近期公司总部与上海分公司需要建立ipsecVPN。
基本信息如下:
总部设备为深信服AF,软件版本为:8.0.17;公网IP为:116.239.13.122;子网ip为10.2.0.0/16
上海分设备为纽盾(Newdon)防火墙, 软件版本:NDF7000-FW60-2.1.8t0, build 34800-20220522.211441;公网IP为:210.22.107.106;内网IP为10.3.0.0/23。
1、总部深信服配置如下:
第一阶段:
第二阶段:入站
第二阶段出站:
上海分纽盾防火墙配置如下:
IPSec隧道:
IPsec规则:
。
现在遇到的问题:
1、总部深信服防火墙日志报错信息如下:
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:8744c910>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:8744c910>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:8744c910>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:8744c910>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:98aae1c0 ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:c3c961ce ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
| | | | [ipsec_vpn][exchange:1030] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]not found child sa with id 8744c910 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:没有可选的提议, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:没有可选的提议, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:e19d8130>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:e19d8130>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:e19d8130>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:e19d8130>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:ac3979c3 ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:7aacba68 ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
| | | | [ipsec_vpn][exchange:1030] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]not found child sa with id e19d8130 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:无效的HASH信息, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:无效的HASH信息, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:1b0362a5>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:1b0362a5>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:1b0362a5>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:1b0362a5>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:a6acd4c7 ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:c196a5d0 ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
| | | | [ipsec_vpn][exchange:1030] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]not found child sa with id 1b0362a5 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:无效的HASH信息, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:无效的HASH信息, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:70d3fe4b>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:70d3fe4b>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:70d3fe4b>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:70d3fe4b>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:45e6eacc ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:96edd866 ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
| | | | [ipsec_vpn][exchange:1030] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]not found child sa with id 70d3fe4b |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:没有可选的提议, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:没有可选的提议, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][exchange:1357] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]开始协商第二阶段[总部-上海分ipsec-总部-上海分ipsec] |
| | | | [ipsec_vpn][ike_sa:878] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:69b483bc>]remote id : IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ike_sa:876] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:69b483bc>]local id : IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0 |
| | | | [webagent][waclient_main:57] 设备上报信息汇总: |
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:314e1cd9>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:314e1cd9>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:314e1cd9>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:314e1cd9>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:d8cce8c9 ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:fc22bb7c ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
| | | | [ipsec_vpn][exchange:1030] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]not found child sa with id 314e1cd9 |
| | | | [ipsec_vpn][ike_sa:1597] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:4d79e038>]跟210.22.107.106<500>建立连接超时,状态 ut-1_in-0 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:无效的HASH信息, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][ike_sa:1783] Delete ike sa 923e5cb24aec29cd 4d79e038 |
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:f57429e0>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:f57429e0>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:f57429e0>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:f57429e0>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:723536c5 ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:9586acac ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
| | | | [ipsec_vpn][exchange:1030] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]not found child sa with id f57429e0 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:没有可选的提议, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][payload_notify:204] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]收到对端的通知:无效的HASH信息, 详情:请检查第二阶段的安全提议是否配置一致, 包括加密算法/认证算法/DH群/生存期 |
| | | | [ipsec_vpn][exchange:1073] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:65a5613b>]收到无效数据包,解析载荷失败 |
| | | | [ipsec_vpn][payload_manager:148] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:65a5613b>]解析载荷sa payload v1失败,返回值-1 |
| | | | [ipsec_vpn][proposal:863] 创建提议失败 |
| | | | [ipsec_vpn][proposal:697] 我方支持变换DH群[3],但对端不支持 |
