Соответствующий фрагмент лога:
Цитата:
Friday April 29, 2011 07:49:23 Send IKE M1(INIT) : 192.168.200.2 --> 62.118.0.3
Friday April 29, 2011 07:49:24 Receive IKE M2(RESP) : 62.118.0.3 --> 192.168.200.2
Friday April 29, 2011 07:49:24 Try to match with ENC:3DES AUTH:PSK HASH:SHA1 Group:Group2
Friday April 29, 2011 07:49:24 Send IKE M3(KEYINIT) : 192.168.200.2 --> 62.118.0.3
Friday April 29, 2011 07:49:24 Receive IKE M4(KEYRESP) : 62.118.0.3 --> 192.168.200.2
Friday April 29, 2011 07:49:24 Send IKE M5(IDINIT) : 192.168.200.2 --> 62.118.0.3
Friday April 29, 2011 07:49:24 Receive IKE M6(IDRESP) : 62.118.0.3 --> 192.168.200.2
Friday April 29, 2011 07:49:24 IKE Phase1 (ISAKMP SA) established : 62.118.0.3 <-> 192.168.200.2
Friday April 29, 2011 07:49:24 Send IKE Q1(QINIT) : 192.168.26.72 --> 192.168.1.0
Friday April 29, 2011 07:49:25 Receive IKE Q2(QRESP) : [192.168.1.0|62.118.0.3]-->[192.168.200.2|192.168.26.72]
Friday April 29, 2011 07:49:25 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group2
Friday April 29, 2011 07:49:25 Send IKE Q3(QHASH) : 192.168.26.72 --> 192.168.1.0
Friday April 29, 2011 07:49:25 IKE Phase2 (IPSEC SA) established : [192.168.1.0|62.118.0.3]<->[192.168.200.2|192.168.26.72]
Friday April 29, 2011 07:49:25 inbound SPI = 0x18006c58, outbound SPI = 0x2816e115
Friday April 29, 2011 07:49:41 IPSec tunnel keep alive : peer IP 192.168.1.1
Friday April 29, 2011 07:49:41 [192.168.26.72|192.168.200.2]-->[62.118.0.3|192.168.1.0]
Friday April 29, 2011 07:49:57 IPSec tunnel keep alive : peer IP 192.168.1.1
Friday April 29, 2011 07:49:57 [192.168.26.72|192.168.200.2]-->[62.118.0.3|192.168.1.0]
Friday April 29, 2011 07:50:13 IPSec tunnel keep alive : peer IP 192.168.1.1
Friday April 29, 2011 07:50:13 [192.168.26.72|192.168.200.2]-->[62.118.0.3|192.168.1.0]
Friday April 29, 2011 07:50:29 IPSec tunnel keep alive : peer IP 192.168.1.1
Friday April 29, 2011 07:50:29 [192.168.26.72|192.168.200.2]-->[62.118.0.3|192.168.1.0]
Friday April 29, 2011 07:50:45 IPSec tunnel keep alive : peer IP 192.168.1.1
Friday April 29, 2011 07:50:45 [192.168.26.72|192.168.200.2]-->[62.118.0.3|192.168.1.0]
Friday April 29, 2011 07:50:56 Warming : delete IPSec tunnel because remote subnet no response
Friday April 29, 2011 07:50:56 Send IKE (INFO) : delete [192.168.26.72|192.168.200.2]-->[62.118.0.3|192.168.1.0] phase 2
Friday April 29, 2011 07:50:56 IKE phase2 (IPSec SA) remove : 192.168.26.72 <-> 192.168.1.0
Похоже на то, что где-то ESP то фильтруется, то не фильтруется, или есть основания подозревать мою собственную криворукость?
Включение-выключение NAT-T ничего не меняет.