DI-804hv.
схема сети:
192.168.2.0 --> di-804hv --> [di-804hv (Центр. офис)] <-- di-804hv <-- 192.168.10.0
Адреса WAN все белые. Повторюсь: иногда все работает, а иногда как сейчас - в VPN Status тоннель стоит, время жизни идет, а пинга нет.
Вот часть логов, может поможет:
Monday July 25, 2005 09:07:27 IKED re-TX : INIT to ххх.ххх.ххх.4
Monday July 25, 2005 08:39:08 Receive IKE Q1(QINIT) : [ххх.ххх.ххх.4]-->[ххх.ххх.ххх.3]
Monday July 25, 2005 08:39:08 Requested routing is [192.168.2.0|ххх.ххх.ххх.4]<->[ххх.ххх.ххх.3|192.168.1.0]
Monday July 25, 2005 08:39:08 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:MD5 HASH:Others PFS(Group):Group1
Monday July 25, 2005 08:39:08 Send IKE Q2(QRESP) : 192.168.1.0 --> 192.168.2.0
Monday July 25, 2005 08:39:08 Receive IKE Q3(QHASH) : [192.168.2.0|ххх.ххх.ххх.4]-->[ххх.ххх.ххх.3|192.168.1.0]
Monday July 25, 2005 08:39:08 IKE Phase2 (IPSEC SA) established : [192.168.2.0|ххх.ххх.ххх.4]<->[ххх.ххх.ххх.3|192.168.1.0]
Monday July 25, 2005 08:39:08 inbound SPI = 0xххх00010, outbound SPI = 0xххх0010
Monday July 25, 2005 08:40:38 Blocked access attempt from 80.227.112.18:30652 to TCP port 15118
Monday July 25, 2005 08:40:41 Blocked access attempt from 80.227.112.18:30652 to TCP port 15118
Monday July 25, 2005 08:47:40 Blocked access attempt from 61.142.245.227:80 to TCP port 58781
Monday July 25, 2005 08:47:43 Blocked access attempt from 61.142.245.227:80 to TCP port 58781
Monday July 25, 2005 08:47:49 Blocked access attempt from 61.142.245.227:80 to TCP port 58781
Monday July 25, 2005 08:48:30 Blocked access attempt from 61.142.245.227:80 to TCP port 58897
Monday July 25, 2005 08:48:33 Blocked access attempt from 61.142.245.227:80 to TCP port 58897
Monday July 25, 2005 08:50:32 Blocked access attempt from 61.142.245.227:80 to TCP port 59043
Monday July 25, 2005 08:50:41 Blocked access attempt from 61.142.245.227:80 to TCP port 59043
Monday July 25, 2005 08:51:25 Blocked access attempt from 61.142.245.227:80 to TCP port 59107
Monday July 25, 2005 08:51:31 Blocked access attempt from 61.142.245.227:80 to TCP port 59107
Monday July 25, 2005 09:06:54 Send IKE (INFO) : delete [192.168.1.0|ххх.ххх.ххх.3]-->[ххх.ххх.ххх.4|192.168.2.0] phase 2
Спасибо.
|