Вот логи. 10.0.1.1 - внешний IP DFL-800, 10.0.2.1 - внешний IP DI-804.
Логи DI-804:
Код:
Wednesday February 21, 2007 11:44:14 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:15 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:15 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:15 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:15 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:44:15 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:44:15 inbound SPI = 0xbd000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:44:15 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:44:16 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:16 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:16 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:16 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:16 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:17 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:17 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:17 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:18 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:18 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:44:18 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:44:18 inbound SPI = 0xbe000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:44:48 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:48 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:49 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:49 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:49 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:49 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:49 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:44:49 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:44:48 inbound SPI = 0xcb000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:44:48 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:44:48 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:44:48 inbound SPI = 0xca000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:44:49 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:44:50 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:50 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:44:50 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:44:50 inbound SPI = 0xcc000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:44:50 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:44:51 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:44:51 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:02 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:02 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:02 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:02 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:45:02 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:45:02 inbound SPI = 0xda000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:45:03 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:45:03 Receive IKE INFO : 10.0.1.1 --> 10.0.2.1
Wednesday February 21, 2007 11:45:01 Receive IKE (INFO) : delete 10.0.1.1 -> 10.0.2.1 phase 1
Wednesday February 21, 2007 11:45:01 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:45:01 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:45:01 inbound SPI = 0x0, outbound SPI = 0x0
Wednesday February 21, 2007 11:45:01 Send IKE (INFO) : delete 10.0.2.1 -> 10.0.1.1 phase 1
Wednesday February 21, 2007 11:45:01 IKE phase1 (ISAKMP SA) remove : 10.0.2.1 <-> 10.0.1.1
Wednesday February 21, 2007 11:45:02 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:45:02 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:02 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:03 Receive IKE M1(INIT) : 10.0.1.1 --> 10.0.2.1
Wednesday February 21, 2007 11:45:03 Try to match with ENC:3DES AUTH:PSK HASH:SHA1 Group:Group5
Wednesday February 21, 2007 11:45:04 Send IKE M2(RESP) : 10.0.2.1 --> 10.0.1.1
Wednesday February 21, 2007 11:45:31 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:31 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:31 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:31 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:45:31 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:45:31 inbound SPI = 0xe7000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:45:32 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:45:33 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:33 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:33 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:33 Blocked access attempt from 84.152.206.146:1845 to TCP port 139
Wednesday February 21, 2007 11:45:34 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:34 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:34 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:34 IKED re-TX : QINIT to 10.0.1.1
Wednesday February 21, 2007 11:45:34 Send IKE (INFO) : delete [192.168.4.0|10.0.2.1]-->[10.0.1.1|192.168.0.0] phase 2
Wednesday February 21, 2007 11:45:34 IKE phase2 (IPSec SA) remove : 192.168.4.0 <-> 192.168.0.0
Wednesday February 21, 2007 11:45:34 inbound SPI = 0xe8000010, outbound SPI = 0x0
Wednesday February 21, 2007 11:45:34 Send IKE Q1(QINIT) : 192.168.4.0 --> 192.168.0.0
Wednesday February 21, 2007 11:45:35 IKED re-TX : QINIT to 10.0.1.1
А вот логи DFL-800:
Код:
2007-02-21
11:41:49 Info IPSEC
01802703
ike_sa_negotiation_completed
ike_sa_completed
rev=1 local_peer="10.0.1.1 ID 10.0.1.1" remote_peer="10.0.2.1 ID 10.0.2.1" spis="Initiator SPI 996590f6
48887663 Responder SPI 3cbc
2007-02-21
11:41:49 Info IPSEC
01802024
ike_sa_negotiation_completed
rev=1 options=Initiator mode=Main Mode auth=Pre-shared keys encryption=3des-cbc keysize= hash=sha1
dhgroup=5 bits=1536 lifetime=28800
2007-02-21
11:41:49 Info IPSEC
01800102
ipsec_event
rev=1 message=""
2007-02-21
11:41:48 Info IPSEC
01803021
ipsec_sa_statistics
rev=1 done=8240 success=1404 failed=6836
2007-02-21
11:41:48 Warning IPSEC
01803020
ipsec_sa_failed
no_ipsec_sa
rev=1 statusmsg="Timeout"
2007-02-21
11:41:48 Info IPSEC
01800102
ipsec_event
rev=1 message=""
2007-02-21
11:41:48 Info IPSEC
01800102
ipsec_event
rev=1 message=" Remote Proxy ID 192.168.4.0/24 any"
2007-02-21
11:41:48 Info IPSEC
01800102
ipsec_event
rev=1 message=" Local Proxy ID 192.168.0.0/16 any"
2007-02-21
11:41:48 Info IPSEC
01802704
ike_sa_negotiation_completed
ike_sa_completed
rev=1 local_peer="10.0.1.1 ID 10.0.1.1" remote_peer="10.0.2.1 ID 10.0.2.1" int_severity=6
2007-02-21
11:41:48 Info IPSEC
01800102
ipsec_event
rev=1 message="IPSec SA [Initiator] negotiation failed:"
2007-02-21
11:41:48 Info IPSEC
01800102
ipsec_event
rev=1 message=""
2007-02-21
11:41:47 Info IPSEC
01802708
ike_sa_destroyed
ike_sa_killed
rev=1 ike_sa= Initiator SPI ESP=0x19d5e287, AH=0x607a9c8d, IPComp=0x7570fc3
2007-02-21
11:40:48 Info IPSEC
01802703
ike_sa_negotiation_completed
ike_sa_completed
rev=1 local_peer="10.0.1.1 ID 10.0.1.1" remote_peer="10.0.2.1 ID 10.0.2.1" spis="Initiator SPI 3512233c
42c6157a Responder SPI 13c7
2007-02-21
11:40:48 Info IPSEC
01802024
ike_sa_negotiation_completed
rev=1 options=Initiator mode=Main Mode auth=Pre-shared keys encryption=3des-cbc keysize= hash=sha1
dhgroup=5 bits=1536 lifetime=28800
2007-02-21
11:40:48 Info IPSEC
01800102
ipsec_event
rev=1 message=""
2007-02-21
11:40:47 Info IPSEC
01803021
ipsec_sa_statistics
rev=1 done=8239 success=1404 failed=6835
2007-02-21
11:40:47 Warning IPSEC
01803020
ipsec_sa_failed
no_ipsec_sa
rev=1 statusmsg="Timeout"
2007-02-21
11:40:47 Info IPSEC
01800102
ipsec_event
rev=1 message=""
2007-02-21
11:40:47 Info IPSEC
01800102
ipsec_event
rev=1 message=" Remote Proxy ID 192.168.4.0/24 any"
2007-02-21
11:40:47 Info IPSEC
01800102
ipsec_event
rev=1 message=" Local Proxy ID 192.168.0.0/16 any"
2007-02-21
11:40:47 Info IPSEC
01802704
ike_sa_negotiation_completed
ike_sa_completed
rev=1 local_peer="10.0.1.1 ID 10.0.1.1" remote_peer="10.0.2.1 ID 10.0.2.1" int_severity=6
2007-02-21
11:40:47 Info IPSEC
01800102
ipsec_event
rev=1 message="IPSec SA [Initiator] negotiation failed:"
2007-02-21
11:40:47 Info IPSEC
01800102
ipsec_event
rev=1 message=""
2007-02-21
11:40:45 Info IPSEC
01802708
ike_sa_destroyed
ike_sa_killed
rev=1 ike_sa= Initiator SPI ESP=0xcaac7590, AH=0x8b739802, IPComp=0x9d71432