<H3C>dis ike sa
Connection-ID Remote Flag DOI
------------------------------------------------------------------
8095 140.206.97.82 RD IPsec
Flags:
RD--READY RL--REPLACED FD-FADING RK-REKEY
<H3C>dis ipsec sa
-------------------------------
Interface: GigabitEthernet1/0/1
-------------------------------
-----------------------------
IPsec policy: GE1/0/1
Sequence number: 1
Mode: ISAKMP
-----------------------------
Tunnel id: 0
Encapsulation mode: tunnel
Perfect Forward Secrecy: dh-group2
Inside VPN:
Extended Sequence Numbers enable: N
Traffic Flow Confidentiality enable: N
Path MTU: 1444
Tunnel:
local address: 180.165.126.126
remote address: 140.206.97.82
Flow:
sour addr: 172.16.1.0/255.255.255.0 port: 0 protocol: ip
dest addr: 172.16.45.0/255.255.255.0 port: 0 protocol: ip
[Inbound ESP SAs]
SPI: 3175925396 (0xbd4cc694)
Connection ID: 21474836480
Transform set: ESP-ENCRYPT-3DES-CBC ESP-AUTH-SHA1
SA duration (kilobytes/sec): 1843200/28800
SA remaining duration (kilobytes/sec): 1843200/28392
Max received sequence-number: 0
Anti-replay check enable: Y
Anti-replay window size: 64
UDP encapsulation used for NAT traversal: N
Status: Active
[Outbound ESP SAs]
SPI: 3920204953 (0xe9a99499)
Connection ID: 4294967297
Transform set: ESP-ENCRYPT-3DES-CBC ESP-AUTH-SHA1
SA duration (kilobytes/sec): 1843200/28800
SA remaining duration (kilobytes/sec): 1843200/28392
Max sent sequence-number: 0
UDP encapsulation used for NAT traversal: N
Status: Active
<H3C>dis ipsec statistics
IPsec packet statistics:
Received/sent packets: 0/0
Received/sent bytes: 0/0
Dropped packets (received/sent): 30/8
Dropped packets statistics
No available SA: 38
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Encapsulation failure: 0
Decapsulation failure: 0
Replayed packets: 0
ACL check failure: 0
MTU check failure: 0
Loopback limit exceeded: 0
Crypto speed limit exceeded: 0
<H3C>
<H3C>dis ipsec sa brief
-----------------------------------------------------------------------------
Interface/Global Dst Address SPI Protocol Status
-----------------------------------------------------------------------------
GE1/0/1 140.206.97.82 3920204953 ESP Active
GE1/0/1 180.165.126.12 3175925396 ESP Active
6
<H3C>
(0)
最佳答案
看着两个阶段都起来了,可以ping一下,然后在设备上看下会话,看收发包统计。
(0)
都是drop的包。这是为什么?对端的acl问题么? Dropped packets (received/sent): 30/8
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
都是drop的包。这是为什么?对端的acl问题么? Dropped packets (received/sent): 30/8