Stanislav Kozlov писал(а):
Приведите логи обоих устройств при такой схеме.
У Вас точно совпадают DH группы? Туннель падает так же после реинитализации?
IKE DH Group: 2
PFS DH Group: 2
на обоих устройствах.
Логи:
DFL-900. Обрыв произошел в районе 8:30-8:40:
11 2007-03-14 07:34:03 INFO IPsec-SA expired: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 559945255(0x21601627)
12 2007-03-14 07:34:03 INFO IPsec-SA expired: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
13 2007-03-14 07:34:06 INFO Respond new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
14 2007-03-14 07:34:06 INFO purged IPsec-SA Proto_id=ESP 559945255.
15 2007-03-14 07:34:06 INFO Initiate new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
16 2007-03-14 07:34:06 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
17 2007-03-14 07:34:06 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 2976258251(0xb16618cb)
18 2007-03-14 07:34:07 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
19 2007-03-14 07:34:07 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 3605969547(0xd6eeba8b)
20 2007-03-14 07:34:07 INFO purged IPsec-SA Proto_id=ESP 2976258251.
21 2007-03-14 07:46:01 INFO Purging ISAKMP-SA 0637a34770f598cc:bfaddc711c364e82.
22 2007-03-14 07:46:01 INFO purged IPsec-SA 3605969547.
23 2007-03-14 07:46:01 INFO purged IPsec-SA 256.
24 2007-03-14 07:46:01 INFO purged ISAKMP-SA 0637a34770f598cc:bfaddc711c364e82.
25 2007-03-14 07:46:01 INFO IPsec-SA request for 172.19.12.131 queued due to no phase1 found.
26 2007-03-14 07:46:01 INFO Initiate new phase 1 negotiation: 172.19.1.3:500<=>172.19.12.131:500
27 2007-03-14 07:46:01 INFO Begin Identity Protection mode.
28 2007-03-14 07:46:01 INFO received Vendor ID: DPD
29 2007-03-14 07:46:02 INFO ISAKMP-SA deleted 172.19.1.3:500-172.19.12.131:500
30 2007-03-14 07:46:02 INFO ISAKMP-SA established 172.19.1.3:500-172.19.12.131:500
31 2007-03-14 07:46:03 INFO Initiate new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
32 2007-03-14 07:46:03 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
33 2007-03-14 07:46:03 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 2681783587(0x9fd8c523)
34 2007-03-14 08:34:04 INFO IPsec-SA expired: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 2681783587(0x9fd8c523)
35 2007-03-14 08:34:04 INFO Initiate new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
36 2007-03-14 08:34:04 INFO IPsec-SA expired: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
37 2007-03-14 08:34:04 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
38 2007-03-14 08:34:05 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 270354244(0x101d4744)
39 2007-03-14 08:34:05 INFO purged IPsec-SA Proto_id=ESP 2681783587.
40 2007-03-14 08:46:01 INFO Purging ISAKMP-SA 7242733d93883f1f:e91a6d6c01dcec6f.
41 2007-03-14 08:46:01 INFO purged IPsec-SA 270354244.
42 2007-03-14 08:46:01 INFO purged IPsec-SA 256.
43 2007-03-14 08:46:01 INFO purged ISAKMP-SA 7242733d93883f1f:e91a6d6c01dcec6f.
44 2007-03-14 08:46:02 INFO ISAKMP-SA deleted 172.19.1.3:500-172.19.12.131:500
45 2007-03-14 08:46:33 INFO IPsec-SA request for 172.19.12.131 queued due to no phase1 found.
46 2007-03-14 08:46:33 INFO Initiate new phase 1 negotiation: 172.19.1.3:500<=>172.19.12.131:500
47 2007-03-14 08:46:33 INFO Begin Identity Protection mode.
48 2007-03-14 08:46:33 INFO received Vendor ID: DPD
49 2007-03-14 08:46:33 INFO ISAKMP-SA established 172.19.1.3:500-172.19.12.131:500
50 2007-03-14 08:46:34 INFO Initiate new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
51 2007-03-14 08:46:34 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 256(0x100)
52 2007-03-14 08:46:34 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 3247733399(0xc1947a97)
53 2007-03-14 08:51:12 INFO purged IPsec-SA Proto_id=ESP 3247733399.
54 2007-03-14 08:51:12 INFO Purging ISAKMP-SA dcb7c3a34a3be8aa:e7bf18e47d4eb67a.
55 2007-03-14 08:51:12 INFO purged IPsec-SA 256.
56 2007-03-14 08:51:12 INFO purged ISAKMP-SA dcb7c3a34a3be8aa:e7bf18e47d4eb67a.
57 2007-03-14 08:51:13 INFO Respond new phase 1 negotiation: 172.19.1.3:500<=>172.19.12.131:500
58 2007-03-14 08:51:13 INFO Begin Identity Protection mode.
59 2007-03-14 08:51:13 INFO received Vendor ID: DPD
60 2007-03-14 08:51:13 INFO ISAKMP-SA deleted 172.19.1.3:500-172.19.12.131:500
61 2007-03-14 08:51:13 INFO Request for establishing IPsec-SA was queued due to no phase1 found.
