补充下DEBUG信息:. t2 U; j& k8 P, \' O1 e3 ?6 n
Aug 27 11:42:37.475: inbound SA from 58.*.*.*to 118.*.*.* (f/i) 0/ 0
- _1 f" v7 V# J# c+ w C (proxy 10.23.8.0 to 10.23.54.32)# M1 j$ k! [9 l% Q
Aug 27 11:42:37.475: has spi 0xCC7B952A and conn_id 03 h. s3 \4 E$ u7 H* e- K; P* ~
Aug 27 11:42:37.475: lifetime of 86400 seconds
P* g) K4 x8 s# O6 y7 {7 t, iAug 27 11:42:37.475: lifetime of 4608000 kilobytes `" o% r" X q" C
Aug 27 11:42:37.475: outbound SA from 118.*.*.* to 58.*.*.*(f/i) 0/0
' A& D# w( ]" s" W/ e8 q, S: h (proxy 10.23.54.32 to 10.23.8.0)' H# I; B- J9 V+ N4 x* |0 N
Aug 27 11:42:37.475: has spi 0x4BB72C8F and conn_id 0/ S$ N- ~; g) h& N! o: s( e
Aug 27 11:42:37.475: lifetime of 86400 seconds
; B" ~; p& w m9 `3 P7 c2 gAug 27 11:42:37.475: lifetime of 4608000 kilobytes0 A, L% d4 a3 U6 ~7 B0 h
Aug 27 11:42:37.475: ISAKMP2001): sending packet to 58.*.*.*my_port 500 peer_port 500 (I) QM_IDLE
( `! ^/ J* F& P3 L# wAug 27 11:42:37.475: ISAKMP2001):Sending an IKE IPv4 Packet.
- g5 C! }/ ~4 E0 P3 jAug 27 11:42:37.475: ISAKMP2001):deleting node 1853074095 error FALSE reason "No Error"
$ m0 m) A) F: iAug 27 11:42:37.475: ISAKMP2001):Node 1853074095, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
" m6 z* r' a. e+ JAug 27 11:42:37.475: ISAKMP2001):Old State = IKE_QM_I_QM1 New State = IKE_QM_PHASE2_COMPLETE% p: J% S9 s) u* h1 _
Aug 27 11:42:37.475: IPSEC(key_engine): got a queue event with 1 KMI message(s)/ T2 |( h0 L. n5 Y$ @7 B
Aug 27 11:42:37.475: Crypto mapdb : proxy_match0 ^) W* v4 I) m/ o5 c0 b) G( @
src addr : 10.23.54.32( U; S! ?) l2 k- ^
dst addr : 10.23.8.0
* L) n9 d1 a. a protocol : 0
/ u( s, q1 t- Z# s7 ^9 I/ ^1 m V src port : 0* l$ D. Y" m- U
dst port : 0) Z) o. x, f' W; y* u
Aug 27 11:42:37.475: IPSEC(crypto_ipsec_sa_find_ident_head): reconnecting with the same proxies and peer 58.20.43.227
$ D# G3 q7 C% \- Y7 d SAug 27 11:42:37.475: IPSEC(rte_mgr): VPN Route Event create SA based on crypto ACL in real time for 58.20.43.227& M2 Y+ u( X* f: H4 @
Aug 27 11:42:37.475: IPSEC(rte_mgr): Route add Peer 58.*.*.*, Destination 10.23.8.0, Nexthop 0.0.0.0, RT type 19 `) K' f+ @6 y# P! Y* Y
Aug 27 11:42:37.475: IPSEC(rte_mgr): VPN Route Refcount 1 Dialer10
7 e: A& T4 k% d9 ^1 t. WAug 27 11:42:37.479: IPSEC(rte_mgr): VPN Route Added 10.23.8.0 255.255.248.0 via 58.*.*.*in IP DEFAULT TABLE with tag 0 distance 1
- ^% ^ D8 |" fAug 27 11:42:37.479: IPSEC(policy_db_add_ident): src 10.23.54.32, dest 10.23.8.0, dest_port 07 B: z x; C5 |: R% R, Z! ?
