DI-804HV 1:
Method: IKE
Local subnet: 10.0.1.0
Local Netmask: 255.255.255.0
Remote subnet: 10.0.0.0
Remote netmask: 255.255.255.0
Preshare key: Key1
Remote ID: ip-address, 195.218.xx.xx
Local ID: ip-address, 195.131.xx.xx
IKE proposal: group2, 3des, md5, 28800, sec
IPSec proposal: group2, esp, 3des, md5, 3600, sec
DI-804HV 2:
Method: IKE
Local subnet: 10.0.2.0
Local Netmask: 255.255.255.0
Remote subnet: 10.0.0.0
Remote netmask: 255.255.255.0
Preshare key: Key2
Remote ID: ip-address, 195.218.xx.xx
Local ID: ip-address, 84.204.xx.xx
IKE proposal: group2, 3des, md5, 28800, sec
IPSec proposal: group2, esp, 3des, md5, 3600, sec
---
DFL-800:
Objects/VPN objects/Pre-shared keys:
Key1
Key2
Address book:
Localnet: 10.0.0.0/24
WanIP: 195.218.xx.xx
IPVpn1: 195.131.xx.xx
IPVpn2: 84.204.xx.xx
VPNPool1: 10.0.1.0/24
VPNPool2: 10.0.2.0/24
Interfaces/IPSec tunnels:
Tunnel1:
Local network: localnet
Remote Network: VPNPool1
Remote endpoint: IPVpn1
Encapsulation mode: Tunnel
IKE Algorithms: High, 28800
IPSec Algorithms: High, 3600
IpSec Life time: 0
Authentification: Pre-shared key - Key1
IKE Settings: Main, DH group 2
Tunnel2:
Local network: localnet
Remote Network: VPNPool2
Remote endpoint: IPVpn2
Encapsulation mode: Tunnel
IKE Algorithms: High, 28800
IPSec Algorithms: High, 3600
IpSec Life time: 0
Authentification: Pre-shared key - Key2
IKE Settings: Main, DH group 2
---
Туннель 2 поднимается, туннель 1 - нет.
На 1 DI-804HV в логе:
Monday September 18, 2006 12:52:32 Send IKE M1(INIT) : 195.131.xx.xx --> 195.218.xx.xx
Monday September 18, 2006 12:52:37 IKED re-TX : INIT to 195.218.xx.xx
Monday September 18, 2006 12:52:42 IKED re-TX : INIT to 195.218.xx.xx
Monday September 18, 2006 12:52:52 IKED re-TX : INIT to 195.218.xx.xx
Monday September 18, 2006 12:53:02 IKED re-TX : INIT to 195.218.xx.xx
Monday September 18, 2006 12:53:22 IKED re-TX : INIT to 195.218.xx.xx
Monday September 18, 2006 12:53:23 Send IKE (INFO) : delete 195.131.xx.xx -> 195.218.xx.xx phase 1
Monday September 18, 2006 12:53:23 IKE phase1 (ISAKMP SA) remove : 195.131.xx.xx <-> 195.218.xx.xx
На DFL-800 появляется IKE SA для 195.131.xx.xx
Потом через какое-то время выдается в лог:
Bad logmsg: [2006-09-18 12:55:09] <6>FW: IPSEC: prio=1 Phase-1 [responder] between ipv4(any:0,[0..3]=195.218.xx.xx) and ipv4(any:0,[0..3]=195.131.xx.xx) failed; Timeout.
Провайдер утверждает, что никакие порты не закрыты.
|