之前一直使用ipsec偶VPN连接,最近突然出现发起端可以ping通对端,接收端无法ping通发起端的情况,发起端所有的设备无变动,配置无变动。接收端配置信息如下。
此图为发起端配置
以下为接收端配置
(0)
最佳答案
需要看一下故障时候dis ike sa和dis ipsec sa是否都有。另外要检查一下两端的路由对不对。
(0)
这个是我测试的摸一个网段,IKE sa 和ipsec sa 应该是都有 <H3C>dis ike sa Connection-ID Remote Flag DOI ------------------------------------------------------------------ 5 49.80.156.127 RD IPsec 2 110.83.16.88 RD IPsec 6 112.86.4.226 RD IPsec 3 180.113.172.24 RD IPsec 15 27.156.26.80 RD IPsec 7 27.155.238.36 RD IPsec 82 117.80.106.252 RD IPsec 20 111.175.84.83 RD IPsec 8 171.43.215.145 RD IPsec 88 27.156.26.140 Unknown IPsec 84 59.173.154.190 RD IPsec 67 59.173.154.190 RD|RL IPsec Flags: RD--READY RL--REPLACED FD-FADING RK-REKEY <H3C>dis ipsec sa ------------------------------- Interface: GigabitEthernet0/0 ----------------------------- IPsec policy: zb100 Sequence number: 3 Mode: Template ----------------------------- Tunnel id: 0 Encapsulation mode: tunnel Perfect Forward Secrecy: dh-group2 Inside VPN: Extended Sequence Numbers enable: N Traffic Flow Confidentiality enable: N Path MTU: 1444 Tunnel: local address: 58.215.215.146 remote address: 111.175.84.83 Flow: sour addr: 192.168.100.0/255.255.255.0 port: 0 protocol: ip dest addr: 192.168.6.0/255.255.255.0 port: 0 protocol: ip [Inbound ESP SAs] SPI: 3161781874 (0xbc74f672) Connection ID: 30064771074 Transform set: ESP-ENCRYPT-3DES-CBC ESP-AUTH-MD5 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1831672/2550 Max received sequence-number: 63663 Anti-replay check enable: Y Anti-replay window size: 64 UDP encapsulation used for NAT traversal: N Status: Active [Outbound ESP SAs] SPI: 453548495 (0x1b0899cf) Connection ID: 30064771075 Transform set: ESP-ENCRYPT-3DES-CBC ESP-AUTH-MD5 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1835358/2550 Max sent sequence-number: 61596 UDP encapsulation used for NAT traversal: N Status: Active
您好,请知:
(1)
路由不可达,sa和ike有存在。 您给的命令会报错。 Unrecognized command found at '^' position. 虽然命令没有执行,不过我重启过设备。情况依旧、
路由不可达,sa和ike有存在。 您给的命令会报错。 Unrecognized command found at '^' position. 虽然命令没有执行,不过我重启过设备。情况依旧、
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
这个是我测试的摸一个网段,IKE sa 和ipsec sa 应该是都有 <H3C>dis ike sa Connection-ID Remote Flag DOI ------------------------------------------------------------------ 5 49.80.156.127 RD IPsec 2 110.83.16.88 RD IPsec 6 112.86.4.226 RD IPsec 3 180.113.172.24 RD IPsec 15 27.156.26.80 RD IPsec 7 27.155.238.36 RD IPsec 82 117.80.106.252 RD IPsec 20 111.175.84.83 RD IPsec 8 171.43.215.145 RD IPsec 88 27.156.26.140 Unknown IPsec 84 59.173.154.190 RD IPsec 67 59.173.154.190 RD|RL IPsec Flags: RD--READY RL--REPLACED FD-FADING RK-REKEY <H3C>dis ipsec sa ------------------------------- Interface: GigabitEthernet0/0 ----------------------------- IPsec policy: zb100 Sequence number: 3 Mode: Template ----------------------------- Tunnel id: 0 Encapsulation mode: tunnel Perfect Forward Secrecy: dh-group2 Inside VPN: Extended Sequence Numbers enable: N Traffic Flow Confidentiality enable: N Path MTU: 1444 Tunnel: local address: 58.215.215.146 remote address: 111.175.84.83 Flow: sour addr: 192.168.100.0/255.255.255.0 port: 0 protocol: ip dest addr: 192.168.6.0/255.255.255.0 port: 0 protocol: ip [Inbound ESP SAs] SPI: 3161781874 (0xbc74f672) Connection ID: 30064771074 Transform set: ESP-ENCRYPT-3DES-CBC ESP-AUTH-MD5 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1831672/2550 Max received sequence-number: 63663 Anti-replay check enable: Y Anti-replay window size: 64 UDP encapsulation used for NAT traversal: N Status: Active [Outbound ESP SAs] SPI: 453548495 (0x1b0899cf) Connection ID: 30064771075 Transform set: ESP-ENCRYPT-3DES-CBC ESP-AUTH-MD5 SA duration (kilobytes/sec): 1843200/3600 SA remaining duration (kilobytes/sec): 1835358/2550 Max sent sequence-number: 61596 UDP encapsulation used for NAT traversal: N Status: Active