设备配置:
acl advanced 3000
rule 0 permit ip source 2.2.2.2 0 destination 4.4.4.4 0
rule 5 permit ip source 11.11.11.11 0 destination 55.55.55.55 0
#
ipsec transform-set 1
esp encryption-algorithm des-cbc
esp authentication-algorithm sha1
#
ipsec policy-template 1 10
transform-set 1
security acl 3000
local-address 10.0.12.1
remote-address 10.0.34.4
ikev2-profile 1
#
ipsec policy 1 10 isakmp template 1
#
ikev2 keychain 1
peer 4.4.4.4
address 10.0.34.4 255.255.255.0
identity address 10.0.34.4
pre-shared-key ciphertext $c$3$wCbHhqv8bTziD8Kjd4y+5APYlSm4pw==
#
ikev2 profile 1
authentication-method local pre-share
authentication-method remote pre-share
keychain 1
identity local address 10.0.12.1
match local address 10.0.12.1
match remote identity address 10.0.34.4 255.255.255.0

业务网段在ipsec路由器上,经过nat环境ikev2 sa建立不起来,路由器1和路由器5是我直连建立不经过nat环境的测试,可以成功建立,出口nat路由器上已经映射udp500和4500端口,麻烦大佬帮看下问题在哪里
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
看目前配置有发现问题么大佬