. n9 l' d0 n3 j" }* e4 }Aug 27 11:42:37.479: IPSEC(create_sa): sa created,
P1 ]8 B' L% F+ n4 `+ e- ^! u (sa) sa_dest= 118.*.*.*, sa_proto= 50, ( a: R* W& t, \3 g; a
sa_spi= 0xCC7B952A(3430651178),
. W+ [. l* Y+ h: n5 e. ] sa_trans= esp-des esp-md5-hmac , sa_conn_id= 1% K' i0 ~/ |: i" a
sa_lifetime(k/sec)= (4434691/86400)
0 X+ D. G! i$ N8 mAug 27 11:42:37.479: IPSEC(create_sa): sa created,' U' @' B1 W. ~$ f4 g0 X0 I5 f9 f6 h
(sa) sa_dest= 58.20.43.227, sa_proto= 50,
% Y! j2 S4 J: u% S1 ^- V5 Y sa_spi= 0x4BB72C8F(1270295695), ) ?) Y' ^# z6 L& o2 B
sa_trans= esp-des esp-md5-hmac , sa_conn_id= 23 v, {; y/ o4 K" p7 V; u! z0 ^
sa_lifetime(k/sec)= (4434691/86400)
G$ D4 |# x. E: l$ p6 [! tAug 27 11:42:37.479: IPSEC(update_current_outbound_sa): get enable SA peer 58.*.*.*current outbound sa to SPI 4BB72C8F
' c) S+ ?# j2 b( \( Q5 lAug 27 11:42:37.479: IPSEC(update_current_outbound_sa): updated peer 58.*.*.*current outbound sa to SPI 4BB72C8F
u" [0 P5 k) K: w' nAug 27 11:42:38.799: ISAKMP2001): retransmitting phase 2 QM_IDLE 475159008 ...7 K# h; I1 j K7 n {
Aug 27 11:42:38.799: ISAKMP (2001): incrementing error counter on node, attempt 1 of 5: retransmit phase 2
/ X8 r& x! J8 F8 CAug 27 11:42:38.799: ISAKMP (2001): incrementing error counter on sa, attempt 1 of 5: retransmit phase 2
2 z8 g* ]; \. j" R3 T/ {Aug 27 11:42:38.799: ISAKMP2001): retransmitting phase 2 475159008 QM_IDLE ) R* @% r/ i u
Aug 27 11:42:38.799: ISAKMP2001): sending packet to 58.*.*.*my_port 500 peer_port 500 (I) QM_IDLE 0 ?, `9 @0 h0 R1 N s, P
Aug 27 11:42:38.799: ISAKMP2001):Sending an IKE IPv4 Packet.
