Attent to match Mqc(0), ifIndex为3,digest为0,没有结果。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Attent to match Mqc(1), ifIndex为3,digest为0,没有结果。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Last dest lip is NULL。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: src IP = 172.16.6.2, dst IP = 192.168.10.2, SPI = 1458266211。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Alloc IPSEC cache: Global fs seq: 0, Private index: 0, Private seq: 1。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/EVENT:新增IP快速转发表项。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: ESP auth algorithm: MD5, ESP encp algorithm: DES-CBC。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: PACKET将被发送到CCF进行同步加密。
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Outbound IPSEC ESP processing: Encryption succeeded, anti-replay SN is 160
*Nov 30 15:58:31:615 2021 H3C IPSEC/7/PACKET: Outbound IPSEC processing: PACKET encapsulation successfully. /报文封装成功。
各位大佬们 请问这是什么一个情况呢
防火墙策略为全放 ,兴趣流A分支允许访问B分支,B分支允许A分支