Chciałbym zapytać czy ta część konfiguracji jest odpowiednia:
Kod: Zaznacz cały
crypto ipsec transform-set TS esp-aes esp-sha-hmac
crypto ipsec transform-set TS1 ah-sha-hmac esp-aes 256
crypto ipsec transform-set TS2 esp-3des esp-sha-hmac
!
crypto map CMAP 10 ipsec-isakmp
set peer 195x
set transform-set TS
set pfs group2
match address VPN-TRAFFIC
Dla podanych parametrów do tunelu:
Ipsec peer: 19xx
Sieć po mojej stronie: 172.18.47.0/24
Sieć po drugiej stronie tunelu : 172.16.0.0/12
IKE group2 1440 min AES-256 SHA1
IPsec group 2 3600 sec AES-254 SHA1
Dodam jeszcze co debug mowi:
Kod: Zaznacz cały
yourname#ping 172.28.31.200 source vlan1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.28.31.200, timeout is 2 seconds:
Packet sent with a source address of 172.18.47.1
*Mar 14 17:55:02.490: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 90.x, remote= 195.x,
local_proxy= 172.18.47.0/255.255.255.0/0/0 (type=4),
remote_proxy= 172.16.0.0/255.240.0.0/0/0 (type=4),
protocol= ESP, transform= esp-aes esp-sha-hmac (Tunnel),
lifedur= 3600s and 4608000kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*Mar 14 17:55:02.494: ISAKMP: set new node 0 to QM_IDLE
*Mar 14 17:55:02.494: SA has outstanding requests (local 131.215.224.64 port 500, remote 131.215.224.36 port 500)
*Mar 14 17:55:02.494: ISAKMP:(2003): sitting IDLE. Starting QM immediately (QM_IDLE )
*Mar 14 17:55:02.494: ISAKMP:(2003):beginning Quick Mode exchange, M-ID of -612884500
*Mar 14 17:55:02.494: ISAKMP:(2003):QM Initiator gets spi
*Mar 14 17:55:02.494: ISAKMP:(2003): sending packet to 195.250.37.168 my_port 500 peer_port 500 (I) QM_IDLE
*Mar 14 17:55:02.494: ISAKMP:(2003):Sending an IKE IPv4 Packet.
*Mar 14 17:55:02.494: ISAKMP:(2003):Node -612884500, Input = IKE_MESG_INTERNAL, IKE_INIT_QM
*Mar 14 17:55:02.494: ISAKMP:(2003):Old State = IKE_QM_READY New State = IKE_QM_I_QM1
*Mar 14 17:55:02.522: ISAKMP (0:2003): received packet from 195.250.37.168 dport 500 sport 500 Global (I) QM_IDLE
*Mar 14 17:55:02.522: ISAKMP: set new node 1091014559 to QM_IDLE
*Mar 14 17:55:02.522: ISAKMP:(2003): processing HASH payload. message ID = 1091014559
*Mar 14 17:55:02.522: ISAKMP:(2003): processing NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
spi 2999247484, message ID = 1091014559, sa = 83D7DEDC
*Mar 14 17:55:02.522: ISAKMP:(2003): deleting spi 2999247484 message ID = -612884500
*Mar 14 17:55:02.522: ISAKMP:(2003):deleting node -612884500 error TRUE reason "Delete Larval"
*Mar 14 17:55:02.526: ISAKMP:(2003):deleting node 1091014559 error FALSE reason "Informational (in) state 1"
*Mar 14 17:55:02.526: ISAKMP:(2003):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Mar 14 17:55:02.526: ISAKMP:(2003):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
.....
Success rate is 0 percent (0/5)
yourname#
*Mar 14 17:55:12.615: ISAKMP:(2003):purging node 1073312661
*Mar 14 17:55:22.608: ISAKMP (0:2003): received packet from 195.x dport 500 sport 500 Global (I) QM_IDLE
*Mar 14 17:55:22.608: ISAKMP: set new node 52740970 to QM_IDLE
*Mar 14 17:55:22.608: ISAKMP:(2003): processing HASH payload. message ID = 52740970
*Mar 14 17:55:22.608: ISAKMP:(2003): processing SA payload. message ID = 52740970
*Mar 14 17:55:22.608: ISAKMP:(2003):Checking IPSec proposal 1
*Mar 14 17:55:22.608: ISAKMP: transform 1, ESP_AES
*Mar 14 17:55:22.608: ISAKMP: attributes in transform:
*Mar 14 17:55:22.608: ISAKMP: group is 2
*Mar 14 17:55:22.608: ISAKMP: SA life type in seconds
*Mar 14 17:55:22.608: ISAKMP: SA life duration (VPI) of 0x0 0x0 0xE 0x10
*Mar 14 17:55:22.608: ISAKMP: authenticator is HMAC-SHA
*Mar 14 17:55:22.612: ISAKMP: encaps is 1 (Tunnel)
*Mar 14 17:55:22.612: ISAKMP: key length is 256
*Mar 14 17:55:22.612: ISAKMP:(2003):atts are acceptable.