/ ^" ?% R$ B- d0 L; H eAug 27 11:42:39.483: ISAKMP (2001): received packet from 58.*.*.*dport 500 sport 500 Global (I) QM_IDLE 1 {+ G) W2 s( \9 @3 s/ h
Aug 27 11:42:39.487: ISAKMP2001): processing HASH payload. message ID = 475159008
4 K! V1 ]+ B- K* a& V0 |7 V) AAug 27 11:42:39.487: ISAKMP2001): processing SA payload. message ID = 475159008
9 F4 i. ?# }) e1 l& f# R3 nAug 27 11:42:39.487: ISAKMP2001):Checking IPSec proposal 1
' t$ }, d- Y7 q3 G9 p1 nAug 27 11:42:39.487: ISAKMP: transform 1, ESP_DES2 {( h! i' p! U+ M* P
Aug 27 11:42:39.487: ISAKMP: attributes in transform:
# M6 {/ T5 C/ u/ P$ R: q& Q8 oAug 27 11:42:39.487: ISAKMP: encaps is 1 (Tunnel)8 Z/ F+ u! i% S, H7 Y2 s( B
Aug 27 11:42:39.487: ISAKMP: SA life type in seconds' H7 ~' `4 Q5 t- A! H9 A+ l
Aug 27 11:42:39.487: ISAKMP: SA life duration (VPI) of 0x0 0x1 0x51 0x80 9 W" L- R, k& R# e
Aug 27 11:42:39.487: ISAKMP: SA life type in kilobytes8 q, w5 F* Y4 F3 w+ S) E
Aug 27 11:42:39.487: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0 # {$ [! u& d. M4 b% h& N
Aug 27 11:42:39.487: ISAKMP: authenticator is HMAC-MD53 |9 p0 A- z" O6 k9 B
Aug 27 11:42:39.487: ISAKMP: group is 28 w K9 B2 c' k: _
Aug 27 11:42:39.487: ISAKMP2001):atts are acceptable.! o" B! a: O- q8 I. q
Aug 27 11:42:39.487: IPSEC(validate_proposal_request): proposal part #1
2 V% A1 |, Q# m1 o. ^3 YAug 27 11:42:39.487: IPSEC(validate_proposal_request): proposal part #1,
! r; B: b' O9 S4 x% T# Q' T' |! Z (key eng. msg.) INBOUND local= 118.*.*.*:0, remote= 58.20.43.227:0, : L$ n4 t+ f' _ t E' n
local_proxy= 10.23.54.32/255.255.255.252/0/0 (type=4),
0 _! H b, i6 G remote_proxy= 10.23.8.0/255.255.248.0/0/0 (type=4),
& w0 y4 s V0 _, ]8 P4 o2 l. y$ F1 H protocol= ESP, transform= NONE (Tunnel),
! I$ A; V0 W( _0 ^ j lifedur= 0s and 0kb, * j8 A' k( m3 E7 @2 w
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x06 r1 X) L" u. ~/ c: T" X
Aug 27 11:42:39.487: Crypto mapdb : proxy_match; Z3 m" V6 V4 C" y! K
src addr : 10.23.54.32$ n9 A8 M5 a: o* |) W
dst addr : 10.23.8.0
8 s0 m9 |0 f8 @" E& C7 K protocol : 0
! D2 D0 U! c! z src port : 08 J9 F' i5 m7 _
dst port : 06 W& F% F5 L$ |, I7 g4 W8 [/ D6 F q
Aug 27 11:42:39.487: ISAKMP2001): processing NONCE payload. message ID = 475159008
3 A. R3 q3 D# O6 N% Y3 ~Aug 27 11:42:39.487: ISAKMP2001): processing KE payload. message ID = 475159008
9 A, n+ W/ I6 @7 o8 K: qAug 27 11:42:39.515: ISAKMP2001): processing ID payload. message ID = 475159008# e- M/ ?, h: I) g
Aug 27 11:42:39.515: ISAKMP2001): processing ID payload. message ID = 4751590080 o6 t; I/ z* z! W2 a
Aug 27 11:42:39.515: ISAKMP2001): Creating IPSec SAs% r8 ]9 H a9 X
Aug 27 11:42:39.515: inbound SA from 58.*.*.*to 118.*.*.* (f/i) 0/ 0
' z( a7 E6 ]5 F% \- z+ l p: `2 u (proxy 10.23.8.0 to 10.23.54.32)6 H. J' i: i3 U) \9 X0 v: u
Aug 27 11:42:39.515: has spi 0xBABB1470 and conn_id 0
8 e' D z# j$ L9 a% V9 V9 oAug 27 11:42:39.515: lifetime of 86400 seconds6 c) Y5 b t& s Z5 W9 B5 K" K
Aug 27 11:42:39.515: lifetime of 4608000 kilobytes
, d* Z6 X3 g9 ?Aug 27 11:42:39.515: outbound SA from 118.*.*.* to 58.*.*.*(f/i) 0/0
0 t6 S& P, m# S3 F8 ~/ [3 Q' V9 [ (proxy 10.23.54.32 to 10.23.8.0)' ~( m& d: H: U1 u% d
Aug 27 11:42:39.515: has spi 0xB6B88103 and conn_id 0
! W2 z- K3 p1 u: TAug 27 11:42:39.515: lifetime of 86400 seconds5 h! y# c0 o/ f8 v$ ?* }' ~
Aug 27 11:42:39.515: lifetime of 4608000 kilobytes. G% B! P0 }+ \# K
Aug 27 11:42:39.515: ISAKMP2001): sending packet to 58.*.*.*my_port 500 peer_port 500 (I) QM_IDLE 7 r4 d8 k1 a! U
Aug 27 11:42:39.519: ISAKMP2001):Sending an IKE IPv4 Packet.
