97¹ú¼Ê

¹¤³§ÑÐѧ Ø­ 97¹ú¼ÊÍøÂçÊý×Ö»¯ÖÇÄܹ¤³§¡°ºÚ¿Æ¼¼¡±´ó½ÒÃØ
Ô¤Ô¼Ö±²¥
ÀÖÏíÓªÒµ°ü¹Ü·þÎñ Ø­ ÊØ»¤Ò½ÁÆÓªÒµÒ»Á¬ÎȹÌ
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

¡¾IPsecϵÁС¿µÚÒ»½×¶ÎЭÉ̲»ÀÖ³É

Ðû²¼Ê±¼ä£º2024-06-13
µã»÷Á¿£º1262

°¸Àý1 IPSECÒ»½×¶ÎЭÉ̲»ÀÖ³É

£¨Ò»£©Õ÷ÏóÐÎò

ͨ¹ýÏÂÁîshow crypto isakmp saÉó²éµÚÒ»½×¶ÎÊÇ·ñ½¨ÉèÀֳɵÄÒªÁìÈçÏ¡£
¶øÈôÊǵ±·ºÆð״̬ΪMM_SI1_WR1, MM_SA_SETUP¡¢MM_SI2_WR2, MM_VERIFY¡¢MM_SI3_WR3, MM_VERIFYʱ¼ä£¬ËµÃ÷ISAKMP SAÎÞ·¨Ð­ÉÌÀֳɡ£

£¨¶þ£©×éÍøÍØÆË

£¨Èý£©¿ÉÄÜÔµ¹ÊÔ­ÓÉ

1¡¢Á¬Í¨ÐÔÒì³£
2¡¢³ö½Ó¿ÚδŲÓÃvpn¼ÓÃÜͼ
3¡¢×ܲ¿ºÍ·ÖÖ§policyÕ½ÂÔÉèÖÃ·×ÆçÖÂ
4¡¢Ô¤¹²ÏíÃÜÔ¿ÉèÖùýʧ
5¡¢FQDNÉèÖùýʧ
6¡¢ÔËÓªÉ̹ýÂË
7¡¢×ܲ¿Îª¶þ¼¶Â·ÓɵÄÇéÐÎϳö¿Ú×°±¸Ã»ÓÐÉèÖÃÓ³Éä
8¡¢¶àÏß·ÇéÐÎÏÂѡ·¹ýʧ

£¨ËÄ£©´¦Öóͷ£°ì·¨

°ì·¨1¡¢±ÈÕÕ·ÖÖ§ºÍ×ܲ¿ÉèÖÃ
È·ÈÏÔ¤¹²ÏíÃØÔ¿¡¢µÚÒ»½×ЭÉ̲ÎÊý¡¢µÚ¶þ½×¶ÎЭÉ̲ÎÊý¡¢¸ÐÐËȤÁ÷µÈÊÇ·ñÒ»ÖÂ