*Mar 14 17:55:22.612: IPSEC(validate_proposal_request): proposal part #1
*Mar 14 17:55:22.612: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 90.x, remote= 195.x,
local_proxy= 172.18.47.0/255.255.255.0/0/0 (type=4),
remote_proxy= 10.0.24.0/255.255.252.0/0/0 (type=4),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Mar 14 17:55:22.612: Crypto mapdb : proxy_match
src addr : 172.18.47.0
dst addr : 10.0.24.0
protocol : 0
src port : 0
dst port : 0
*Mar 14 17:55:22.612: Crypto mapdb : proxy_match
src addr : 172.18.47.0
dst addr : 10.0.24.0
protocol : 0
src port : 0
dst port : 0
*Mar 14 17:55:22.612: map_db_find_best did not find matching map
*Mar 14 17:55:22.612: IPSEC(ipsec_process_proposal): proxy identities not supported
*Mar 14 17:55:22.612: ISAKMP:(2003): IPSec policy invalidated proposal with error 32
*Mar 14 17:55:22.612: ISAKMP:(2003): phase 2 SA policy not acceptable! (local 90.156.23.17 remote 195.250.37.168)
*Mar 14 17:55:22.612: ISAKMP: set new node 875995458 to QM_IDLE
*Mar 14 17:55:22.612: ISAKMP:(2003):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
spi 2213199176, message ID = 875995458
*Mar 14 17:55:22.612: ISAKMP:(2003): sending packet to 195.250.37.168 my_port 500 peer_port 500 (I) QM_IDLE
*Mar 14 17:55:22.612: ISAKMP:(2003):Sending an IKE IPv4 Packet.
*Mar 14 17:55:22.612: ISAKMP:(2003):purging node 875995458
*Mar 14 17:55:22.616: ISAKMP:(2003):deleting node 52740970 error TRUE reason "QM rejected"
*Mar 14 17:55:22.616: ISAKMP:(2003):Node 52740970, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
*Mar 14 17:55:22.616: ISAKMP:(2003):Old State = IKE_QM_READY New State = IKE_QM_READY
*Mar 14 17:55:32.490: IPSEC(key_engine): request timer fired: count = 1,
(identity) local= 90.156.23.17, remote= 195.x,
local_proxy= 172.18.47.0/255.255.255.0/0/0 (type=4),
remote_proxy= 172.16.0.0/255.240.0.0/0/0 (type=4)
*Mar 14 17:55:32.490: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 90.156.23.17, remote= 195.x,
local_proxy= 172.18.47.0/255.255.255.0/0/0 (type=4),
remote_proxy= 172.16.0.0/255.240.0.0/0/0 (type=4),
protocol= ESP, transform= esp-aes esp-sha-hmac (Tunnel),
lifedur= 3600s and 4608000kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*Mar 14 17:55:32.490: ISAKMP: set new node 0 to QM_IDLE
*Mar 14 17:55:32.490: SA has outstanding requests (local 131.215.224.64 port 500, remote 131.215.224.36 port 500)
*Mar 14 17:55:32.490: ISAKMP:(2003): sitting IDLE. Starting QM immediately (QM_IDLE )
*Mar 14 17:55:32.490: ISAKMP:(2003):beginning Quick Mode exchange, M-ID of 1265617136
*Mar 14 17:55:32.490: ISAKMP:(2003):QM Initiator gets spi
*Mar 14 17:55:32.490: ISAKMP:(2003): sending packet to 195.250.37.168 my_port 500 peer_port 500 (I) QM_IDLE
*Mar 14 17:55:32.490: ISAKMP:(2003):Sending an IKE IPv4 Packet.
