|
|
|
|
|
|
|
[Original]
[Print]
[Top]
|
我的VPN采用FREESWAN 有六个点.其他5个点都是成功的.只有一个不成功.
LEFT : ipsec whack --status | grep dygsgl7
000 "dygsgl7-dygscenter1": 91.0.0.0/8===221.237.21.211[@dygscenter.3322.org]---221.237.16.1...221.237.16.1---220.166.249.70[@dygsgl7.3322.org]===192.168.8.0/24; erouted; eroute owner: #6
000 "dygsgl7-dygscenter1": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "dygsgl7-dygscenter1": policy: RSASIG+ENCRYPT+TUNNEL+PFS+UP; prio: 8,24; interface: ppp0;
000 "dygsgl7-dygscenter1": newest ISAKMP SA: #2; newest IPsec SA: #6;
000 "dygsgl7-dygscenter2": 130.0.0.0/8===221.237.21.211[@dygscenter.3322.org]---221.237.16.1...221.237.16.1---220.166.249.70[@dygsgl7.3322.org]===192.168.8.0/24; erouted; eroute owner: #5
000 "dygsgl7-dygscenter2": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "dygsgl7-dygscenter2": policy: RSASIG+ENCRYPT+TUNNEL+PFS+UP; prio: 8,24; interface: ppp0;
000 "dygsgl7-dygscenter2": newest ISAKMP SA: #0; newest IPsec SA: #5;
000 #6: "dygsgl7-dygscenter1" STATE_QUICK_I2 (sent QI2, IPsec SA established); EVENT_SA_REPLACE in 26503s; newest IPSEC; eroute owner
000 #6: "dygsgl7-dygscenter1" esp.73b6646b@220.166.249.70 esp.9834f952@221.237.21.211 tun.0@220.166.249.70 tun.0@221.237.21.211
000 #2: "dygsgl7-dygscenter1" STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in 1433s; newest ISAKMP
000 #5: "dygsgl7-dygscenter2" STATE_QUICK_I2 (sent QI2, IPsec SA established); EVENT_SA_REPLACE in 26458s; newest IPSEC; eroute owner
000 #5: "dygsgl7-dygscenter2" esp.59550504@220.166.249.70 esp.ee193751@221.237.21.211 tun.0@220.166.249.70 tun.0@221.237.21.211
RIGHT: ipsec whack --status
000 interface lo/lo ::1
000 interface lo/lo 127.0.0.1
000 interface eth0/eth0 192.168.8.1
000 interface ppp0/ppp0 220.166.249.70
000 %myid = (none)
000 debug none
000
000 "dygsgl7-dygscenter1": 192.168.8.0/24===220.166.249.70[@dygsgl7.3322.org]---221.237.16.1...221.237.16.1---221.237.21.211[@dygscenter.3322.org]===91.0.0.0/8; erouted; eroute owner: #22
000 "dygsgl7-dygscenter1": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "dygsgl7-dygscenter1": policy: RSASIG+ENCRYPT+TUNNEL+PFS+UP; prio: 8,24; interface: ppp0;
000 "dygsgl7-dygscenter1": newest ISAKMP SA: #20; newest IPsec SA: #22;
000 "dygsgl7-dygscenter1": IKE algorithms wanted: 5_000-1-5, 5_000-2-5, 5_000-1-2, 5_000-2-2, flags=-strict
000 "dygsgl7-dygscenter1": IKE algorithms found: 5_192-1_128-5, 5_192-2_160-5, 5_192-1_128-2, 5_192-2_160-2,
000 "dygsgl7-dygscenter1": IKE algorithm newest: 3DES_CBC_192-MD5-MODP1536
000 "dygsgl7-dygscenter1": ESP algorithms wanted: 3_000-1, 3_000-2, flags=-strict
000 "dygsgl7-dygscenter1": ESP algorithms loaded: 3_192-1_128, 3_192-2_160,
000 "dygsgl7-dygscenter1": ESP algorithm newest: 3DES_0-HMAC_MD5; pfsgroup=<Phase1>
000 "dygsgl7-dygscenter2": 192.168.8.0/24===220.166.249.70[@dygsgl7.3322.org]---221.237.16.1...221.237.16.1---221.237.21.211[@dygscenter.3322.org]===130.0.0.0/8; erouted; eroute owner: #21
000 "dygsgl7-dygscenter2": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "dygsgl7-dygscenter2": policy: RSASIG+ENCRYPT+TUNNEL+PFS+UP; prio: 8,24; interface: ppp0;
000 "dygsgl7-dygscenter2": newest ISAKMP SA: #0; newest IPsec SA: #21;
000 "dygsgl7-dygscenter2": IKE algorithms wanted: 5_000-1-5, 5_000-2-5, 5_000-1-2, 5_000-2-2, flags=-strict
000 "dygsgl7-dygscenter2": IKE algorithms found: 5_192-1_128-5, 5_192-2_160-5, 5_192-1_128-2, 5_192-2_160-2,
000 "dygsgl7-dygscenter2": ESP algorithms wanted: 3_000-1, 3_000-2, flags=-strict
000 "dygsgl7-dygscenter2": ESP algorithms loaded: 3_192-1_128, 3_192-2_160,
000 "dygsgl7-dygscenter2": ESP algorithm newest: 3DES_0-HMAC_MD5; pfsgroup=<Phase1>
000
000 #60: "dygsgl7-dygscenter1" STATE_MAIN_R1 (sent MR1, expecting MI2); EVENT_RETRANSMIT in 15s
000 #59: "dygsgl7-dygscenter1" STATE_MAIN_R1 (sent MR1, expecting MI2); EVENT_RETRANSMIT in 15s
000 #22: "dygsgl7-dygscenter1" STATE_QUICK_R2 (IPsec SA established); EVENT_SA_REPLACE in 27110s; newest IPSEC; eroute owner
000 #22: "dygsgl7-dygscenter1" esp.9834f952@221.237.21.211 esp.73b6646b@220.166.249.70 tun.0@221.237.21.211 tun.0@220.166.249.70
000 #20: "dygsgl7-dygscenter1" STATE_MAIN_R3 (sent MR3, ISAKMP SA established); EVENT_SA_REPLACE in 1908s; newest ISAKMP
000 #21: "dygsgl7-dygscenter2" STATE_QUICK_R2 (IPsec SA established); EVENT_SA_REPLACE in 27109s; newest IPSEC; eroute owner
000 #21: "dygsgl7-dygscenter2" esp.ee193751@221.237.21.211 esp.59550504@220.166.249.70 tun.0@221.237.21.211 tun.0@220.166.249.70
000
请教大家问题何在?
此线路也是近期才出问题的.
.
|
|
|
[Original]
[Print]
[Top]
|
|
|