IPSec: ip route-static 0.0.0.0 0 4.4.4.1(首先保证isp互通,下一条isp对端地址)
acl advanced 3500(感兴趣流规则,总部和分支的业务网段)
rule 0 permit ip source 10.10.10.0 0.0.0.255 destination 10.11.11.0 0.0.0.255
acl advanced 3000(公网出口NAT转换首先拒绝掉感兴趣流,再允许所有)
rule 5 deny ip source 10.10.10.0 0.0.0.255 destination 10.11.11.0 0.0.0.255
rule 10 permit ip [RTA] ipsec transform-set tran1
[RTA-ipsec-tranfsorm-set-tran1] encapsulation-mode tunnel
[RTA-ipsec-tranfsorm-set-tran1] protocol esp
[RTA-ipsec-tranfsorm-set-tran1] esp encryption-algorithm des-cbc
[RTA-ipsec-tranfsorm-set-tran1] esp authentication-algorithm sha1
[RTA-ipsec-tranfsorm-set-tran1] quit
[RTA]ike keychain 1
[RTA-keychain-key1]pre-shared-key address 对端公网地址+掩码 key simple 密码
[RTA-keychain-key1]quit
[RTA]ike profile 1
[RTA-profile-pro1]keychain 1
[RTA-profile-pro1]match remote identity address 对端公网地址+掩码
[RTA-profile-pro1]quit
[RTA] ipsec policy map1 10 isakmp
[RTA-ipsec-policy-isakmp-map1-10] transform-set tran1
[RTA-ipsec-policy-isakmp-map1-10] security acl 3500
[RTA-ipsec-policy-isakmp-map1-10] ike-profile pro1
[RTA-ipsec-policy-isakmp-map1-10] local address 本端公网地址(不加掩码)
[RTA-ipsec-policy-isakmp-map1-10] remote-address 对端公网地址(不加掩码)
[RTA-ipsec-policy-isakmp-map1-10] quit [RTA] interface serial0/0(本端公网出口)
[RTA-Serial0/0] ipsec apply policy map1
(0)
最佳答案
单侧配置无法准确判断,建议看下dis ike sa和dis ipsec sa情况。
多数情况是2端配置不一致导致。
如果ike都无法建立检查下组网情况,看下是否流能可达。通常多出口环境会有这个问题。
(0)
dis ike sa 没有,两边配置一样,我对端地址,感兴趣流,策略绑定端口,都没问题,也不知道咋个排查
dis ike sa 没有,两边配置一样,我对端地址,感兴趣流,策略绑定端口,都没问题,也不知道咋个排查
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明