! ` }# b) e6 q& a" fAug 27 11:42:39.519: ISAKMP2001):deleting node 475159008 error FALSE reason "No Error"
7 u( _+ b& w; f' H& o5 ?& W hAug 27 11:42:39.519: ISAKMP2001):Node 475159008, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH* z8 I: u h5 G' E1 j
Aug 27 11:42:39.519: ISAKMP2001):Old State = IKE_QM_I_QM1 New State = IKE_QM_PHASE2_COMPLETE8 N8 {. Z; I4 j. }
Aug 27 11:42:39.519: IPSEC(key_engine): got a queue event with 1 KMI message(s)
- ~8 P+ M1 G3 G7 z* E" t! bAug 27 11:42:39.519: Crypto mapdb : proxy_match
7 Q) s. A$ K& \& ? src addr : 10.23.54.32
. S' B/ Z4 d+ l1 { dst addr : 10.23.8.08 U, f: q* p: G7 J" `+ W0 N
protocol : 0, W- V2 j3 u x* a# t# {8 \6 C
src port : 06 Y& y% [6 c6 D+ Y D& `; h
dst port : 0
- E8 S9 C' v* X% CAug 27 11:42:39.519: IPSEC(crypto_ipsec_sa_find_ident_head): reconnecting with the same proxies and peer 58.20.43.227) ?; B& N) z8 E# j* r6 V
Aug 27 11:42:39.519: IPSEC(rte_mgr): VPN Route Event create SA based on crypto ACL in real time for 58.20.43.2277 E, w3 E% y) u, `7 W& q+ F/ `
Aug 27 11:42:39.519: IPSEC(rte_mgr): Route add Peer 58.*.*.*, Destination 10.23.8.0, Nexthop 0.0.0.0, RT type 1; W7 w' R0 y0 D) b, K N
Aug 27 11:42:39.519: IPSEC(rte_mgr):Search route found ID 1
# p7 j% V- ] E, U4 g4 N' zAug 27 11:42:39.519: IPSEC(rte_mgr): VPN Route Refcount 2 58.*.*.*on Dialer10
! T" t+ p$ @5 O% QAug 27 11:42:39.519: IPSEC(create_sa): sa created,
9 O, w; q; h- e7 |/ Y$ { (sa) sa_dest= 118.*.*.*, sa_proto= 50, . w9 |3 h1 ?* {9 a
sa_spi= 0xBABB1470(3132822640),
5 k5 _ W$ U5 _+ Q sa_trans= esp-des esp-md5-hmac , sa_conn_id= 3+ d5 B0 `- O1 b# V4 h8 e
sa_lifetime(k/sec)= (4558678/86400)
6 A; P5 D% C( D% j( Q: PAug 27 11:42:39.519: IPSEC(create_sa): sa created,
4 V3 p: G; T# c (sa) sa_dest= 58.20.43.227, sa_proto= 50, ; A9 k/ n5 K- g6 U5 O7 `0 m
sa_spi= 0xB6B88103(3065544963),
/ X. e2 b+ n- G: f- F* A sa_trans= esp-des esp-md5-hmac , sa_conn_id= 4
8 o8 ]( A' a I$ \1 j# Q' b, q sa_lifetime(k/sec)= (4558678/86400)! O; g) @2 m. i. c- |
Aug 27 11:42:39.519: IPSEC(update_current_outbound_sa): get enable SA peer 58.*.*.*current outbound sa to SPI B6B88103
4 r$ j& {2 |7 @2 U7 hAug 27 11:42:39.519: IPSEC(update_current_outbound_sa): updated peer 58.*.*.*current outbound sa to SPI B6B88103
{, s5 C0 Y8 v" EAug 27 11:42:39.519: IPSEC(check_delete_duplicate_sa_bundle): found duplicated fresh SA bundle, aging it out. min_spi=4BB72C8F
3 Z* w) _, e5 o+ CAug 27 11:42:39.519: IPSEC(early_age_out_sibling): sibling outbound SPI 4BB72C8F expiring in 30 seconds due to it's a duplicate SA bundle.