a¡¢ÉèÖÃIPsec µÚÒ»½×¶Î
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾


°ì·¨2¡¢È·¶¨VPNÊÇ·ñ½¨ÉèÀÖ³É
a¡¢Web½çÃæÏÔʾÀ¶É«µÄÇéÐλòµã»÷ÏÔʾÒѽÓÈë
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
b¡¢ÏÂÁîÐпÉÒÔͨ¹ýshow crypto stateÉó²éVPNµÚÒ»½×¶ÎµÄÇéÐÎ
show crypto is sa Éó²éµÚÒ»½×¶Î½¨ÉèµÄÇéÐΣ¬IDLE״̬ÌåÏÖÊǽ¨ÉèÕý³£µÄ״̬
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
¡¾Ôö²¹¡¿
Ò»½×¶Î½¨Éè²»ÀÖ³É״̬ÏÔʾ
  1¡¢·ÖÖ§µÄ״̬»úΪMM_SI1_WR1, MM_SA_SETUP£¬¶ø×ܲ¿Ã»ÓÐ״̬»úÐÅÏ¢
  µÚÒ»¸ö±¨ÎÄ·¢³ö£¬×ܲ¿Ã»ÓÐÊÕµ½
  2¡¢·ÖÖ§µÄ״̬»úΪMM_SI1_WR1, MM_SA_SETUP£¬²¢ÇÒ´òÓ¡Send ISAKMP negotiate message failed, errno:148, No route to host syslog
  µÚÒ»¸ö±¨ÎÄ·¢³ö£¬¿ÉÊÇ·ÓÉѡ·ʧ°Ü£¨¼ì²éÏÂת·¢Â·ÓÉ£©
  3¡¢·ÖÖ§ºÍ×ܲ¿µÄ״̬»ú¶¼Îª£ºMM_SI1_WR1, MM_SA_SETUP
  ¿ÉÒÔͨ¹ýdebug cry isÉó²é£¬ÈôÌáÐÑno proposal chosen£¬Ð­É̲ÎÊý·×ÆçÖ£»ÈôÊÇÐèÒªÉèÖÃfqdn£¬ÐèҪʹÓÃÒ°Âùģʽ¶Ô½Ó
  4¡¢·ÖÖ§ºÍ×ܲ¿µÄ״̬»ú¶¼Îª£ºMM_SI2_WR2, MM_VERIFY
  ¿¨ÔÚÈýËı¨ÎĽ»»¥£¬¿ÉÒÔͨ¹ýdebug cry isÐÅÏ¢Éó²éÈÕÖ¾£¬Ò»Ñùƽ³£À´ËµÊDZ¨ÎÄÖØ´«£¬»òÕßʹÓÃÖ¤ÊéЭÉÌ£¬Ö¤Êé×°Öñ£´æÎÊÌâ
  5¡¢·ÖÖ§ºÍ×ܲ¿µÄ״̬»ú¶¼Îª£ºMM_SI3_WR3, MM_VERIFY
  Ô¤¹²ÏíÃÜÔ¿·×ÆçÖ£¬Éí·ÝÑé֤ʧ°Ü£¬natÇéÐηºÆð¶ª°ü£¬Í¨¹ýdebug cry isÉó²éЭÉ̵ÄÇéÐΣ¬ÒÔ¼°×°±¸ÍâÍø¿Ú×¥°ü¿ÉÒÔ½øÒ»²½Éó²éÏÂ

°ì·¨3¡¢¼ì²é×ܲ¿ºÍ·ÖÖ§ÊÇ·ñÁ¬Í¨ÐÔÒì³£

a¡¢×ܲ¿ºÍ·Ö²¿½¨ÉèVPNÊ×ÏÈÒª°ü¹Ü×Ü·Ö²¿µÄ¹«ÍøµØÖ·Á¬Í¨ÐÔÕý³££¬ÈçÏÂͼ£¬¼ÙÉèÏÂͼÁ½Ì¨×°±¸¶¼Îª³ö¿Ú£¬½Ó¿ÚÉϵÄÉèÖõÄÊǹ«ÍøµØÖ·×ܲ¿³ö¿ÚIP
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾


·ÖÖ§³ö¿ÚIP

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

³ö¿ÚµØÖ·Á¬Í¨ÐÔ²âÊÔ£¬ÏÂÁîÐÐÉÏ´ø¶ÔÓ¦½Ó¿ÚµØÖ·ÎªÔ´ping¶Ô¶Ë¹«ÍøµØÖ·£¬ÈçÏÂͼ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

b¡¢ÈôÊÇ×Ü·Ö²¿ÁªÍ¨ÐÔÇ·ºà£¬show crypto stateÊÇûÓдòÓ¡ÐÅÏ¢µÄ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
show crypto state
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

°ì·¨4¡¢¼ì²éVPNÆ¥Åä¶ÔÓ¦µÄ³ö½Ó¿ÚÏÂÊÇ·ñŲÓÃVPN¼ÓÃÜͼ

a¡¢ÏÂÁîÐÐÏÂŲÓüÓÃÜͼµÄÏÂÁî
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

×ܲ¿ÈôÊÇûÓÐŲÓüÓÃÜͼµÄÇéÐÎÏ£¬×ܲ¿show crypto stateûÓдòÓ¡ÐÅÏ¢£¬·Ö²¿show crypto state¿¨ÔÚµÚÒ»¡¢¶þ±¨ÎĽ»»¥×´Ì¬
×ܲ¿£º
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
·Ö²¿£º
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·Ö²¿Ã»ÓÐŲÓüÓÃÜͼµÄÇéÐÎÏ£¬×Ü·Ö²¿show crypto state¶¼Ã»ÓдòÓ¡ÐÅÏ¢
×ܲ¿£º
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
·Ö²¿£º
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

