设置列表
建立 ipsec vpn 通过ping 触发感兴趣流ike sa不存在,对端可以触发并建立第一、第二阶段。,但是ping不通对端,检查路由和acl匹配都没问题,配置没问题
debug抓ike error ,没有显示
(0)
最佳答案
第一阶段能起来 那说明密钥之类的没啥问题、
第二阶段就是 兴趣流了 两端相互都检查下,两端的地址需要是镜像的。错了就建立不起来。很容易出错
还有 如果是用了nat out的话 需要在出口的acl上把兴趣流禁止掉 不然直接走out转发了
res Ike sa
res ipsec sa
检查完上面操作 用这两条命令清空下 重新出发一下 、看下协商
(0)
第一个分支通,第二个不通,删了第一个分支ipsec 策略,第二个通
可以看下ike统计情况,哪一端ping触发就在哪一端看。
命令如下:dis ike statistics
查看前先reset ike statis,然后看下是否本端丢包未触发
https://www.h3c.com/cn/d_202103/1389425_30005_0.htm#aa_356
(0)
<H3C>dis ike statistics IKE statistics: No matching proposal: 12 Invalid ID information: 0 Unavailable certificate: 0 Unsupported DOI: 0 Unsupported situation: 0 Invalid proposal syntax: 0 Invalid SPI: 0 Invalid protocol ID: 0 Invalid certificate: 0 Authentication failure: 0 Invalid flags: 0 Invalid message id: 0 Invalid COOKIE: 0 Invalid transform ID: 0 Malformed payload: 0 Invalid key information: 0 Invalid hash information: 0 Unsupported attribute: 0 Unsupported certificate type: 0 Invalid certificate authority: 0 Invalid signature: 0 Unsupported exchange type: 0 No available SA: 0 Retransmit timeout: 1 Not enough memory: 0 Enqueue fails: 0 Failures to send R_U_THERE DPD packets: 0 Failures to receive R_U_THERE DPD packets: 0 Failures to send ACK DPD packets: 0 Failures to receive ACK DPD packets: 0 Sent P1 SA lifetime change packets: 0 Received P1 SA lifetime change packets: total=0, process failures=0 (no SA=0,failures to reset SA soft lifetime=0,failures to reset SA hard lifetime=0) Sent P2 SA lifetime change packets: 0 Received P2 SA lifetime change packets: total=0, process failures=0
<H3C>dis ike statistics IKE statistics: No matching proposal: 12 Invalid ID information: 0 Unavailable certificate: 0 Unsupported DOI: 0 Unsupported situation: 0 Invalid proposal syntax: 0 Invalid SPI: 0 Invalid protocol ID: 0 Invalid certificate: 0 Authentication failure: 0 Invalid flags: 0 Invalid message id: 0 Invalid COOKIE: 0 Invalid transform ID: 0 Malformed payload: 0 Invalid key information: 0 Invalid hash information: 0 Unsupported attribute: 0 Unsupported certificate type: 0 Invalid certificate authority: 0 Invalid signature: 0 Unsupported exchange type: 0 No available SA: 0 Retransmit timeout: 1 Not enough memory: 0 Enqueue fails: 0 Failures to send R_U_THERE DPD packets: 0 Failures to receive R_U_THERE DPD packets: 0 Failures to send ACK DPD packets: 0 Failures to receive ACK DPD packets: 0 Sent P1 SA lifetime change packets: 0 Received P1 SA lifetime change packets: total=0, process failures=0 (no SA=0,failures to reset SA soft lifetime=0,failures to reset SA hard lifetime=0) Sent P2 SA lifetime change packets: 0 Received P2 SA lifetime change packets: total=0, process failures=0
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
相当于您这边设备 分别对接了两个点 是吧?