阿里云VPN网关与IDC网关连接第一阶段协商未成功。帮我分析一下,谢了。
1、阿里云VPN网关配置
{
"LocalSubnet": "10.116.0.0/16",
"RemoteSubnet": "172.17.0.0/16",
"IpsecConfig": {
"IpsecPfs": "group2",
"IpsecEncAlg": "aes",
"IpsecAuthAlg": "md5",
"IpsecLifetime": 86400
},
"Local": "xxx.xxx.xxx.xxx",
"Remote": "yyy.yyy.yyy.yyy",
"IkeConfig": {
"IkeAuthAlg": "md5",
"LocalId": "xxx.xxx.xxx.xxx",
"IkeEncAlg": "aes",
"IkeVersion": "ikev1",
"IkeMode": "main",
"IkeLifetime": 86400,
"RemoteId": "yyy.yyy.yyy.yyy",
"Psk": "kyglbd82eb8hgcnp",
"IkePfs": "group2"
}
}
2、IDC网关(思科路由器)配置如下:
crypto isakmp policy 100
encryption aes
hash md5
authentication pre-share
group 2
lifetime 86400
!
crypto isakmp key kyglbd82eb8hgcnp address yyy.yyy.yyy.yyy
!
crypto ipsec transform-set AliVPN esp-aes esp-md5-hmac
!
crypto map clientmap 100 ipsec-isakmp
set peer yyy.yyy.yyy.yyy
set security-association lifetime seconds 86400
set transform-set AliVPN
set pfs group2
match address AliVPN-ACL
ip access-list extended AliVPN-ACL
permit ip 10.116.0.0 0.0.255.255 172.17.0.0 0.0.255.255
3、日志如下
2018-09-21 17:28:35 14[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 5 of request message ID 0, seq 3
2018-09-21 17:28:35 14[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:28:54 14[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending keep alive to xxx.xxx.xxx.xxx[4500]
2018-09-21 17:29:14 11[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending keep alive to xxx.xxx.xxx.xxx[4500]
2018-09-21 17:29:34 14[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending keep alive to xxx.xxx.xxx.xxx[4500]
2018-09-21 17:29:50 11[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> giving up after 5 retransmits
2018-09-21 17:29:50 11[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> peer not responding, trying again (2/3)
2018-09-21 17:29:50 11[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> initiating Main Mode IKE_SA vco-2zecu5qsefdknk9a9zmdf[48] to xxx.xxx.xxx.xxx
2018-09-21 17:29:50 11[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> generating ID_PROT request 0 [ SA V V V V V ]
2018-09-21 17:29:50 11[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[500] to xxx.xxx.xxx.xxx[500] (224 bytes)
2018-09-21 17:29:50 06[NET] <vco-2zecu5qsefdknk9a9zmdf|48> received packet: from xxx.xxx.xxx.xxx[500] to 172.17.1.16[500] (108 bytes)
2018-09-21 17:29:50 06[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> parsed ID_PROT response 0 [ SA V ]
2018-09-21 17:29:50 06[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received NAT-T (RFC 3947) vendor ID
2018-09-21 17:29:50 06[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
2018-09-21 17:29:50 06[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[500] to xxx.xxx.xxx.xxx[500] (236 bytes)
2018-09-21 17:29:50 12[NET] <vco-2zecu5qsefdknk9a9zmdf|48> received packet: from xxx.xxx.xxx.xxx[500] to 172.17.1.16[500] (296 bytes)
2018-09-21 17:29:50 12[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> parsed ID_PROT response 0 [ KE No V V V V NAT-D NAT-D ]
2018-09-21 17:29:50 12[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received Cisco Unity vendor ID
2018-09-21 17:29:50 12[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received DPD vendor ID
2018-09-21 17:29:50 12[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> received unknown vendor ID: b8:fd:13:8e:3a:7e:00:53:2b:f3:b5:af:dd:41:48:bd
2018-09-21 17:29:50 12[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received XAuth vendor ID
2018-09-21 17:29:50 12[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> generating ID_PROT request 0 [ ID HASH ]
2018-09-21 17:29:50 12[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:29:54 11[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 1 of request message ID 0, seq 3
2018-09-21 17:29:54 11[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:30:02 06[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 2 of request message ID 0, seq 3
2018-09-21 17:30:02 06[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:30:15 14[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 3 of request message ID 0, seq 3
2018-09-21 17:30:15 14[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:30:38 12[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 4 of request message ID 0, seq 3
2018-09-21 17:30:38 12[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:31:20 07[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 5 of request message ID 0, seq 3
2018-09-21 17:31:20 07[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:32:36 07[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> giving up after 5 retransmits
2018-09-21 17:32:36 07[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> peer not responding, trying again (3/3)
2018-09-21 17:32:36 07[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> initiating Main Mode IKE_SA vco-2zecu5qsefdknk9a9zmdf[48] to xxx.xxx.xxx.xxx
2018-09-21 17:32:36 07[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> generating ID_PROT request 0 [ SA V V V V V ]
2018-09-21 17:32:36 07[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[500] to xxx.xxx.xxx.xxx[500] (224 bytes)
2018-09-21 17:32:36 08[NET] <vco-2zecu5qsefdknk9a9zmdf|48> received packet: from xxx.xxx.xxx.xxx[500] to 172.17.1.16[500] (108 bytes)
2018-09-21 17:32:36 08[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> parsed ID_PROT response 0 [ SA V ]
2018-09-21 17:32:36 08[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received NAT-T (RFC 3947) vendor ID
2018-09-21 17:32:36 08[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
2018-09-21 17:32:36 08[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[500] to xxx.xxx.xxx.xxx[500] (236 bytes)
2018-09-21 17:32:36 10[NET] <vco-2zecu5qsefdknk9a9zmdf|48> received packet: from xxx.xxx.xxx.xxx[500] to 172.17.1.16[500] (296 bytes)
2018-09-21 17:32:36 10[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> parsed ID_PROT response 0 [ KE No V V V V NAT-D NAT-D ]
2018-09-21 17:32:36 10[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received Cisco Unity vendor ID
2018-09-21 17:32:36 10[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received DPD vendor ID
2018-09-21 17:32:36 10[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> received unknown vendor ID: b8:fd:13:8e:a6:71:2c:2b:1e:9b:c2:48:94:54:2b:13
2018-09-21 17:32:36 10[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> received XAuth vendor ID
2018-09-21 17:32:36 10[ENC] <vco-2zecu5qsefdknk9a9zmdf|48> generating ID_PROT request 0 [ ID HASH ]
2018-09-21 17:32:36 10[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:32:40 11[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 1 of request message ID 0, seq 3
2018-09-21 17:32:40 11[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:32:47 10[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 2 of request message ID 0, seq 3
2018-09-21 17:32:47 10[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:33:00 06[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 3 of request message ID 0, seq 3
2018-09-21 17:33:00 06[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:33:23 07[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 4 of request message ID 0, seq 3
2018-09-21 17:33:23 07[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:34:05 10[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> sending retransmit 5 of request message ID 0, seq 3
2018-09-21 17:34:05 10[NET] <vco-2zecu5qsefdknk9a9zmdf|48> sending packet: from 172.17.1.16[4500] to xxx.xxx.xxx.xxx[4500] (76 bytes)
2018-09-21 17:35:21 12[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> giving up after 5 retransmits
2018-09-21 17:35:21 12[IKE] <vco-2zecu5qsefdknk9a9zmdf|48> establishing IKE_SA failed, peer not responding
以上