IPsec策略都是一样的,认证算法和加密算法都是对的,FQND本端和对端也是一样的
NAT动态转换
(0)
最佳答案
dis acl 看下是否有匹配到acl
(0)
感谢,连通了
感谢,连通了
两端都检查一下,尤其感兴趣数据流和NAT排查,都没问题就debug吧
(0)
感谢,连通了
Sent SA-Acquire message : SP ID = 0 *Sep 17 21:46:54:282 2022 H3C IPSEC/7/EVENT: Received negotiatiate SA message from IPsec kernel. *Sep 17 21:46:58:840 2022 H3C IPSEC/7/EVENT: Found block-flow node. *Sep 17 21:46:58:840 2022 H3C IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 4294901760. *Sep 17 21:46:58:840 2022 H3C IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. *Sep 17 21:47:03:840 2022 H3C IPSEC/7/EVENT: Found block-flow node. *Sep 17 21:47:03:840 2022 H3C IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 4294901760. *Sep 17 21:47:03:840 2022 H3C IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. *Sep 17 21:47:08:840 2022 H3C IPSEC/7/EVENT: Found block-flow node. *Sep 17 21:47:08:840 2022 H3C IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 4294901760. *Sep 17 21:47:08:840 2022 H3C IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel. *Sep 17 21:47:13:840 2022 H3C IPSEC/7/EVENT: Found block-flow node. *Sep 17 21:47:13:840 2022 H3C IPSEC/7/PACKET: Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 4294901760. *Sep 17 21:47:13:840 2022 H3C IPSEC/7/ERROR: The reason of dropping packet is no available IPsec tunnel.
感谢,连通了
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
感谢,通了