设置列表 有序列表 无序列表对齐方式 靠左 居中 靠右 hcl2.1.1中无法建立ike sa已确定路由可达,接口未应用策略时,10.1.1.1与10.1.2.1可互相ping通,但display ike sa,如下:无法建立ike sa,请问大神什么原因?配置如下:R1[r1] ip route-static 10.1.2.0 255.255.255.0 1.1.1.2[r1] acl advanced 3101[r1-acl-ipv4-adv-3101] rule permit ip source 10.1.1.0 0.0.0.255 destination10.1.2.0 0.0.0.255[r1] ipsec transform-set tran1[r1-ipsec-transform-set-tran1] encapsulation-mode tunnel[r1-ipsec-transform-set-tran1] protocol esp[r1-ipsec-transform-set-tran1] esp encryption-algorithm aes-cbc-128[r1-ipsec-transform-set-tran1] esp authentication-algorithm sha1[r1] ike keychain keychain1[r1-ike-keychain-keychain1] pre-shared-key address 2.2.2.2 255.255.0.0 key simple123456[r1] ike profile profile1[r1-ike-profile-profile1] keychain keychain1[r1-ike-profile-profile1] local-identity address 1.1.1.1[r1-ike-profile-profile1] match remote identity address 2.2.2.2 255.255.0.0[r1] ipsec policy map1 10 isakmp[r1-ipsec-policy-isakmp-map1-10] remote-address 2.2.2.2[r1-ipsec-policy-isakmp-map1-10] security acl 3101[r1-ipsec-policy-isakmp-map1-10] transform-set tran1[r1-ipsec-policy-isakmp-map1-10] ike-profile profile1[r1] interface gigabitethernet 1/0/1[r1-GigabitEthernet1/0/1] ipsec apply policy map1 R2[r2] ip route-static 10.1.1.0 255.255.255.0 2.2.2.1[r2] acl advanced 3101[r2-acl-ipv4-adv-3101] rule permit ip source 10.1.2.0 0.0.0.255 destination10.1.1.0 0.0.0.255[r2] ipsec transform-set tran1[r2-ipsec-transform-set-tran1] encapsulation-mode tunnel[r2-ipsec-transform-set-tran1] protocol esp[r2-ipsec-transform-set-tran1] esp encryption-algorithm aes-cbc-128[r2-ipsec-transform-set-tran1] esp authentication-algorithm sha1[r2]ike keychain keychain1[r2-ike-keychain-keychain1] pre-shared-key address 1.1.1.1 255.255.0.0 key simple123456[r2] ike profile profile1[r2-ike-profile-profile1] keychain keychain1[r2-ike-profile-profile1] local-identity address 2.2.2.2[r2-ike-profile-profile1] match remote identity address 1.1.1.1 255.255.0.0[r2] ipsec policy use1 10 isakmp[r2-ipsec-policy-isakmp-use1-10] remote-address 1.1.1.1[r2-ipsec-policy-isakmp-use1-10] security acl 3101[r2-ipsec-policy-isakmp-use1-10] transform-set tran1[r2-ipsec-policy-isakmp-use1-10] ike-profile profile1[r2] interface gigabitethernet 1/0/1[r2-GigabitEthernet1/0/1] ipsec apply policy use1
设置列表 有序列表 无序列表对齐方式 靠左 居中 靠右 hcl2.1.1中无法建立ike sa已确定路由可达,接口未应用策略时,10.1.1.1与10.1.2.1可互相ping通,但display ike sa,如下:无法建立ike sa,请问大神什么原因?配置如下:R1[r1] ip route-static 10.1.2.0 255.255.255.0 1.1.1.2[r1] acl advanced 3101[r1-acl-ipv4-adv-3101] rule permit ip source 10.1.1.0 0.0.0.255 destination10.1.2.0 0.0.0.255[r1] ipsec transform-set tran1[r1-ipsec-transform-set-tran1] encapsulation-mode tunnel[r1-ipsec-transform-set-tran1] protocol esp[r1-ipsec-transform-set-tran1] esp encryption-algorithm aes-cbc-128[r1-ipsec-transform-set-tran1] esp authentication-algorithm sha1[r1] ike keychain keychain1[r1-ike-keychain-keychain1] pre-shared-key address 2.2.2.2 255.255.0.0 key simple123456[r1] ike profile profile1[r1-ike-profile-profile1] keychain keychain1[r1-ike-profile-profile1] local-identity