Имеем сеть:
1. Remote computer 192.168.1.50 (mask 255.255.255.0, dg 192.168.1.1)
2. DFL-600 - LAN 192.198.1.1 (mask 255.255.255.0)
3. DFL-600 - WAN xxx.xxx.xxx.67 (mask 255.255.255.192, dg WAN xxx.xxx.xxx.65)
IPSec
4. ISA 2004 WAV WAN xxx.xxx.xxx.66 (mask 255.255.255.192, dg WAN xxx.xxx.xxx.65)
5. IAS 2004 LAN yyy.yyy.yyy.yyy (mask 255.255.255.0)
Настройки DFL-600:
Termination IP xxx.xxx.xxx.66
IKE Mode Main
Encapsulation Tunnel
NAT traversal Normal
IPSec Operation ESP
P1 Proposals
Group 2 28800 3DES MD5
P2 Proposals
Group 2 ESP 20480 3DES HMAC-SHA
Starting Target Host yyy.yyy.yyy.0
Subnet Mask 255.255.255.0
Настройка ISA
Local Tunnel Endpoint: xxx.xxx.xxx.66
Remote Tunnel Endpoint: xxx.xxx.xxx.67
IKE Phase I Parameters:
Mode: Main mode
Encryption: 3DES
Integrity: MD5
Diffie-Hellman group: Group 2 (1024 bit)
Authentication method: Pre-shared secret (---)
Security Association lifetime: 28800 seconds
IKE Phase II Parameters:
Mode: ESP tunnel mode
Encryption: 3DES
Integrity: SHA1
Perfect Forward Secrecy: ON
Diffie-Hellman group: Group 2 (1024 bit)
Time rekeying: ON
Security Association lifetime: 20480 seconds
Kbyte rekeying: OFF
Remote Network 'aaa' IP Subnets:
Subnet: 192.168.1.0/255.255.255.0
Local Network 'Internal' IP Subnets:
Subnet: yyy.yyy.yyy.0/255.255.255.0
Суть такая, что в DFL-600 значения
Starting Target Host yyy.yyy.yyy.0
Subnet Mask 255.255.255.0
заменяются на
Starting Target Host xxx.xxx.xxx.66
Subnet Mask xxx.xxx.xxx.66
тунель не падает, но по нему, есно, ничего идти не может!
Условия эксплуатации идеальные - +18С
|