; B1 m- O5 W; A; G1 Z( z) gRouter(config-if)#- x% a0 M) Z1 d& n* i' w
Aug 27 11:43:02.435: ISAKMP (2001): received packet from 58.*.*.*dport 500 sport 500 Global (I) QM_IDLE
# j: P4 L: z7 w4 F/ e* J0 LAug 27 11:43:02.435: ISAKMP: set new node -917327660 to QM_IDLE ) Z! R, S% K& z4 c. ~
Aug 27 11:43:02.435: ISAKMP2001): processing HASH payload. message ID = 3377639636
2 b& k: T( x+ FAug 27 11:43:02.435: ISAKMP2001): processing DELETE payload. message ID = 3377639636
: r* Y4 F7 S+ b" p7 i! XAug 27 11:43:02.435: ISAKMP2001):peer does not do paranoid keepalives.. r7 T5 L& q! L5 F* {8 R5 o
0 _* B* t* s4 u1 a- ^( m7 aAug 27 11:43:02.435: ISAKMP2001):deleting node -917327660 error FALSE reason "Informational (in) state 1") L) R* e6 d. B, a a) Q
Aug 27 11:43:02.435: IPSEC(key_engine): got a queue event with 1 KMI message(s)3 ?' v1 g# \7 H( t
Aug 27 11:43:02.435: IPSEC(key_engine_delete_sas): rec'd delete notify from ISAKMP
9 G4 ]4 G. m, C2 _3 fAug 27 11:43:04.519: ISAKMP: set new node 804935725 to QM_IDLE
0 c' m0 |. M6 \) m( GAug 27 11:43:04.519: ISAKMP2001): sending packet to 58.*.*.*my_port 500 peer_port 500 (I) QM_IDLE
c! V: X8 h. {Aug 27 11:43:04.519: ISAKMP2001):Sending an IKE IPv4 Packet.
( l, Z8 Y0 v& n! W2 Z H! UAug 27 11:43:04.519: ISAKMP2001):purging node 804935725/ ? W# }) Q* w- ?8 S
Aug 27 11:43:04.519: ISAKMP2001):Input = IKE_MESG_FROM_IPSEC, IKE_PHASE2_DEL3 }& H8 A; x! w/ \4 I
Aug 27 11:43:04.519: ISAKMP2001):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
0 G( W& L- d* ?: \) e2 H# F' H' d2 q8 @
Aug 27 11:43:07.435: ISAKMP (2001): received packet from 58.*.*.*dport 500 sport 500 Global (I) QM_IDLE ' H. J5 n9 H5 N/ E2 s
Aug 27 11:43:07.435: ISAKMP: set new node -492395739 to QM_IDLE . R& t- c! E% F/ W* R
Aug 27 11:43:07.435: ISAKMP2001): processing HASH payload. message ID = 3802571557
1 a2 c3 }* N3 Y5 U& U, v; R, wAug 27 11:43:07.435: ISAKMP2001): processing DELETE payload. message ID = 3802571557
0 m9 q# `- V. ~* Q! ^" F8 y. t9 wAug 27 11:43:07.435: ISAKMP2001):peer does not do paranoid keepalives.
