MSR路由器旁路部署IPsec VPN 不通。
R1R2出口设备;R3R4旁挂做IPsec VPN,实现内网172互通,(R2 R4配置已经上传,R1 R3类似)
目前配置ike sa 可以建立,ipsec sa无法建立.
debug ipsec all:
<FB1>*Apr 20 14:47:01:788 2019 FB1 IPSEC/7/EVENT: Sent debug message to all nodes, message type is 0x3. *Apr 20 14:47:15:247 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:15:247 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:17:452 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:17:452 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:19:656 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:19:656 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:21:862 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:21:862 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:24:060 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 *Apr 20 14:47:24:060 2019 FB1 IPSEC/7/EVENT: The policy's acl or ike profile does not match the flow, Name = 1, Seqnum = 1 undo debugging all All possible debugging has been turned off.
(0)
最佳答案
The policy's acl or ike profile does not match the flow.
数据流量和acl感兴趣流不匹配,检查下吧,如果做了nat注意nat outbound acl将感兴趣流deny掉
轻轻松松配路由:https://zhiliao.h3c.com/topic/huati/1247
下载常用配置案例参考下
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
3/4不过已经通了