]dis ipsec sa ------------------------------- Interface: GigabitEthernet0/1 ------------------------------- ----------------------------- IPsec policy: r3 Sequence number: 1 Mode: ISAKMP ----------------------------- Tunnel id: 0 Encapsulation mode: tunnel Perfect Forward Secrecy: Inside VPN: Extended Sequence Numbers enable: N Traffic Flow Confidentiality enable: N Path MTU: 1428 Tunnel: local address: 100.1.1.1 remote address: 100.2.2.2 Flow: sour addr: 192.168.1.0/255.255.255.0 port: 0 protocol: ip dest addr: 192.168.2.0/255.255.255.0 port: 0 protocol: ip [Inbound ESP SAs] SPI: 4147937693 (0xf73c819d) Connection ID: 4294967296 Transform set: ESP-ENCRYPT-AES-CBC-128 ESP-AUTH-SHA1 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1843200/3578 Max received sequence-number: 0 Anti-replay check enable: Y Anti-replay window size: 64 UDP encapsulation used for NAT traversal: N Status: Active [Outbound ESP SAs] SPI: 2381865055 (0x8df8605f) Connection ID: 4294967297 Transform set: ESP-ENCRYPT-AES-CBC-128 ESP-AUTH-SHA1 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1843199/3578 Max sent sequence-number: 4 UDP encapsulation used for NAT traversal: N Status: Active [r1]
[r3]dis ipsec sa ------------------------------- Interface: GigabitEthernet0/0 ------------------------------- ----------------------------- IPsec policy: r1 Sequence number: 1 Mode: ISAKMP ----------------------------- Tunnel id: 0 Encapsulation mode: tunnel Perfect Forward Secrecy: Inside VPN: Extended Sequence Numbers enable: N Traffic Flow Confidentiality enable: N Path MTU: 1428 Tunnel: local address: 100.2.2.2 remote address: 100.1.1.1 Flow: sour addr: 192.168.2.0/255.255.255.0 port: 0 protocol: ip dest addr: 192.168.1.0/255.255.255.0 port: 0 protocol: ip [Inbound ESP SAs] SPI: 2381865055 (0x8df8605f) Connection ID: 4294967296 Transform set: ESP-ENCRYPT-AES-CBC-128 ESP-AUTH-SHA1 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1843199/3431 Max received sequence-number: 4 Anti-replay check enable: Y Anti-replay window size: 64 UDP encapsulation used for NAT traversal: N Status: Active [Outbound ESP SAs] SPI: 4147937693 (0xf73c819d) Connection ID: 4294967297 Transform set: ESP-ENCRYPT-AES-CBC-128 ESP-AUTH-SHA1 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1843200/3431 Max sent sequence-number: 0 UDP encapsulation used for NAT traversal: N Status: Active [r3]
(0)
最佳答案
检查一下感兴趣匹配的对不对
(0)
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 (4 times matched) rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 (14 times matched)
看你的感兴趣是Flow: sour addr: 192.168.1.0/255.255.255.0 port: 0 protocol: ip dest addr: 192.168.2.0/255.255.255.0
看看acl与nat拒绝的acl写的对不对
(0)
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 (4 times matched) rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 (14 times matched)
没写拒绝的就写了通过的
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 (4 times matched) rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 (14 times matched)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 (4 times matched) rule 0 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 (14 times matched)