Второй раз за истекшие сутки наблюдаю такую картину: возникает ошибка при пересоздании IPSec VPN туннеля. Туннель пересоздается раз в час. На 804-ом IP адрес статический, поднят Dynamic VPN. На 808-ом Dynamic PPPoE. Обычно пересоздание туннеля происходит без каких-либо проблем, а тут уже повторяемость события начинает несколько напрягать.
В чем может быть проблема?
Логи:
DI-808HV
Цитата:
Wed Nov 28 08:32:58 2007 Send IKE (INFO) : delete [192.168.181.0|89.252.70.102]-->[84.242.242.194|192.168.40.0] phase 2
Wed Nov 28 08:32:58 2007 IKE phase2 (IPSec SA) remove : 192.168.181.0 <-> 192.168.40.0
Wed Nov 28 08:32:58 2007 inbound SPI = 0x1a130010, outbound SPI = 0x97810010
Wed Nov 28 08:32:58 2007 Send IKE (INFO) : delete 89.252.70.102 -> 84.242.242.194 phase 1
Wed Nov 28 08:32:58 2007 IKE phase1 (ISAKMP SA) remove : 89.252.70.102 <-> 84.242.242.194
Wed Nov 28 08:32:58 2007 Send IKE A1(AINIT) : 89.252.70.102 --> 84.242.242.194
Wed Nov 28 08:32:58 2007 Receive IKE A2(ARESP) : [84.242.242.194]-->[89.252.70.102]
Wed Nov 28 08:32:58 2007 Try to match with ENC:3DES AUTH:PSK HASH:MD5 Group:Group2
Wed Nov 28 08:32:59 2007 Send IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:32:59 2007 IKE Phase1 (ISAKMP SA) established : [89.252.70.102]<->[84.242.242.194]
Wed Nov 28 08:32:59 2007 Send IKE Q1(QINIT) : 192.168.181.0 --> 192.168.40.0
Wed Nov 28 08:33:03 2007 receiving a re-Tx MM msg, response the last msg
Wed Nov 28 08:33:03 2007 IKED re-TX : MM to 84.242.242.194
Wed Nov 28 08:33:04 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:33:08 2007 receiving a re-Tx MM msg, response the last msg
Wed Nov 28 08:33:08 2007 IKED re-TX : MM to 84.242.242.194
Wed Nov 28 08:33:09 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:33:18 2007 receiving a re-Tx MM msg, response the last msg
Wed Nov 28 08:33:18 2007 IKED re-TX : MM to 84.242.242.194
Wed Nov 28 08:33:19 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:33:28 2007 receiving a re-Tx MM msg, response the last msg
Wed Nov 28 08:33:28 2007 IKED re-TX : MM to 84.242.242.194
Wed Nov 28 08:33:29 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:33:48 2007 receiving a re-Tx MM msg, response the last msg
Wed Nov 28 08:33:48 2007 IKED re-TX : MM to 84.242.242.194
Wed Nov 28 08:33:49 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:33:49 2007 Receive IKE INFO : 84.242.242.194 --> 89.252.70.102
Wed Nov 28 08:33:50 2007 Send IKE (INFO) : delete [192.168.181.0|89.252.70.102]-->[84.242.242.194|192.168.40.0] phase 2
Wed Nov 28 08:33:50 2007 IKE phase2 (IPSec SA) remove : 192.168.181.0 <-> 192.168.40.0
Wed Nov 28 08:33:50 2007 inbound SPI = 0x1c130010, outbound SPI = 0x0
Wed Nov 28 08:33:50 2007 Send IKE Q1(QINIT) : 192.168.181.0 --> 192.168.40.0
Wed Nov 28 08:33:55 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:34:00 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:34:10 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:34:20 2007 IKED re-TX : QINIT to 84.242.242.194
