F5000M-IPSEC第二阶段协商不起来
【本端配置】
Advanced IPv4 ACL named IPsec_GXB_IPv4_1, 1 rule,
ACL's step is 5
rule 0 permit ip destination 10.255.224.0 0.0.0.255 (22958 times matched)
#
ipsec transform-set GXB_IPv4_1
esp encryption-algorithm aes-cbc-128
esp authentication-algorithm sha1
#
ipsec policy GXB 1 isakmp
transform-set GXB_IPv4_1
security acl name IPsec_GXB_IPv4_1
local-address 1.1.1.1
remote-address 2.2.2.2
ike-profile GXB_IPv4_1
#
ike profile GXB_IPv4_1
keychain GXB_IPv4_1
match remote identity address 2.2.2.2 255.255.255.255
match local address 1.1.1.1
proposal 1
#
ike proposal 1
encryption-algorithm aes-cbc-128
#
ike keychain GXB_IPv4_1
match local address 1.1.1.1
pre-shared-key address 2.2.2.2 255.255.255.255 key cipher $c$3$0vxn9Z/bx5tzMTOUlkUAUAsYijVx529ECSIyZr0=
#
ipsec policy GXB 1 isakmp
transform-set GXB_IPv4_1
security acl name IPsec_GXB_IPv4_1
local-address 1.1.1.1
remote-address 2.2.2.2
ike-profile GXB_IPv4_1
#
interface Route-Aggregation1
ipsec apply policy GXB
【报错信息】
Can't find block-flow node.
*Nov 30 10:25:30:304 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:25:30:304 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:25:30:304 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Sent SA-Acquire message : SP ID = 0
*Nov 30 10:25:30:304 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Received negotiatiate SA message from IPsec kernel.
*Nov 30 10:25:30:304 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Got SA time-based soft lifetime settings when filling Sp data.
Configured soft lifetime buffer : 0 seconds.
Configured global soft lifetime buffer : 0 seconds.
*Nov 30 10:25:44:534 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:25:44:534 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:25:44:534 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
%Nov 30 10:25:44:983 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
*Nov 30 10:25:45:535 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:25:45:535 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:25:45:535 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:25:46:528 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Failed to match profile: IKE profile was while IPsec used profile GXB_IPv4_1.
*Nov 30 10:25:46:529 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Failed to match profile: IKE profile was while IPsec used profile GXB_IPv4_1.
*Nov 30 10:25:47:539 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:25:47:539 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:25:47:539 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
%Nov 30 10:25:49:983 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
*Nov 30 10:25:51:551 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:25:51:551 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:25:51:551 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
%Nov 30 10:25:54:983 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
*Nov 30 10:25:55:791 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Sent delete SA message to all nodes, message type is 0x16.
*Nov 30 10:25:55:791 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
The SA doesn't exist in kernel.
*Nov 30 10:25:59:567 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Can't find block-flow node.
*Nov 30 10:25:59:567 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:25:59:567 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:25:59:567 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Sent SA-Acquire message : SP ID = 0
*Nov 30 10:25:59:567 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Received negotiatiate SA message from IPsec kernel.
*Nov 30 10:25:59:567 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Got SA time-based soft lifetime settings when filling Sp data.
Configured soft lifetime buffer : 0 seconds.
Configured global soft lifetime buffer : 0 seconds
*Nov 30 10:26:11:782 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:11:782 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:11:782 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:26:12:783 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:12:783 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:12:783 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:26:14:787 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:14:787 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:14:787 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:26:15:615 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:15:615 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:15:615 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
%Nov 30 10:26:16:065 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
*Nov 30 10:26:18:799 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:18:799 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:18:799 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
%Nov 30 10:26:21:065 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
%Nov 30 10:26:26:065 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
*Nov 30 10:26:26:814 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:26:814 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:26:814 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
*Nov 30 10:26:27:708 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Failed to match profile: IKE profile was while IPsec used profile GXB_IPv4_1.
*Nov 30 10:26:27:708 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Failed to match profile: IKE profile was while IPsec used profile GXB_IPv4_1.
%Nov 30 10:26:31:087 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;
*Nov 30 10:26:34:432 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/EVENT: -COntext=1;
Found block-flow node.
*Nov 30 10:26:34:432 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/PACKET: -COntext=1;
Failed to find SA by SP, SP Index = 0, SP Convert-Seq = 65536.
*Nov 30 10:26:34:432 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IPSEC/7/ERROR: -COntext=1;
The reason of dropping packet is no available IPsec tunnel.
undo debugging all
All possible debugging has been turned off.
<ZJ-SX-QFC-FW-1.SOC.F5000-M>%Nov 30 10:26:37:066 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M ARP/6/DUPIFIP: -COntext=1;

#
*Nov 30 12:14:28:777 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/ERROR: -COntext=1; vrf = 0, local = 115.239.131.117, remote = 103.118.53.252/4500
Failed to get IPsec policy for phase 2 responder. Delete IPsec SA.
*Nov 30 12:14:28:777 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/ERROR: -COntext=1; vrf = 0, local = 115.239.131.117, remote = 103.118.53.252/4500
Failed to negotiate IPsec SA.
*Nov 30 12:14:28:777 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/EVENT: -COntext=1; Delete IPsec SA.
*Nov 30 12:14:28:777 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/PACKET: -COntext=1; vrf = 0, local = 115.239.131.117, remote = 103.118.53.252/4500
Encrypt the packet.
*Nov 30 12:14:28:778 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/PACKET: -COntext=1; vrf = 0, local = 115.239.131.117, remote = 103.118.53.252/4500
Construct notification packet: INVALID_ID_INFORMATION.
*Nov 30 12:14:28:778 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/PACKET: -COntext=1; vrf = 0, local = 115.239.131.117, remote = 103.118.53.252/4500
Sending packet to 103.118.53.252 remote port 4500, local port 4500.
*Nov 30 12:14:28:778 2025 ZJ-SX-QFC-FW-1.SOC.F5000-M IKE/7/PACKET: -COntext=1; vrf = 0, local = 115.239.131.117, remote = 103.118.53.252/4500
I-COOKIE: edafee7401cedfdf
R-COOKIE: 63fd4e731f9f765f
next payload: HASH
version: ISAKMP Version 1.0
exchange mode: Info
flags: ENCRYPT
message ID: 8058f067
length: 76
暂无评论
打开你的电脑,在浏览器输入知了社区,找到这个帖子,要么在别人下面评论,要么点我的头像。
参考手册排查下 H3C SecPath 防火墙产品 维护宝典-6W10019-IPsec
参考手册配置 1.19.2 网关与网关之间采用IKE方式建立保护IPv4报文的IPsec隧道配置举例(预共享密钥认证方式)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论