[sjs_firewall]ping 172.16.1.1
Ping 172.16.1.1 (172.16.1.1): 56 data bytes, press CTRL_C to break
--- Ping statistics for 172.16.1.1 ---
1 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss
[sjs_firewall]dis ike sa
Connection-ID Remote Flag DOI
------------------------------------------------------------------
[sjs_firewall]dis ips
[sjs_firewall]dis ipsec sa
[sjs_firewall]
我都设置的123,肯定没问题。而且看了根本就没有创建隧道。
[sjs_firewall]ping 172.16.1.1 Ping 172.16.1.1 (172.16.1.1): 56 data bytes, press CTRL_C to break --- Ping statistics for 172.16.1.1 --- 1 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss [sjs_firewall]dis ike sa Connection-ID Remote Flag DOI ------------------------------------------------------------------ [sjs_firewall]dis ips [sjs_firewall]dis ipsec sa [sjs_firewall]
域间策略我默认是全部都双向都放通的。
到local的策略也要放通
到local单独放通
都是放通的,始终不行。
测试下两个设备互访访问下对端公网IP
可以ping通。
私网172.16和172.26互访下