Wed Nov 28 08:34:40 2007 IKED re-TX : QINIT to 84.242.242.194
..... выделенная цепочка событий повторяется до момента перезагрузки
Wed Nov 28 08:47:03 2007 PPPoE start to hang-up
...... перезагрузка роутера
DI-804HVЦитата:
Wed Nov 28 08:33:14 2007 Receive IKE INFO : 89.252.70.102 --> 84.242.242.194
Wed Nov 28 08:33:14 2007 Receive IKE (INFO) : delete [192.168.181.0|89.252.70.102]-->[84.242.242.194|192.168.40.0] phase 2
Wed Nov 28 08:33:14 2007 Send IKE (INFO) : delete [192.168.40.0|84.242.242.194]-->[89.252.70.102|192.168.181.0] phase 2
Wed Nov 28 08:33:14 2007 IKE phase2 (IPSec SA) remove : 192.168.40.0 <-> 192.168.181.0
Wed Nov 28 08:33:14 2007 inbound SPI = 0x97810010, outbound SPI = 0x1a130010
Wed Nov 28 08:33:14 2007 Receive IKE INFO : 89.252.70.102 --> 84.242.242.194
Wed Nov 28 08:33:14 2007 Receive IKE (INFO) : delete 89.252.70.102 -> 84.242.242.194 phase 1
Wed Nov 28 08:33:14 2007 Send IKE (INFO) : delete 84.242.242.194 -> 89.252.70.102 phase 1
Wed Nov 28 08:33:14 2007 IKE phase1 (ISAKMP SA) remove : 84.242.242.194 <-> 89.252.70.102
Wed Nov 28 08:33:14 2007 Receive IKE A1(AINIT) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:33:14 2007 Try to match with ENC:3DES AUTH:PSK HASH:MD5 Group:Group2
Wed Nov 28 08:33:15 2007 Send IKE A2(ARESP) : [84.242.242.194]-->[89.252.70.102]
Wed Nov 28 08:33:15 2007 Receive IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:33:15 2007 Error : 89.252.70.102 -> 84.242.242.194 QM must after P1 and MsgID!=0
Wed Nov 28 08:33:20 2007 IKED re-TX : ARESP to 89.252.70.102
Wed Nov 28 08:33:20 2007 Receive IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:33:20 2007 Error : 89.252.70.102 -> 84.242.242.194 QM must after P1 and MsgID!=0
Wed Nov 28 08:33:25 2007 IKED re-TX : ARESP to 89.252.70.102
Wed Nov 28 08:33:25 2007 Receive IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:33:25 2007 Error : 89.252.70.102 -> 84.242.242.194 QM must after P1 and MsgID!=0
Wed Nov 28 08:33:35 2007 IKED re-TX : ARESP to 89.252.70.102
Wed Nov 28 08:33:35 2007 Receive IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:33:35 2007 Error : 89.252.70.102 -> 84.242.242.194 QM must after P1 and MsgID!=0
Wed Nov 28 08:33:45 2007 IKED re-TX : ARESP to 89.252.70.102
Wed Nov 28 08:33:45 2007 Receive IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:33:45 2007 Error : 89.252.70.102 -> 84.242.242.194 QM must after P1 and MsgID!=0
Wed Nov 28 08:34:05 2007 IKED re-TX : ARESP to 89.252.70.102
Wed Nov 28 08:34:05 2007 Receive IKE A3(AHASH) : [89.252.70.102]-->[84.242.242.194]
Wed Nov 28 08:34:05 2007 Error : 89.252.70.102 -> 84.242.242.194 QM must after P1 and MsgID!=0
Wed Nov 28 08:34:06 2007 Send IKE (INFO) : delete 84.242.242.194 -> 89.252.70.102 phase 1
Wed Nov 28 08:34:06 2007 IKE phase1 (ISAKMP SA) remove : 84.242.242.194 <-> 89.252.70.102
.... далее в логе никаких событий не зафиксировано до момента
...... перезагрузки вызывающего роутера
Wed Nov 28 08:47:24 2007 Receive IKE A1(AINIT) : [89.252.70.102]-->[84.242.242.194]