address 1.1.1.1[r1-ike-profile-profile1] match remote identity address 2.2.2.2 255.255.0.0[r1] ipsec policy map1 10 isakmp[r1-ipsec-policy-isakmp-map1-10] remote-address 2.2.2.2[r1-ipsec-policy-isakmp-map1-10] security acl 3101[r1-ipsec-policy-isakmp-map1-10] transform-set tran1[r1-ipsec-policy-isakmp-map1-10] ike-profile profile1[r1] interface gigabitethernet 1/0/1[r1-GigabitEthernet1/0/1] ipsec apply policy map1 R2[r2] ip route-static 10.1.1.0 255.255.255.0 2.2.2.1[r2] acl advanced 3101[r2-acl-ipv4-adv-3101] rule permit ip source 10.1.2.0 0.0.0.255 destination10.1.1.0 0.0.0.255[r2] ipsec transform-set tran1[r2-ipsec-transform-set-tran1] encapsulation-mode tunnel[r2-ipsec-transform-set-tran1] protocol esp[r2-ipsec-transform-set-tran1] esp encryption-algorithm aes-cbc-128[r2-ipsec-transform-set-tran1] esp authentication-algorithm sha1[r2]ike keychain keychain1[r2-ike-keychain-keychain1] pre-shared-key address 1.1.1.1 255.255.0.0 key simple123456[r2] ike profile profile1[r2-ike-profile-profile1] keychain keychain1[r2-ike-profile-profile1] local-identity address 2.2.2.2[r2-ike-profile-profile1] match remote identity address 1.1.1.1 255.255.0.0[r2] ipsec policy use1 10 isakmp[r2-ipsec-policy-isakmp-use1-10] remote-address 1.1.1.1[r2-ipsec-policy-isakmp-use1-10] security acl 3101[r2-ipsec-policy-isakmp-use1-10] transform-set tran1[r2-ipsec-policy-isakmp-use1-10] ike-profile profile1[r2] interface gigabitethernet 1/0/1[r2-GigabitEthernet1/0/1] ipsec apply policy use1
(0)
最佳答案
格式太乱了,一般IKE无法建立,配置问题比较大,检查一下两边的密码是否一致,可以写个简单的,比如123456,再看一下ike profile里的match remote写的对不对,这个要写对面的标识,比如接口IP地址什么的,然后就是要看ike proposal是否一致,这个有默认配置,可以不配置,还有就是acl的rule,两边是否为镜像配置。
还有就是IPsec policy下的remote-address,这个一定要配置
(0)
你这格式没法看啊
第一步 查看两边是否可达对端的公网ip地址
第二步查看acl,看看你的ipsec流量是否被匹配,注意要在配置nat时将ipsec流量拒绝
第三步 你打开DEBUG IKE ERROR 和DEBUG IPSEC error,看看报什么错
(0)
兄弟,能把你这个拓扑导出发一份到我邮箱,我来排下错,谢谢,邮箱是54557404@qq.com,你也可以来我qq,我们有专业的群,大家可以一起交流
请问下怎么调格式?我从WPS里面直接复制粘贴的
我没有配nat debug显示: The reason of dropping packet is no available IPsec tunnel. The reason of dropping packet is no available IPsec tunnel. <r1>dis ipsec policy ------------------------------------------- IPsec Policy: map1 Interface: GigabitEthernet0/1 ------------------------------------------- ----------------------------- Sequence number: 10 Mode: ISAKMP ----------------------------- Traffic Flow Confidentiality: Disabled Security data flow: 3101 Selector mode: standard Local address: 1.1.1.1 Remote address: 2.2.2.2 Transform set: tran1 IKE profile: profile1 IKEv2 profile: SA duration(time based): 3600 seconds SA duration(traffic based): 1843200 kilobytes SA idle time: <r1>
dis acl all查看你的感兴趣流是否匹配了吗?你要把DEBUG IKE ERROR 也打开
我在用HCL做实验时,你把IKE PROFILE里面的 local-identity address 这个去掉
不知道是不是模拟器bug
看了下你的配置没啥问题,把刚刚说的去掉,如果不行,把acl删除重新建吧(我遇到这种情况的)
兄弟,能把你这个拓扑导出发一份到我邮箱,我来排下错,谢谢,邮箱是54557404@qq.com,你也可以来我qq,我们有专业的群,大家可以一起交流
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
我配的密码就是123456,match remote identity address 1.1.1.1 255.255.0.0也没问题,ike用的默认配置,acl两端为镜像配置,remote-address也配了,可就是不行