<H3C>t d The current terminal is enabled to display debugging logs. <H3C>ping -a 192.168.27.251 192.168.10.251 Ping 192.168.10.251 (192.168.10.251) from 192.168.27.251: 56 data bytes, press CTRL+C to break *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: --- Sent IPsec packet, pkt len : 84 --- *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Attent to match Mqc(0), ifIndex is 17411, digest is 0, no result. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Attent to match Mqc(1), ifIndex is 17411, digest is 0, no result. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Last dest lip is NULL. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: src IP = 192.168.27.251, dst IP = 192.168.10.251, SPI = 234563668. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Alloc IPsec cache: Global fs seq : 6, Private index : 0, Private seq : 5. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/EVENT: Add ip fastforward cache : ulDirtection = 2, ifIndexOut = 2 *Jan 2 05:04:47:426 2011 H3C IPSEC/7/EVENT: Added IP fast forwarding entry. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: ESP auth algorithm: MD5, ESP encp algorithm: 3DES-CBC. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Packet will be sent to CCF for sync-encryption. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Outbound IPsec ESP processing: Encryption succeeded, anti-replay SN is 30. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: Packet encapsulated successfully. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/EVENT: Start to fill reply cache key, SrcAddr : 110.189.155.125, DstAddr : 110.185.170.62, SPI :234563668, SrcPort : 3579, DstPort : 10324. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/EVENT: Fill output IPsec packet reply cache key. *Jan 2 05:04:47:426 2011 H3C IPSEC/7/EVENT: Find another sa, spi : 0x117bb6b8, SrcPort : 4475, DstPort : 46776. Request time out *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: FS Check : fs sequence num in IPsec fast cache is 6, current fs sequence num is 6 *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: FS Check : No Change. Tunnel index = 0, Tunnel seq = 5. *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: --- Sent packet by IPsec fast forwarding --- *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: src IP = 192.168.27.251, dst IP = 192.168.10.251, SPI = 234563668. *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: ESP auth algorithm: MD5, ESP encp algorithm: 3DES-CBC. *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: Packet will be sent to CCF for sync-encryption. *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: Outbound IPsec ESP processing: Encryption succeeded, anti-replay SN is 31. *Jan 2 05:04:49:630 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: Packet encapsulated successfully. Request time out *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: FS Check : fs sequence num in IPsec fast cache is 6, current fs sequence num is 6 *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: FS Check : No Change. Tunnel index = 0, Tunnel seq = 5. *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: --- Sent packet by IPsec fast forwarding --- *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: src IP = 192.168.27.251, dst IP = 192.168.10.251, SPI = 234563668. *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: ESP auth algorithm: MD5, ESP encp algorithm: 3DES-CBC. *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: Packet will be sent to CCF for sync-encryption. *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: Outbound IPsec ESP processing: Encryption succeeded, anti-replay SN is 32. *Jan 2 05:04:51:833 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: Packet encapsulated successfully. Request time out *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: FS Check : fs sequence num in IPsec fast cache is 6, current fs sequence num is 6 *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: FS Check : No Change. Tunnel index = 0, Tunnel seq = 5. *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: --- Sent packet by IPsec fast forwarding --- *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: src IP = 192.168.27.251, dst IP = 192.168.10.251, SPI = 234563668. *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: ESP auth algorithm: MD5, ESP encp algorithm: 3DES-CBC. *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: Packet will be sent to CCF for sync-encryption. *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: Outbound IPsec ESP processing: Encryption succeeded, anti-replay SN is 33. *Jan 2 05:04:54:036 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: Packet encapsulated successfully. Request time out *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: FS Check : fs sequence num in IPsec fast cache is 6, current fs sequence num is 6 *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: FS Check : No Change. Tunnel index = 0, Tunnel seq = 5. *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: --- Sent packet by IPsec fast forwarding --- *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: src IP = 192.168.27.251, dst IP = 192.168.10.251, SPI = 234563668. *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: ESP auth algorithm: MD5, ESP encp algorithm: 3DES-CBC. *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: Packet will be sent to CCF for sync-encryption. *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: Outbound IPsec ESP processing: Encryption succeeded, anti-replay SN is 34. *Jan 2 05:04:56:239 2011 H3C IPSEC/7/PACKET: Outbound IPsec processing: Packet encapsulated successfully. Request time out --- Ping statistics for 192.168.10.251 --- 5 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss <H3C>%Jan 2 05:04:58:442 2011 H3C PING/6/PING_STATISTICS: Ping statistics for 192.168.10.251: 5 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss. <H3C> <H3C>undo debugging all All possible debugging has been turned off.
dis ike sa 和dis ipsec sa 都有信息,但是业务不通这能看出是哪的问题么?
(0)
最佳答案
相关业务加到感兴趣数据流里和有相应路由吗
(0)
有的
检查下有没有其他设备做限制了,tracert下看看
隧道都起来了,不通和IPSec模块没关系啊
(0)
用户视图reset ipsec sa然后reset ike sa,在协商一次看下
重新协商也是一样的
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
检查下有没有其他设备做限制了,tracert下看看