| | | | [ipsec_vpn][ike_sa:938] [@总部-上海分<总部-上海分ipsec-总部-上海分ipsec>:210.22.107.106<500><923e5cb24aec29cd:65a5613b>]接受对端第二阶段的协商, 第二阶段名称总部-上海分ipsec-总部-上海分ipsec |
| | | | [ipsec_vpn][exchange:993] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:65a5613b>]收到对端第二阶段的协商, 本端身份IPV4_ADDR_SUBNET:10.2.0.0/255.255.0.0, 对端身份IPV4_ADDR_SUBNET:10.3.0.0/255.255.254.0 |
| | | | [ipsec_vpn][ipsec:62] [210.22.107.106<500>]无法处理快速交换类型数据包 |
| | | | [ipsec_vpn][exchange:1460] [@总部-上海分:210.22.107.106<500><923e5cb24aec29cd:00000000>]send notify 没有可选的提议 |
| | | | [ipsec_vpn][proposal:613] 第二阶段使用对端的生存期95040 |
| | | | [ipsec_vpn][proposal:840] remote #0 3:9a1a20c2 ;tid:12[0:1 1 0][1:2 95040 0][2:3 2 0][3:4 1 0][4:5 5 0][5:6 256 0] |
| | | | [ipsec_vpn][proposal:839] local #0 3:623f8a5a ;tid:12[0:1 1 0][1:2 86400 0][2:4 1 0][3:5 5 0][4:6 256 0] |
上海分纽盾防火墙报错内容如下:
1 | 07[ENC] parsed INFORMATIONAL_V1 request 2982415063 [ HASH N(DPD_ACK) ] | 2022-12-07 12:58:13 | 2 | 07[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (108 bytes) | 2022-12-07 12:58:13 | 3 | 09[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (108 bytes) | 2022-12-07 12:58:13 | 4 | 09[ENC] generating INFORMATIONAL_V1 request 587109439 [ HASH N(DPD) ] | 2022-12-07 12:58:13 | 5 | 09[IKE] sending DPD request | 2022-12-07 12:58:13 | 6 | 04[IKE] QUICK_MODE request with message ID 2622688679 processing failed | 2022-12-07 12:58:13 | 7 | 04[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (92 bytes) | 2022-12-07 12:58:13 | 8 | 04[ENC] generating INFORMATIONAL_V1 request 3382219034 [ HASH N(INVAL_HASH) ] | 2022-12-07 12:58:13 | 9 | 04[IKE] integrity check failed | 2022-12-07 12:58:13 | 10 | 04[ENC] received HASH payload does not match | 2022-12-07 12:58:13 | 11 | 04[ENC] parsed QUICK_MODE request 2622688679 [ HASH SA No ID ID ] | 2022-12-07 12:58:13 | 12 | 04[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (172 bytes) | 2022-12-07 12:58:13 | 13 | 16[IKE] QUICK_MODE request with message ID 439034139 processing failed | 2022-12-07 12:58:13 | 14 | 16[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (92 bytes) | 2022-12-07 12:58:13 | 15 | 16[ENC] generating INFORMATIONAL_V1 request 1769970578 [ HASH N(INVAL_HASH) ] | 2022-12-07 12:58:13 | 16 | 16[IKE] integrity check failed | 2022-12-07 12:58:13 | 17 | 16[ENC] received HASH payload does not match | 2022-12-07 12:58:13 | 18 | 16[ENC] parsed QUICK_MODE request 439034139 [ HASH SA No ID ID ] | 2022-12-07 12:58:13 | 19 | 16[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (172 bytes) | 2022-12-07 12:58:13 | 20 | 12[IKE] received NO_PROPOSAL_CHOSEN error notify | 2022-12-07 12:58:08 | 21 | 12[ENC] parsed INFORMATIONAL_V1 request 620756992 [ HASH N(NO_PROP) ] | 2022-12-07 12:58:08 | 22 | 12[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (76 bytes) | 2022-12-07 12:58:08 | 23 | 10[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (332 bytes) | 2022-12-07 12:58:08 | 24 | 10[ENC] generating QUICK_MODE request 1035138506 [ HASH SA No KE ID ID ] | 2022-12-07 12:58:08 | 25 | 13[CFG] received stroke: initiate '1670219317951_0_165_1_0_0' | 2022-12-07 12:58:08 | 26 | 10[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (92 bytes) | 2022-12-07 12:58:03 | 27 | 10[ENC] generating INFORMATIONAL_V1 request 2230177409 [ HASH N(NO_PROP) ] | 2022-12-07 12:58:03 | 28 | 10[IKE] no matching proposal found, sending NO_PROPOSAL_CHOSEN | 2022-12-07 12:58:03 | 29 | 10[IKE] received 86400s lifetime, configured 95040s | 2022-12-07 12:58:03 | 30 | 10[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_1024/NO_EXT_SEQ | 2022-12-07 12:58:03 | 31 | 10[CFG] received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ | 2022-12-07 12:58:03 | 32 | 10[ENC] parsed QUICK_MODE request 439034139 [ HASH SA No ID ID ] | 2022-12-07 12:58:03 | 33 | 10[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (172 bytes) | 2022-12-07 12:58:03 | 34 | 16[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (92 bytes) | 2022-12-07 12:58:03 | 35 | 16[ENC] generating INFORMATIONAL_V1 request 1665144817 [ HASH N(NO_PROP) ] | 2022-12-07 12:58:03 | 36 | 16[IKE] no matching proposal found, sending NO_PROPOSAL_CHOSEN | 2022-12-07 12:58:03 | 37 | 16[IKE] received 86400s lifetime, configured 95040s | 2022-12-07 12:58:03 | 38 | 16[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_1024/NO_EXT_SEQ | 2022-12-07 12:58:03 | 39 | 16[CFG] received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ | 2022-12-07 12:58:03 | 40 | 16[ENC] parsed QUICK_MODE request 2622688679 [ HASH SA No ID ID ] | 2022-12-07 12:58:03 | 41 | 16[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (172 bytes) | 2022-12-07 12:58:03 | 42 | 08[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (108 bytes) | 2022-12-07 12:58:01 | 43 | 08[ENC] generating INFORMATIONAL_V1 request 3217484096 [ HASH N(DPD_ACK) ] | 2022-12-07 12:58:01 | 44 | 08[ENC] parsed INFORMATIONAL_V1 request 1094179874 [ HASH N(DPD) ] | 2022-12-07 12:58:01 | 45 | 08[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (108 bytes) | 2022-12-07 12:58:01 | 46 | 11[IKE] received NO_PROPOSAL_CHOSEN error notify | 2022-12-07 12:57:58 | 47 | 11[ENC] parsed INFORMATIONAL_V1 request 603979776 [ HASH N(NO_PROP) ] | 2022-12-07 12:57:58 | 48 | 11[NET] received packet: from 116.239.13.122[500] to 210.22.107.106[500] (76 bytes) | 2022-12-07 12:57:58 | 49 | 09[NET] sending packet: from 210.22.107.106[500] to 116.239.13.122[500] (332 bytes) | 2022-12-07 12:57:58 | 50 | 09[ENC] generating QUICK_MODE request 155845490 [ HASH SA No KE ID ID ] | 2022-12-07 12:57:58 |
请教各位大神:我的配置是不是有什么问题?应该如何修改?
|