62 2007-03-14 08:51:13 WARNING Ignore INITIAL-CONTACT notification, because it is only accepted after...
63 2007-03-14 08:51:14 INFO ISAKMP-SA established 172.19.1.3:500-172.19.12.131:500
64 2007-03-14 08:51:14 INFO Initiate new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
65 2007-03-14 08:51:14 INFO Respond new phase 2 negotiation: 172.19.1.3:0<=>172.19.12.131:0
66 2007-03-14 08:51:14 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 237664645(0xe2a7985)
67 2007-03-14 08:51:14 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 2679176806(0x9fb0fe66)
68 2007-03-14 08:51:15 INFO IPsec-SA established: ESP/Tunnel 172.19.12.131:0->172.19.1.3:0 50283767(0x2ff44f7)
69 2007-03-14 08:51:15 INFO IPsec-SA established: ESP/Tunnel 172.19.1.3:0->172.19.12.131:0 3786123649(0xe1aba981)
70 2007-03-14 08:52:24 INFO purged IPsec-SA Proto_id=ESP 3786123649.
dfl-200:
[2007-03-14 08:49:37] <5>EFW: CONN: rule=IPsecBeforeRules conn=close connipproto=UDP connrecvif=WAN connsrcip=172.19.1.3 connsrcport=500 conndestif=core conndestip=172.19.12.131 conndestport=500 origsent=812 termsent=0
[2007-03-14 08:47:27] <6>EFW: IPSEC: prio=1 SA ESP[c1947a97] alg [des-cbc/8]+hmac[hmac-md5-96] bundle [45,0] pri 0 opts src=ipv4_subnet(any:0,[0..7]=172.16.0.0/19) dst=ipv4_subnet(any:0,[0..7]=172.16.32.0/24)
[2007-03-14 08:47:27] <6>EFW: IPSEC: prio=1 SA ESP[00000100] alg [des-cbc/8]+hmac[hmac-md5-96] bundle [45,0] pri 0 opts src=ipv4_subnet(any:0,[0..7]=172.16.32.0/24) dst=ipv4_subnet(any:0,[0..7]=172.16.0.0/19)
[2007-03-14 08:47:27] <6>EFW: IPSEC: prio=1 Phase-2 [responder] done bundle 45 with 2 SA's by rule 3:`ipsec ipv4_subnet(any:0,[0..7]=172.16.32.0/24)<->ipv4_subnet(any:0,[0..7]=172.16.0.0/19)(gw:ipv4(any:0,[0..3]=172.19.1.3))'
[2007-03-14 08:47:25] <6>EFW: IPSEC: prio=1 Phase-1 [responder] between ipv4(udp:500,[0..3]=172.19.12.131) and ipv4(udp:500,[0..3]=172.19.1.3) done.
[2007-03-14 08:47:25] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=UDP connrecvif=WAN connsrcip=172.19.1.3 connsrcport=500 conndestif=core conndestip=172.19.12.131 conndestport=500
[2007-03-14 08:37:08] <5>EFW: CONN: rule=IPsecBeforeRules conn=close connipproto=UDP connrecvif=WAN connsrcip=172.19.1.3 connsrcport=500 conndestif=core conndestip=172.19.12.131 conndestport=500 origsent=400 termsent=0
[2007-03-14 08:35:01] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=ESP connrecvif=WAN connsrcip=172.19.1.3 connsrcid=0 conndestif=core conndestip=172.19.12.131 conndestid=0
[2007-03-14 08:34:57] <6>EFW: IPSEC: prio=1 SA ESP[101d4744] alg [des-cbc/8]+hmac[hmac-md5-96] bundle [44,0] pri 0 opts src=ipv4_subnet(any:0,[0..7]=172.16.0.0/19) dst=ipv4_subnet(any:0,[0..7]=172.16.32.0/24)
[2007-03-14 08:34:57] <6>EFW: IPSEC: prio=1 SA ESP[00000100] alg [des-cbc/8]+hmac[hmac-md5-96] bundle [44,0] pri 0 opts src=ipv4_subnet(any:0,[0..7]=172.16.32.0/24) dst=ipv4_subnet(any:0,[0..7]=172.16.0.0/19)
[2007-03-14 08:34:57] <6>EFW: IPSEC: prio=1 Phase-2 [responder] done bundle 44 with 2 SA's by rule 3:`ipsec ipv4_subnet(any:0,[0..7]=172.16.32.0/24)<->ipv4_subnet(any:0,[0..7]=172.16.0.0/19)(gw:ipv4(any:0,[0..3]=172.19.1.3))'
[2007-03-14 08:34:56] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=UDP connrecvif=WAN connsrcip=172.19.1.3 connsrcport=500 conndestif=core conndestip=172.19.12.131 conndestport=500
Так же замечено, что когда перестают ходить пакеты, в статусе vpn у dfl-200, в "Listing of active IKE SAs - all tunnels" появляется не одна строчка с установленным туннелем, а две-три-четыре, все одинаковые.