DFL-1500
Firmware Version: NetOS Ver2.115 (WALL) #b
DFL-700
Firmware version: 1.35.00-PRE001
DFL-200
Firmware: 1.33.00-SU1
Согласно FAQ настроил Ipsec между DFL-1500 и DFL-700
параметры Ipsec на стороне DFL-1500
Name - Sh
Local Address:
Subnet Adress
Ip 172.16.1.0
Subnet Mask 255.255.252.0
Remote Address:
Subnet Address:
Ip 192.168.0.0
Mask: 255.255.255.0
Negotiation Mode - Main
Encapsulation Mode - Tunnel
Outgoing Interface - WAN1
Peer Ip Address - Static IP - 81.222.44.**
My Identifier - Ip address
Peer`s Identifier - Ip address
ESP algorithm - Encrypt and Autenticate DES, MD5
PreSharedKey 852963
Transport Layer Protocol - ANY
Enable Replay Detection - NO
PHASE 1
Negotiation Mode - MAIN
Pre-Shared key 852963
Encryption Algorithm - Encrypt and Autenticate (DES,MD5)
SA Life Time - 28800 sec
Key Group - DH2
PHASE 2
Encapsulation - Tunnnel
Active Protocol - ESP
Encryption Algorithm - Encrypt and Autenticate (DES,MD5)
SA Life Time - 28800 sec
PFS - DH1
Параметры на стороне DFL-700
Name Sh
Local Net: 192.168.0.0/24
Autentification - PSK
PSK - 852963
Lan-to-Lan tunnel
Remote Net: 172.16.1.0-172.16.2.254
Remote Gateway: 81.222.44.**
Route - Automatically add a route for the remote networks
Limit MTU - 1424
IKE Mode - Main mode IKE
IKE DH-group - 2 modp 1024 bit
Enable PFS
PFS Dh-group - 1 modp 768 bit
Nat Traversal - disabled
KeepAlives - No Keepalives
IKE Proposal list
DES MD5 0kb 28800sec
- MD5 0 28800
IPsec proposal list
DES MD5 0kb 28800sec
- MD5 0 28800
(Точно такие же настройки пробовал вбивать для теста и на DFL-200)
После пробного пинга и попытки установить туннель, в логах DFL-1500 пишется следующее, и туннель не устанавливается:
29 2007-10-17 15:30:16 INFO Respond new phase 1 negotiation: 81.222.44.1*:500<=>81.222.44.2*:500
30 2007-10-17 15:30:16 INFO Begin Identity Protection mode.
31 2007-10-17 15:30:16 INFO received Vendor ID: DPD
32 2007-10-17 15:30:16 INFO received Vendor ID: draft-ietf-ipsec-nat-t-ike-00
33 2007-10-17 15:30:16 INFO received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
34 2007-10-17 15:30:16 INFO received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
35 2007-10-17 15:30:16 INFO received Vendor ID: draft-ietf-ipsec-nat-t-ike-03
36 2007-10-17 15:30:16 WARNING Ignore INITIAL-CONTACT notification, because it is only accepted after...
37 2007-10-17 15:30:16 INFO ISAKMP-SA established 81.222.44.1*:500-81.222.44.2*:500
38 2007-10-17 15:30:17 INFO Respond new phase 2 negotiation: 81.222.44.4*:0<=>81.222.44.2*:0
39 2007-10-17 15:30:17 ERROR Failed to get sainfo.
40 2007-10-17 15:30:17 ERROR Failed to get sainfo.
41 2007-10-17 15:30:17 ERROR Failed to pre-process Packet.
42 2007-10-17 15:30:17 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
43 2007-10-17 15:30:17 ERROR Failed to get sainfo.
44 2007-10-17 15:30:17 ERROR Failed to get sainfo.
45 2007-10-17 15:30:17 ERROR Failed to pre-process Packet.
46 2007-10-17 15:30:18 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
47 2007-10-17 15:30:18 ERROR Failed to get sainfo.
48 2007-10-17 15:30:18 ERROR Failed to get sainfo.
49 2007-10-17 15:30:18 ERROR Failed to pre-process Packet.
50 2007-10-17 15:30:20 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
51 2007-10-17 15:30:20 ERROR Failed to get sainfo.
52 2007-10-17 15:30:20 ERROR Failed to get sainfo.
53 2007-10-17 15:30:20 ERROR Failed to pre-process Packet.
54 2007-10-17 15:30:24 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
55 2007-10-17 15:30:24 ERROR Failed to get sainfo.
56 2007-10-17 15:30:24 ERROR Failed to get sainfo.
57 2007-10-17 15:30:24 ERROR Failed to pre-process Packet.
58 2007-10-17 15:30:32 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
59 2007-10-17 15:30:32 ERROR Failed to get sainfo.
60 2007-10-17 15:30:32 ERROR Failed to get sainfo.
61 2007-10-17 15:30:32 ERROR Failed to pre-process Packet.
62 2007-10-17 15:30:48 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
63 2007-10-17 15:30:48 ERROR Failed to get sainfo.
64 2007-10-17 15:30:48 ERROR Failed to get sainfo.
65 2007-10-17 15:30:48 ERROR Failed to pre-process Packet.
66 2007-10-17 15:31:18 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
67 2007-10-17 15:31:18 ERROR Failed to get sainfo.
68 2007-10-17 15:31:18 ERROR Failed to get sainfo.
69 2007-10-17 15:31:18 ERROR Failed to pre-process Packet.
70 2007-10-17 15:31:48 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
71 2007-10-17 15:31:48 ERROR Failed to get sainfo.
72 2007-10-17 15:31:48 ERROR Failed to get sainfo.
73 2007-10-17 15:31:48 ERROR Failed to pre-process Packet.
74 2007-10-17 15:32:18 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
75 2007-10-17 15:32:18 ERROR Failed to get sainfo.
76 2007-10-17 15:32:18 ERROR Failed to get sainfo.
77 2007-10-17 15:32:18 ERROR Failed to pre-process Packet.
78 2007-10-17 15:32:48 INFO Respond new phase 2 negotiation: 81.222.44.1*:0<=>81.222.44.2*:0
79 2007-10-17 15:32:48 ERROR Failed to get sainfo.
80 2007-10-17 15:32:48 ERROR Failed to get sainfo.
81 2007-10-17 15:32:48 ERROR Failed to pre-process Packet.
После этого вновь идет первая фаза, и ситуация повторяется.
Т.е. ни DFL-700 ни DFL-200 не могут установить IPsec туннель с DFL-1500
физически данные устройства находятся в подсети одного провайдера (отличаются только последние цифры айпи адреса).
Уважаемый support, подскажите, как можно решить данную проблему..
Поиском нашел точно такую же проблему на данному форуме, но ответа там также не было.
viewtopic.php?t=13001