发新话题
打印

[问题求助] IKE 用户vpn连接问题,朋友们请帮下忙!

IKE 用户vpn连接问题,朋友们请帮下忙!

客户端日志如下,请各位朋友分析一下是什么原因,如何解决!
4-07: 08:10:48.671
4-07: 08:10:48.671 My Connections\no1 - Initiating IKE Phase 1 (IP ADDR=1.1.1.1)
4-07: 08:10:48.812 My Connections\no1 - SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 6x)
4-07: 08:10:48.812 My Connections\no1 - RECEIVED<<< ISAKMP OAK AG (SA, VID 3x, KE, NON, ID, HASH, VID, NAT-D 2x)
4-07: 08:10:48.812 My Connections\no1 - Received message for non-active SA
4-07: 08:10:48.812 My Connections\no1 - RECEIVED<<< ISAKMP OAK AG (SA, VID 3x, KE, NON, ID, HASH, VID, NAT-D 2x)
4-07: 08:10:48.812 Incorrect Phase 1 ID type (expected ID_IPV4_ADDR):
4-07: 08:10:48.812   received ID DOMAIN=XXX
4-07: 08:10:48.812 My Connections\no1 - Peer supports Dead Peer Detection Version 1.0
4-07: 08:10:48.812 My Connections\no1 - Dead Peer Detection enabled
4-07: 08:10:48.812 My Connections\no1 - Peer is NAT-T draft-02 capable
4-07: 08:10:48.812 My Connections\no1 - Dead Peer Detection enabled
4-07: 08:10:48.812 My Connections\no1 - NAT is detected for Client
4-07: 08:10:48.812 My Connections\no1 - Floating to IKE non-500 port
4-07: 08:10:48.906 No matching Phase 1 ID received for Policy Entry My Connections\no1.
4-07: 08:10:48.906 My Connections\no1 - SENDING>>>> ISAKMP OAK INFO (HASH, NOTIFY:INVALID_ID_INFO)
4-07: 08:10:48.906 My Connections\no1 - Discarding IKE SA negotiation
4-07: 08:10:48.906    MY COOKIE 83 6e e8 24 1f 74 37 c
4-07: 08:10:48.906    HIS COOKIE d5 6b f a9 32 80 29 9f
4-07: 08:10:52.703 My Connections\no1 - RECEIVED<<< ISAKMP OAK AG (SA, VID 3x, KE, NON, ID, HASH, VID, NAT-D 2x)
4-07: 08:10:52.703 My Connections\no1 - Received message for non-active SA

TOP

最好也能贴出 防火墙一端的  log
生命无止境,永攀最高峰!

TOP

Rejected an IKE packet on ethernet0/2 from 1.1.1.3:29164 to 1.1.1.7:500 with cookies 4061c19f3e1c64e8 and a734e1187fcef4b2 because The peer sent a packet with a message ID before Phase 1 authentication was done.

看日志应该是第一阶段的phase不匹配,但我查了一下,防火墙及客户端的设置没有问题啊1

[ 本帖最后由 ycclwyf 于 2008-4-7 09:40 编辑 ]

TOP

get sa, get proxy 啥的看一下,检查一下配置,另外,检查一下中间又没有nat设备

TOP

哈哈,看看这个:http://k968888.blog.sohu.com/84918025.html
今天刚给客户处理的。

TOP

谢谢兄弟们帮忙,问题已解决

TOP

回复 6# 的帖子

问题出在哪里?

TOP

发新话题