Здравствуйте, Пытаюсь настроить ipsec туннельб 1 фаза подключения прохожит нормально, но на второй все обрывается в логе вижу вот что:
WAN Type: Static IP Address (v1.05)
Display time: Friday October 06, 2006 17:16:57
Friday October 06, 2006 17:01:29 Send IKE M1(INIT) : 212.13.138.182 --> 195.68.186.131
Friday October 06, 2006 17:01:30 Receive IKE M2(RESP) : 195.68.186.131 --> 212.13.138.182
Friday October 06, 2006 17:01:30 Try to match with ENC:3DES AUTH:PSK HASH:SHA1 Group:Group2
Friday October 06, 2006 17:01:30 Send IKE M3(KEYINIT) : 212.13.138.182 --> 195.68.186.131
Friday October 06, 2006 17:01:30 Receive IKE M4(KEYRESP) : 195.68.186.131 --> 212.13.138.182
Friday October 06, 2006 17:01:32 Send IKE M5(IDINIT) : 212.13.138.182 --> 195.68.186.131
Friday October 06, 2006 17:01:32 Receive IKE M6(IDRESP) : 195.68.186.131 --> 212.13.138.182
Friday October 06, 2006 17:01:32 IKE Phase1 (ISAKMP SA) established : 195.68.186.131 <-> 212.13.138.182
Friday October 06, 2006 17:01:32 Send IKE Q1(QINIT) : 10.106.8.0 --> 10.107.0.0
Friday October 06, 2006 17:01:33 Receive IKE INFO : 195.68.186.131 --> 212.13.138.182
Friday October 06, 2006 17:01:38 IKED re-TX : QINIT
Friday October 06, 2006 17:01:43 IKED re-TX : QINIT
Friday October 06, 2006 17:01:53 IKED re-TX : QINIT
Friday October 06, 2006 17:02:03 IKED re-TX : QINIT
Friday October 06, 2006 17:02:23 IKED re-TX : QINIT
Friday October 06, 2006 17:02:24 Send IKE (INFO) : delete [10.106.8.0|212.13.138.182]-->[195.68.186.131|10.107.0.0] phase 2
Friday October 06, 2006 17:02:24 IKE phase2 (IPSec SA) remove : 10.106.8.0 <-> 10.107.0.0
Friday October 06, 2006 17:02:24 inbound SPI = 0x5000010, outbound SPI = 0x0
Friday October 06, 2006 17:06:47 Send IKE Q1(QINIT) : 10.106.8.0 --> 10.107.0.0
Friday October 06, 2006 17:06:47 Receive IKE INFO : 195.68.186.131 --> 212.13.138.182
Friday October 06, 2006 17:06:52 IKED re-TX : QINIT
Friday October 06, 2006 17:06:57 IKED re-TX : QINIT
Friday October 06, 2006 17:07:07 IKED re-TX : QINIT
Friday October 06, 2006 17:07:17 IKED re-TX : QINIT
Friday October 06, 2006 17:07:37 IKED re-TX : QINIT
Friday October 06, 2006 17:07:37 Send IKE (INFO) : delete [10.106.8.0|212.13.138.182]-->[195.68.186.131|10.107.0.0] phase 2
Friday October 06, 2006 17:07:37 IKE phase2 (IPSec SA) remove : 10.106.8.0 <-> 10.107.0.0
Friday October 06, 2006 17:07:37 inbound SPI = 0x6000010, outbound SPI = 0x0
Настройки роутера такие же как у вас в FAQ по VPN, настройки соединения в MS ISA 2004 - соответсвуют настройкам роутера. Я не знаю надо ли настраивать отдельно политику ipsec на сервереб впрочем это тоже пробовал, хотя мне кажется, что ISA переписывает настройки самого сервера.
Подскажите, что можно сделать, должно же ведь работать.
|