George Shot писал(а):
поднять VPN м-у D-Link DI808/Zyxel 791 и Zyxel 792
А теперь будут слайды:
D-Link log:
Thursday May 11, 2006 19:24:22 Receive IKE INFO : yyy.yyy.yyy.yyy --> xxx.xxx.xxx.xxx
Thursday May 11, 2006 19:24:22 Receive IKE (INFO) : delete yyy.yyy.yyy.yyy -> xxx.xxx.xxx.xxx phase 1
Thursday May 11, 2006 19:24:22 Send IKE (INFO) : delete [192.168.0.0|xxx.xxx.xxx.xxx]-->[yyy.yyy.yyy.yyy|192.168.12.0] phase 2
Thursday May 11, 2006 19:24:22 IKE phase2 (IPSec SA) remove : 192.168.0.0 <-> 192.168.12.0
Thursday May 11, 2006 19:24:22 inbound SPI = 0x0, outbound SPI = 0x0
Thursday May 11, 2006 19:24:22 Send IKE (INFO) : delete xxx.xxx.xxx.xxx -> yyy.yyy.yyy.yyy phase 1
Thursday May 11, 2006 19:24:22 IKE phase1 (ISAKMP SA) remove : xxx.xxx.xxx.xxx <-> yyy.yyy.yyy.yyy
Thursday May 11, 2006 19:24:23 Receive IKE M1(INIT) : yyy.yyy.yyy.yyy --> xxx.xxx.xxx.xxx
Thursday May 11, 2006 19:24:23 Try to match with ENC:3DES AUTH:PSK HASH:SHA1 Group:Group1
Thursday May 11, 2006 19:24:23 Send IKE M2(RESP) : xxx.xxx.xxx.xxx --> yyy.yyy.yyy.yyy
Thursday May 11, 2006 19:24:24 Receive IKE M3(KEYINIT) : yyy.yyy.yyy.yyy --> xxx.xxx.xxx.xxx
Thursday May 11, 2006 19:24:24 Send IKE M4(KEYRESP) : xxx.xxx.xxx.xxx --> yyy.yyy.yyy.yyy
Thursday May 11, 2006 19:24:25 Receive IKE M5(IDINIT) : yyy.yyy.yyy.yyy --> xxx.xxx.xxx.xxx
Thursday May 11, 2006 19:24:25 Send IKE M6(IDRESP) : xxx.xxx.xxx.xxx --> yyy.yyy.yyy.yyy
Thursday May 11, 2006 19:24:25 IKE Phase1 (ISAKMP SA) established : xxx.xxx.xxx.xxx <-> yyy.yyy.yyy.yyy
Thursday May 11, 2006 19:24:25 Receive IKE Q1(QINIT) : [yyy.yyy.yyy.yyy]-->[xxx.xxx.xxx.xxx]
Thursday May 11, 2006 19:24:25 Requested routing is [192.168.12.0|yyy.yyy.yyy.yyy]<->[xxx.xxx.xxx.xxx|192.168.0.0]
Thursday May 11, 2006 19:24:25 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group1
Thursday May 11, 2006 19:24:29 Receive IKE Q1(QINIT) : [yyy.yyy.yyy.yyy]-->[xxx.xxx.xxx.xxx]
Thursday May 11, 2006 19:24:29 Requested routing is [192.168.12.0|yyy.yyy.yyy.yyy]<->[xxx.xxx.xxx.xxx|192.168.0.0]
Thursday May 11, 2006 19:24:29 Requested routing is [192.168.12.0|yyy.yyy.yyy.yyy]<->[xxx.xxx.xxx.xxx|192.168.0.0]
Thursday May 11, 2006 19:24:29 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group1
Thursday May 11, 2006 19:24:37 Receive IKE Q1(QINIT) : [yyy.yyy.yyy.yyy]-->[xxx.xxx.xxx.xxx]
Thursday May 11, 2006 19:24:37 Requested routing is [192.168.12.0|yyy.yyy.yyy.yyy]<->[xxx.xxx.xxx.xxx|192.168.0.0]
Thursday May 11, 2006 19:24:37 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group1
Thursday May 11, 2006 19:24:53 Receive IKE Q1(QINIT) : [yyy.yyy.yyy.yyy]-->[xxx.xxx.xxx.xxx]
Thursday May 11, 2006 19:24:53 Requested routing is [192.168.12.0|yyy.yyy.yyy.yyy]<->[xxx.xxx.xxx.xxx|192.168.0.0]
Thursday May 11, 2006 19:24:53 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group1
Zyxel log:
Index: Date/Time: Log:
------------------------------------------------------------
001 11 May 19:22:31 Send:[HASH][DEL]
002 11 May 19:22:32 Send Main Mode request to <xxx.xxx.xxx.xxx>
003 11 May 19:22:32 Send:[SA][VID]
004 11 May 19:22:32 Recv:[SA]
005 11 May 19:22:33 Send:[KE][NONCE]
006 11 May 19:22:33 Recv:[KE][NONCE]
007 11 May 19:22:33 Send:[ID][HASH][NOTFY:INIT_CONTACT]
008 11 May 19:22:33 Recv:[ID][HASH]
009 11 May 19:22:33 Phase 1 IKE SA process done
010 11 May 19:22:33 Start Phase 2: Quick Mode
011 11 May 19:22:34 Send:[HASH][SA][NONCE][KE][ID][ID]
012 11 May 19:22:37 !! IKE Negotiation is in process
013 11 May 19:23:02 !! IKE Packet Retransmit
014 11 May 19:23:31 Send:[HASH][DEL]
015 11 May 19:23:32 Send Main Mode request to <xxx.xxx.xxx.xxx>
016 11 May 19:23:32 Send:[SA][VID]
017 11 May 19:23:32 Recv:[SA]
018 11 May 19:23:33 Send:[KE][NONCE]
019 11 May 19:23:33 Recv:[KE][NONCE]
020 11 May 19:23:33 Send:[ID][HASH][NOTFY:INIT_CONTACT]
021 11 May 19:23:33 Recv:[ID][HASH]
022 11 May 19:23:33 Phase 1 IKE SA process done
023 11 May 19:23:33 Start Phase 2: Quick Mode
024 11 May 19:23:34 !! IKE Packet Retransmit
------------------------
как видно из логов первый этап контакта успешно случается, а вот фаза2 повторяется бесконечное количество раз, видимо концы с концами не сходятся в шифровании или еще где..
КАК ПОБЕДИТЬ!?