按照以下方式配置
<WiNet_0.H3C>display current-configuration
#
version 5.20, Release 2516P15
#
sysname H3C
#
clock timezone Beijing add 08:00:00
#
l2tp enable
#
domain default enable system
#
dns resolve dns proxy enable
#
telnet server enable
#
dar p2p signature-file flash:/p2p_default.mtd
#
ndp enable
#
ntdp enable ntdp hop 8
#
cluster enable
#
port-security enable
#
password-recovery enable
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
ip pool 0 192.168.10.5 192.168.10.100
#
ike proposal 1
encryption-algorithm aes-cbc 256
dh group2
authentication-algorithm md5
#
ike peer zilliz_hz
exchange-mode aggressive
proposal 1
pre-shared-key cipher xxxxx
nat traversal
#
ipsec transform-set zilliz_hz
encapsulation-mode transport
transform esp
esp authentication-algorithm sha1
esp encryption-algorithm aes-cbc-128
#
ipsec policy-template 1048576.1_t 1
connection-name zilliz_hz
ike-peer zilliz_hz
transform-set zilliz_hz
sa duration traffic-based 1843200
sa duration time-based 3600
reverse-route
#
ipsec policy 1048576 1 isakmp template 1048576.1_t
#
dhcp server ip-pool vlan1 extended
network ip range 192.168.1.2 192.168.1.254
network mask 255.255.255.0
gateway-list 192.168.1.1
dns-list 192.168.1.1
#
user-group system
group-attribute allow-guest
#
local-user zilliz_hz
password cipher xxxxx
authorization-attribute level 2
service-type ppp
#
cwmp
undo cwmp enable
#
l2tp-group 1
undo tunnel authentication
allow l2tp virtual-template 0
tunnel password cipher xxxx
#
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
tcp mss 1024
#
interface Virtual-Template0
ppp authentication-mode chap domain system
remote address pool
ip address 192.168.10.1 255.255.255.0
#
结果连接时,日志打印
-Src addr=221.104.213.100-Dst addr=180.169.38.214-I_COOKIE=685160ac09f2b82e-R_COOKIE=6daee43382715e39-Cause=No proposal is chosen-Payload=PROPOSAL; IKE packet dropped.
未连接成功
(0)
最佳答案
No proposal is chosen 已经提示了,两边的ike proposal不匹配,不能完成协商,核对一下两边的ike porposal内容是否一致
(0)
我安卓都是怎么可以设置ike porposal?
我在ubuntu下用sudo ike-scan 180.169.38.234 获取ike porposal,没法获取。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
不懂,没接触过ubuntu建立ipsec这种情况。。。