debug日志:
*Sep 23 17:46:30:042 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: PKI_Certificate_ACP: Matches the attribute 1 in attribute group 'group1'. Checking the next attribute.
*Sep 23 17:46:30:042 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: PKI_Certificate_ACP: Matched rule number: 1, which has the action permit, in access control policy 'policy1'. The certificate is trusted.
*Sep 23 17:46:30:043 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: Get verify result from cache successfully.
*Sep 23 17:46:30:044 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: Verify certificate by domain srcb successfully.
*Sep 23 17:46:30:045 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: Get Local keypair successfully.
*Sep 23 17:46:30:045 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: Failed to get local certificate and keypair from cache.
*Sep 23 17:46:30:509 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: PKI_Certificate_ACP: Matches the attribute 1 in attribute group 'group1'. Checking the next attribute.
*Sep 23 17:46:30:509 2026 LHB10-KFEXTLNS-5660 PKI/7/PKI_DEBUG: PKI_Certificate_ACP: Matched rule number: 1, which has the action permit, in access control policy 'policy1'. The certificate is trusted.
*Sep 23 17:46:30:510 2026 LH-5660 PKI/7/PKI_DEBUG: Get verify result from cache successfully.
*Sep 23 17:46:30:511 2026 LH-5660 PKI/7/PKI_DEBUG: Verify certificate by domain srcb successfully.
*Sep 23 17:46:30:512 2026 LH-5660 PKI/7/PKI_DEBUG: Get Local keypair successfully.
*Sep 23 17:46:30:512 2026 LH-5660 PKI/7/PKI_DEBUG: Failed to get local certificate and keypair from cache.
这是VPN配置
acl advanced 3004
rule 0 permit ip source x.x.x.x 0.0.0.15 destination y.y.y.y 0.0.1.255
ipsec policy-template template2 20
transform-set bjrenhangcjwy
security acl 3004
remote-address c.c.c.c
ike-profile bjrenhangcjwy
ipsec transform-set bjrenhangcjwy
esp encryption-algorithm 3des-cbc
esp authentication-algorithm sha1
ike profile bjrenhangcjwy
certificate domain srcb
dpd interval 10 on-demand
match remote identity address c.c.c.c 255.255.255.255
match remote certificate policy1
proposal 3
pki certificate access-control-policy policy1
rule 1 permit group1
pki domain srcb
certificate request from ca
certificate request entity srcb
public-key rsa general name local
undo crl check enable
pki entity srcb
common-name srcb
country cn
locality srcb
organization-unit srcb
organization srcb
ike dpd interval 30 retry 60 periodic
ike identity fqdn srcb
interface GigabitEthernet2/0/0
ipsec apply policy 30
*Sep 23 11:26:36:554 2026 LHB10-KFEXTLNS-5660 IKE/7/PACKET: vrf = 0, local = 112.95.233.24, remote = 183.195.117.253/500 Construct notification packet: CERTIFICATE_UNAVAILABLE.这是最后一行结尾
*Sep 23 11:26:36:554 2026 LHB10-KFEXTLNS-5660 IKE/7/PACKET: vrf = 0, local = 112.95.233.24, remote = 183.195.117.253/500 Construct notification packet: CERTIFICATE_UNAVAILABLE.这是最后一行结尾
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明