
请求帮助:思科ASA 5520和华为eudemon 300建立L2L vpn不通。
( I8 V! V T U! n* d! S/ Q! g1 O( |* t: A7 \2 [- `' G' D" K
用sh crypto iskmp sa,能看到隧道已经建立。用sh cryp ipsec sa,只能看到加密的数据包,不能看到解密的包。为什么?请高手解答。) M8 S" ]7 X3 _9 ~9 z3 @
& d" Z; j2 Z1 a+ T/ qFW-02# sh cryp isak sa detail
' u* q) b. `0 y- v4 v& r IKE Peer: 60.12.194.14
; v' E$ l6 K% n4 B4 T Type : L2L Role : initiator
# p$ v9 I% u4 ~3 O Rekey : no State : MM_ACTIVE
0 R6 _' j" K i/ O U# Q4 v& r# R9 F6 A4 @1 w5 {
FW-02# sh cryp isak sa detail( T+ x2 W/ b8 c, M* w: Q0 j
IKE Peer: 60.12.194.14
2 M+ C7 X$ X& `- X D2 \; \$ k* L Type : L2L Role : initiator
# F& C4 }1 E" e; @1 f Rekey : no State : MM_ACTIVE ' z" k: E3 ?" y! }! S, o& m
Encrypt : des Hash : SHA
* l) i* ^. _- u& I, _ Auth : preshared Lifetime: 86400" v8 a+ G3 n1 x' l4 D, }: Q
Lifetime Remaining: 856775 k& w" }" [; `; l+ \
' m7 ~$ I$ r% N. gFW-02# sh crypt ipsec sa
+ t! Y/ u5 L0 y$ O6 j; A G9 q+ K7 p# E" y1 }
interface: outside
8 m8 K `, J/ G0 \9 {" S Crypto map tag: mymap, seq num: 20, local addr: 119.57.5.54 U& z/ p6 l" y) U$ v( T
T* R7 C! R1 U3 M6 b access-list outside_20_cryptomap permit ip host 10.0.1.17 172.16.12.0 255.255.255.0 7 h0 y: I( P1 K3 |
local ident (addr/mask/prot/port): (10.0.1.17/255.255.255.255/0/0)7 j' Y% `/ R [/ M5 y/ K2 F& S
remote ident (addr/mask/prot/port): (172.16.12.0/255.255.255.0/0/0)
4 |: L" D9 Z' b9 P: Q1 {9 g current_peer: 60.12.194.14
5 _% o1 u$ a5 K2 ]$ A
6 R5 x* g* [# c3 } #pkts encaps: 435, #pkts encrypt: 435, #pkts digest: 435
4 D; R$ q8 d9 n8 O0 u3 ` #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0' Y0 L1 J9 E' B1 w6 P) I1 v4 Z$ G
#pkts compressed: 0, #pkts decompressed: 0
, M1 r* W% b* A #pkts not compressed: 435, #pkts comp failed: 0, #pkts decomp failed: 0
* f# g8 }' b( p: T% i. V& Q #send errors: 0, #recv errors: 0
& i! i% ?5 }) N: g( S, l% a. r( R+ @4 g% g+ J" @: t0 x( U9 q; D
local crypto endpt.: 119.57.5.5, remote crypto endpt.: 60.12.194.14
+ I* J8 l0 R1 O& _' d
/ X$ ^% F; Y5 U8 t4 l; v path mtu 1500, ipsec overhead 58, media mtu 1500
) z# q+ E! L4 g* D3 r! G current outbound spi: 3ECC31B0
- L3 x6 o8 {9 l" _5 f! E# q8 h8 h0 Z2 q |& z. k) L* g" t
inbound esp sas:+ E' c2 x; ~; P. Q$ w+ L% E7 @5 M
spi: 0x11CAA980 (298494336)/ g, |4 E) G5 Y- h4 X0 I
transform: esp-des esp-md5-hmac none V8 [8 `9 s; X1 P; A
in use settings ={L2L, Tunnel, PFS Group 2, }
8 a2 c7 D9 [* ^! l N slot: 0, conn_id: 316, crypto-map: mymap" a' ]. t9 K& F' {8 X
sa timing: remaining key lifetime (kB/sec): (1710000/2815)
$ _: V4 S6 |6 _; K IV size: 8 bytes
7 W2 W, U8 {. F replay detection support: Y Y& V- Z7 S* d' {& f# W
outbound esp sas:
$ C1 B0 E' n$ l, v3 _+ g spi: 0x3ECC31B0 (1053569456)
' v1 H" m' B0 K& a& F2 e$ a transform: esp-des esp-md5-hmac none
5 H4 W1 Q) \. l6 L( i2 \ in use settings ={L2L, Tunnel, PFS Group 2, }$ @9 L& G( v: R2 P" D
slot: 0, conn_id: 316, crypto-map: mymap
5 e F" H; u9 I2 X, Z# g sa timing: remaining key lifetime (kB/sec): (1709960/2767)" S2 k( f8 ?" v+ u9 E" z ]
IV size: 8 bytes2 B4 H) {# {( X& r7 @# m+ p# p
replay detection support: Y |
|