°ì·¨5¡¢¼ì²é×ܲ¿ºÍ·ÖÖ§policyÕ½ÂÔÉèÖÃ·×ÆçÖÂ
×Ü·Ö²¿Ö®¼äisaÕ½ÂÔ²ÎÊýÐèÒªÖðÒ»¶ÔÓ¦£¬ÈôÊÇ·×ÆçÑùÊǽ¨Éè²»ÆðÀ´µÄ£¬ÏêϸÈçÏÂͼ
×ܲ¿£º
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·Ö²¿£º
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾


¡¾Ôö²¹¡¿
µÚÒ»½×¶ÎЭÉ̲ÎÊý¶ÔÓ¦ÏÂÁîÐÐΪshow crypto isa policy
b¡¢ÈôÊÇÓÉÓÚµÚÒ»½×¶ÎЭÉ̲ÎÊý·×ÆçÖ£¬µ¼ÖÂshow crypto state¿¨ÔÚµÚÒ»¡¢¶þ±¨ÎĽ»»¥×´Ì¬
Ö÷ģʽЭÉÌʧ°Ü£¬show crypto state·¢Ã÷·ÖÖ§µÄ״̬»úΪMM_SI1_WR1, MM_SA_SETUP£¬¶ø×ܲ¿Ã»ÓÐ״̬»úÐÅÏ¢
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

°ì·¨6¡¢¼ì²éÔ¤¹²ÏíÃÜÔ¿ÉèÖÃÊÇ·ñ¹ýʧ

Ô¤¹²ÏíÃÜÔ¿ÉèÖùýʧµ¼ÖÂIPsecµÚÒ»½×¶ÎЭÉÌÎå¡¢Áù¸ö±¨ÎĽ»»¥²»Àֳɣ¬ÔÚ×Ü·Ö²¿ÉÏͨ¹ýshow crypto state¿´µ½µÄ״̬»®·ÖΪ
·Ö²¿£º
×ܲ¿£º

¡¾Ôö²¹¡¿

11.xµÄ×°±¸¿ÉÒÔÉó²éÄ¿½ñÉèÖõÄÔ¤¹²ÏíÃÜÔ¿ÊǼ¸¶à£¬Í¨¹ýÏÂÁîshow crypto isa key decrypt
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
¶ÔÓ¦µÄweb½çÃæÉèÖÃÒ³Ãæ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾



°ì·¨7¡¢¼ì²éÊÇ·ñQDNÉèÖùýʧ

·Ö²¿ÏÔʾÎåÁù¸ö±¨ÎĽ»»¥×´Ì¬
×ܲ¿ÏÔʾµÚÒ»½×¶Î½¨ÉèÍê³É
×ܲ¿ÉèÖãº
·ÖÖ§FQDN¶ÔÓ¦µÄÏÂÁîÐÐÉèÖÃΪ£ºself-identity fqdn EG3000GE
·Ö²¿ÉèÖãº
×ܲ¿FQDNÉèÖÃΪ£º
self-identity fqdn EG3000SE
crypto isakmp key 7 151b5f7246 hostname EG3000GE
crypto map gi0/7 1 ipsec-isakmp
set peer EG3000GE
·Ö²¿ÉϵĶԶËIDÐèÒªºÍ×ܲ¿µÄ±¾»úIDÒ»ÖÂ

°ì·¨8¡¢¼ì²éÊÇ·ñÔËÓªÉ̹ýÂË

¿ÉÒÔͨ¹ýshow ip f f | in 500Éó²é¶ÔÓ¦µÄÁ÷±íÐÅÏ¢ÊÇ·ñÓе½EG£¬ÈôÊÇûÓУ¬²¢ÇÒ×°±¸Éϲ¢Ã»ÓÐip session filterµÄÉèÖþÙÐйýÂË£¬¿ÉÒÔÏÓÒÉÔËÓªÉÌÎÊÌâ.
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾


°ì·¨9¡¢×ܲ¿Îª¶þ¼¶Â·ÓɵÄÇéÐÎϳö¿Ú×°±¸Ã»ÓÐÉèÖÃÓ³Éä

ÍøÂçÍØÆËΪ³ö¿Ú·ÓÉÏÂÁªEGÏÂÁªÄÚÍø£¬EG×÷Ϊ¶þ¼¶Â·ÓÉÉèÖÃIPsec×ܲ¿£¬ÐèÒªÔÚ×ܲ¿³ö¿ÚÉèÖÃÓ³ÉäUDP4500ºÍ500
¶ÔÓ¦web½çÃæÉèÖãº
¶ÔÓ¦ÏÂÁîÐÐÉèÖãº

