Посмотрел я утилитой ikesnoop. При подключении вроде все нормально.
Вот лог:
Код:
2008-07-16 14:16:23: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Informational
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x52e2de0c
Packet length : 64 bytes
# payloads : 2
Payloads:
HASH (Hash)
Payload data length : 16 bytes
D (Delete)
Payload data length : 12 bytes
Protocol ID : ESP
Delete SPIs : 0x90e9c95d
2008-07-16 14:16:23: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:16:28: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:16:33: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:16:43: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:16:53: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:17:13: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:17:14: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Informational
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x0d566112
Packet length : 64 bytes
# payloads : 2
Payloads:
HASH (Hash)
Payload data length : 16 bytes
D (Delete)
Payload data length : 12 bytes
Protocol ID : Reserved
Delete SPIs : 0x91e967b9
2008-07-16 14:17:14: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:17:19: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:17:24: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:17:34: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:17:44: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:04: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:05: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Informational
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x832d9500
Packet length : 64 bytes
# payloads : 2
Payloads:
HASH (Hash)
Payload data length : 16 bytes
D (Delete)
Payload data length : 12 bytes
Protocol ID : Reserved
Delete SPIs : 0x92e90317
2008-07-16 14:18:05: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:10: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:15: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:25: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:35: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:55: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:18:56: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Informational
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x971f3f0f
Packet length : 64 bytes
# payloads : 2
Payloads:
HASH (Hash)
Payload data length : 16 bytes
D (Delete)
Payload data length : 12 bytes
Protocol ID : Reserved
Delete SPIs : 0x93e99d76
2008-07-16 14:18:56: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:01: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:06: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:16: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:26: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:46: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:47: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Informational
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x46f3c206
Packet length : 64 bytes
# payloads : 2
Payloads:
HASH (Hash)
Payload data length : 16 bytes
D (Delete)
Payload data length : 12 bytes
Protocol ID : Reserved
Delete SPIs : 0x94e93ad8
2008-07-16 14:19:47: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Quick mode
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x06611de3
Packet length : 292 bytes
# payloads : 6
Payloads:
HASH (Hash)
Payload data length : 16 bytes
SA (Security Association)
Payload data length : 52 bytes
DOI : 1 (IPsec DOI)
Proposal 1/1
Protocol 1/1
Protocol ID : ESP
SPI Size : 4
SPI Value : 0x95e9d53b
Transform 1/1
Transform ID : 3DES
Authentication algorithm : HMAC-MD5
Encapsulation mode : Tunnel
Group description : MODP 1024
SA life type : Seconds
SA life duration : 360
NONCE (Nonce)
Payload data length : 20 bytes
KE (Key Exchange)
Payload data length : 128 bytes
ID (Identification)
Payload data length : 12 bytes
ID : ipv4_subnet(any:0,[0..7]=192.168.203.0/24)
ID (Identification)
Payload data length : 12 bytes
ID : ipv4_subnet(any:0,[0..7]=192.168.0.0/24)
2008-07-16 14:19:47: IkeSnoop: Sending IKE packet to 85.112.59.94:500
Exchange type : Quick mode
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x06611de3
Packet length : 288 bytes
# payloads : 6
Payloads:
HASH (Hash)
Payload data length : 16 bytes
SA (Security Association)
Payload data length : 52 bytes
DOI : 1 (IPsec DOI)
Proposal 1/1
Protocol 1/1
Protocol ID : ESP
SPI Size : 4
SPI Value : 0x24c2fb76
Transform 1/1
Transform ID : 3DES
Authentication algorithm : HMAC-MD5
Encapsulation mode : Tunnel
Group description : MODP 1024
SA life type : Seconds
SA life duration : 360
NONCE (Nonce)
Payload data length : 16 bytes
KE (Key Exchange)
Payload data length : 128 bytes
ID (Identification)
Payload data length : 12 bytes
ID : ipv4_subnet(any:0,[0..7]=192.168.203.0/24)
ID (Identification)
Payload data length : 12 bytes
ID : ipv4_subnet(any:0,[0..7]=192.168.0.0/24)
2008-07-16 14:19:47: IkeSnoop: Received IKE packet from 85.112.59.94:500
Exchange type : Quick mode
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xb79dd46f7412940 -> 0x1f10f26ba86ba93
Message ID : 0x06611de3
Packet length : 48 bytes
# payloads : 1
Payloads:
HASH (Hash)
Payload data length : 16 bytes
В настройках тонеля поставил лайф тайм 360 секунд. После их истечения реконнект происходит очень долго.
Как я понял это из за вот этих холостых пакетов:
Код:
2008-07-16 14:18:56: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:01: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:06: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:16: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:26: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:46: IkeSnoop: Received IKE packet from 85.112.59.94:500
2008-07-16 14:19:47: IkeSnoop: Received IKE packet from 85.112.59.94:500
В чём их причине не понятно.