*Mar 14 17:55:32.494: ISAKMP:(2003):Node 1265617136, Input = IKE_MESG_INTERNAL, IKE_INIT_QM
*Mar 14 17:55:32.494: ISAKMP:(2003):Old State = IKE_QM_READY New State = IKE_QM_I_QM1
*Mar 14 17:55:32.518: ISAKMP (0:2003): received packet from 195.x dport 500 sport 500 Global (I) QM_IDLE
*Mar 14 17:55:32.518: ISAKMP: set new node -1153272622 to QM_IDLE
*Mar 14 17:55:32.518: ISAKMP:(2003): processing HASH payload. message ID = -1153272622
*Mar 14 17:55:32.518: ISAKMP:(2003): processing NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
spi 4077110252, message ID = -1153272622, sa = 83D7DEDC
*Mar 14 17:55:32.518: ISAKMP:(2003): deleting spi 4077110252 message ID = 1265617136
*Mar 14 17:55:32.518: ISAKMP:(2003):deleting node 1265617136 error TRUE reason "Delete Larval"
*Mar 14 17:55:32.518: ISAKMP:(2003):deleting node -1153272622 error FALSE reason "Informational (in) state 1"
*Mar 14 17:55:32.518: ISAKMP:(2003):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Mar 14 17:55:32.518: ISAKMP:(2003):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Mar 14 17:55:52.524: ISAKMP:(2003):purging node -612884500
*Mar 14 17:55:52.528: ISAKMP:(2003):purging node 1091014559
*Mar 14 17:56:02.493: IPSEC(key_engine): request timer fired: count = 2,
(identity) local= 90.x, remote= 195.x8,
local_proxy= 172.18.47.0/255.255.255.0/0/0 (type=4),
remote_proxy= 172.16.0.0/255.240.0.0/0/0 (type=4)
*Mar 14 17:56:12.619: ISAKMP:(2003):purging node 52740970
*Mar 14 17:56:22.520: ISAKMP:(2003):purging node 1265617136
*Mar 14 17:56:22.520: ISAKMP:(2003):purging node -1153272622
*Mar 14 17:56:22.604: ISAKMP (0:2003): received packet from 195.250.37.168 dport 500 sport 500 Global (I) QM_IDLE
*Mar 14 17:56:22.604: ISAKMP: set new node -1254283385 to QM_IDLE
*Mar 14 17:56:22.608: ISAKMP:(2003): processing HASH payload. message ID = -1254283385
*Mar 14 17:56:22.608: ISAKMP:(2003): processing SA payload. message ID = -1254283385
*Mar 14 17:56:22.608: ISAKMP:(2003):Checking IPSec proposal 1
*Mar 14 17:56:22.608: ISAKMP: transform 1, ESP_AES
*Mar 14 17:56:22.608: ISAKMP: attributes in transform:
*Mar 14 17:56:22.608: ISAKMP: group is 2
*Mar 14 17:56:22.608: ISAKMP: SA life type in seconds
*Mar 14 17:56:22.608: ISAKMP: SA life duration (VPI) of 0x0 0x0 0xE 0x10
*Mar 14 17:56:22.608: ISAKMP: authenticator is HMAC-SHA
*Mar 14 17:56:22.608: ISAKMP: encaps is 1 (Tunnel)
*Mar 14 17:56:22.608: ISAKMP: key length is 256
*Mar 14 17:56:22.608: ISAKMP:(2003):atts are acceptable.
*Mar 14 17:56:22.608: IPSEC(validate_proposal_request): proposal part #1
*Mar 14 17:56:22.608: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 90.x7, remote= 195x,
local_proxy= 172.18.47.0/255.255.255.0/0/0 (type=4),
remote_proxy= 10.0.24.0/255.255.252.0/0/0 (type=4),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Mar 14 17:56:22.608: Crypto mapdb : proxy_match
src addr : 172.18.47.0
dst addr : 10.0.24.0
protocol : 0
src port : 0
dst port : 0
*Mar 14 17:56:22.608: Crypto mapdb : proxy_match
src addr : 172.18.47.0
dst addr : 10.0.24.0
protocol : 0
src port : 0
dst port : 0
*Mar 14 17:56:22.608: map_db_find_best did not find matching map
*Mar 14 17:56:22.608: IPSEC(ipsec_process_proposal): proxy identities not supported
*Mar 14 17:56:22.608: ISAKMP:(2003): IPSec policy invalidated proposal with error 32
*Mar 14 17:56:22.608: ISAKMP:(2003): phase 2 SA policy not acceptable! (local 90.156.23.17 remote 195.250.37.168)
*Mar 14 17:56:22.608: ISAKMP: set new node -1155097540 to QM_IDLE
*Mar 14 17:56:22.608: ISAKMP:(2003):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
spi 2213199176, message ID = -1155097540
*Mar 14 17:56:22.612: ISAKMP:(2003): sending packet to 195.x my_port 500 peer_port 500 (I) QM_IDLE
*Mar 14 17:56:22.612: ISAKMP:(2003):Sending an IKE IPv4 Packet.
*Mar 14 17:56:22.612: ISAKMP:(2003):purging node -1155097540
*Mar 14 17:56:22.612: ISAKMP:(2003):deleting node -1254283385 error TRUE reason "QM rejected"
*Mar 14 17:56:22.612: ISAKMP:(2003):Node -1254283385, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
*Mar 14 17:56:22.612: ISAKMP:(2003):Old State = IKE_QM_READY New State = IKE_QM_READY
Zawsze może być bardziej przejebane, a więc cieszmy się z tego jak jest teraz.