' V+ B4 i! H4 C/ G+ z$ F2 L- M. t' e) b! Y; T3 q
Aug 27 11:43:07.435: ISAKMP2001):deleting node -492395739 error FALSE reason "Informational (in) state 1"
; \* E$ K, r) d# s. u- iAug 27 11:43:07.439: IPSEC(key_engine): got a queue event with 1 KMI message(s)
, W/ a. \0 R6 d N: g( dAug 27 11:43:07.439: IPSEC(key_engine_delete_sas): rec'd delete notify from ISAKMP: s, h2 t0 B) P# ?' @
Aug 27 11:43:07.439: IPSEC(key_engine_delete_sas): delete SA with spi 0x4BB72C8F proto 50 for 58.20.43.2279 _# S5 C0 a+ z: L1 @5 Q) r) H
Aug 27 11:43:07.439: IPSEC(delete_sa): deleting SA,
; u8 \- l7 a* X* o( i0 \ (sa) sa_dest= 118.*.*.*, sa_proto= 50,
% h3 C: E1 D8 h sa_spi= 0xCC7B952A(3430651178),
) F9 M# G l4 J1 o+ z4 i sa_trans= esp-des esp-md5-hmac , sa_conn_id= 1* P5 a9 {: w; _( h& P5 H
sa_lifetime(k/sec)= (4434691/86400),
2 B# \4 A6 ?8 E [ q" S (identity) local= 118.*.*.*:0, remote= 58.20.43.227:0, * w1 V% Q2 z# G5 U9 H; ? J
local_proxy= 10.23.54.32/255.255.255.252/0/0 (type=4), " A% P; `) F+ ?/ ~) u
remote_proxy= 10.23.8.0/255.255.248.0/0/0 (type=4)
+ ?3 B/ P+ V( qAug 27 11:43:07.439: IPSEC(delete_sa): deleting SA,
9 y/ _; t5 }# D$ ^, k/ O (sa) sa_dest= 58.20.43.227, sa_proto= 50,
7 [8 r2 v7 R& S0 X sa_spi= 0x4BB72C8F(1270295695),
3 y1 X' G3 `6 B4 b sa_trans= esp-des esp-md5-hmac , sa_conn_id= 25 J4 `1 ~: ?; r. X5 P' o- P
sa_lifetime(k/sec)= (4434691/86400),- p9 @; O, y* o# w& F: Y* |" T
(identity) local= 118.*.*.*:0, remote= 58.20.43.227:0, . I4 B4 }$ \. U
local_proxy= 10.23.54.32/255.255.255.252/0/0 (type=4), 8 q. ?( u) U+ G5 V, N
remote_proxy= 10.23.8.0/255.255.248.0/0/0 (type=4)6 s0 {7 b) W- y0 C0 j$ [& P3 i
Aug 27 11:43:07.439: IPSEC(rte_mgr): Delete Route found ID 1
1 _: w; t5 o6 k. x8 O7 C0 TAug 27 11:43:07.439: IPSEC(rte_mgr): VPN Route Refcount 1 Dialer10! E; R9 m) S i2 Q
Router(config-if)#
8 M6 [) E! r# j2 F) t/ BAug 27 11:43:27.475: ISAKMP2001):purging node 1853074095
6 Y: Q1 C4 ?" a5 g" B* VAug 27 11:43:29.519: ISAKMP2001):purging node 475159008: E8 W1 x" v0 G
Aug 27 11:43:52.435: ISAKMP2001):purging node -917327660
3 u9 t1 L6 r' X0 z1 T3 F; d: P5 w. b8 \Aug 27 11:43:57.435: ISAKMP2001):purging node -492395739 |