°ì·¨10¡¢¶àÏß·ÇéÐÎÏÂѡ·¹ýʧ

¿ÉÒÔͨ¹ýÉó²éÁ÷±íµÄ³ö½Ó¿ÚÅжÏÊÇ·ñÊÇÍù·µÂ·¾¶·×ÆçÖÂ
½â¾ö¼Æ»®£º¶àÏß·µÄÇéÐÎÏÂÓпÉÄܵ¼ÖÂÍù·µÂ·¾¶·×ÆçÖ£¬½¨ÒéÉèÖÃÒ»Ìõ¾²Ì¬Â·ÓÉ£¬Ä¿µÄµØÖ·Ö¸Ïò¶Ô¶Ë¹«ÍøµØÖ·×ß¶ÔÓ¦µÄÏÂÒ»Ìø£¬°ü¹ÜÍù·µÂ·¾¶Ò»ÖÂ
ÏêϸÉèÖÃÈçÏ£º
Éó²éIPSEC±¨ÎÄѡ·ҪÁ죺
sh ip f m | in FLOW-AUDIT-K ---show³öÀ´ºó£¬Éó²éµÚÒ»ÁеÄÊýÖµ
sh ip f pri ÊýÖµ | in 500
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾


£¨Î壩ÐÅÏ¢ÍøÂç

ÈôÊÇÉÏÊöÒªÁì¾ÙÐÐÉèÖüì²éºóÒÀ¾ÉÎÞ·¨Õý³£½¨ÉèIPSec VPN£¬¿ÉÒÔÍøÂçÒÔÏÂÐÅÏ¢Ö®ºó·´Ïì 4008-111-000¹¤³Ìʦ£¬Ð­ÖúÄú½øÒ»²½ÅŲé¹ÊÕÏ¡£
show version
show int usage
sh tcp connect
sh ip udp
sh memory
sh cpu | ex 0.00
sh exec
show coredump file
show run
show log reverse
show ip interface brief
show ip route
show crypto state £¨ÍøÂç3´Î£¬Ã¿´Î¾àÀë5s£©
show ip fpm flow | in 500 £¨ÍøÂç3´Î£¬Ã¿´Î¾àÀë5s£©
show ip fpm pri 1 | in 500
show crypto log
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
IPSEC·ÖÖ§ÐÅÏ¢ÍøÂ磺
debug cry isa
debug cry ipsec
terminal monitor
ÍøÂç5·ÖÖÓ×óÓÒ
Undebug all --ÍøÂçÍêÐèÒª¹Ø±ÕdebugÐÅÏ¢
IPSEC×ܲ¿ÐÅÏ¢ÍøÂ磺£¨ÍƼö×ܲ¿Ö»ÓÐÒ»ÆðIPSEC¿ÉÒÔ¿ªÆôÍøÂ磬Áè¼ÝÒ»ÆðÒÔÉÏÉóÉ÷¿ªÆôdebug£¬ÒÔÃâÓ°ÏìÓªÒµ£©
debug cry isa
debug cry ipsec
terminal monitor
ÍøÂç5·ÖÖÓ×óÓÒ
Undebug all --ÍøÂçÍêÐèÒª¹Ø±ÕdebugÐÅÏ¢

£¨Áù£©×ܽáÓ뽨Òé

IKE SA½¨Éèʧ°Ü³£¼ûÔµ¹ÊÔ­ÓÉÊÇIKEЭÉ̱¨ÎIJ»¿É´ï£¬ºÍIKE SAÁ½Í·Õ½ÂÔ£¨¼ÓÃÜËã·¨¡¢DH×é¡¢Ô¤¹²ÏíÃØÔ¿¡¢Éí·ÝÈÏÖ¤ÒªÁ죩²»Æ¥Åä

ÈçÓö¸Ã¹ÊÕÏÎÞ·¨¶¨Î»½â¾öµÄ¿Éµã»÷£ºÊÛºóÉÁµçÍà ´¦Öóͷ£
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌâ £¿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù £¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£© £¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£© £¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Òé £¿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