Cisco网络技术论坛

返回   Cisco网络技术论坛 > Cisco专区 > Cisco网络协议分析、故障诊断【泰克实验室】

Cisco网络协议分析、故障诊断【泰克实验室】 Net130和泰克网络实验室携手,共同分析讨论疑难问题,让我们一起努力,为未来加油!

发表新主题 回复
 
主题工具
旧 2014-07-17, 10:14   #1
jtthrille
注册用户
级别:0 | 在线时长:4小时 | 升级还需:1小时
 
注册日期: Aug 2013
帖子: 5
现金:3金币
资产:3金币
声望力: 0
声望: 10 jtthrille 向着好的方向发展
声望力: 0
jtthrille 向着好的方向发展
赞成 EZ-vpn问题

EZ-VPN server端配置好后,用cisco软件连接,总是连不上server,show crypto isakmp sa是有的,但没有ipsec sa,以下有本人debug出来的信息,求高手指点:
*Jul 16 09:29:40.903: IPSEC(key_engine): got a queue event with 1 KMI message(s)
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= PCP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes 256 esp-md5-hmac comp-lzs }
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= PCP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes 256 esp-sha-hmac comp-lzs }
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= PCP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes esp-md5-hmac comp-lzs }
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2
*Jul 16 09:29:46.655: IPSEC(validate_proposal_request): proposal part #2,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= PCP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.655: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes esp-sha-hmac comp-lzs }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes 256 esp-md5-hmac }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes 256 esp-sha-hmac }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes esp-md5-hmac }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-aes esp-sha-hmac }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #2
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #2,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= PCP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-3des esp-md5-hmac comp-lzs }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #2
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #2,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= PCP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.659: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
{esp-3des esp-sha-hmac comp-lzs }
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1
*Jul 16 09:29:46.659: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= 192.168.1.1, remote= 192.168.1.10,
local_proxy= 0.0.0.0/0.0.0.0/0/0 (type=4),
remote_proxy= 123.1.1.15/255.255.255.255/0/0 (type=1),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
*Jul 16 09:29:46.663: IPSEC(key_engine): got a queue event with 1 KMI message(s)
*Jul 16 09:29:46.663: IPSEC(policy_db_add_ident): src 0.0.0.0, dest 123.1.1.15, dest_port 0

*Jul 16 09:29:46.663: IPSEC(create_sa): sa created,
(sa) sa_dest= 192.168.1.1, sa_proto= 50,
sa_spi= 0x5A14A6C9(1511302857),
帅哥 jtthrille 当前离线  
回复时引用此帖
发表新主题 回复

标签
ez-vpn

主题工具

发帖规则
不可以发表新主题
不可以发表回复
不可以上传附件
不可以编辑自己的帖子

启用 BB 代码
论坛启用 表情符号
论坛启用 [IMG] 代码
论坛禁用 HTML 代码

论坛跳转

相似的主题
主题 主题作者 版面 回复 最后发表
VPN连不上的问题,急救!! brown_zhou Cisco技术 2 2003-11-05 16:03
急问关于VPN的2个问题啊,谢谢! tiantianok Cisco技术 2 2003-10-30 17:51
大家好,新来乍到,请多关照,VPN问题。 竹笋 Cisco技术 17 2003-10-15 17:47
请教关于cisco1721配置vpn的问题! 初学者 Cisco技术 9 2003-08-07 09:17
请教各位或版主: 我在做用PPTP和IPSEC做点对点VPN时遇到了问题? suobk Cisco技术 2 2003-07-25 18:10


所有时间均为北京时间。现在的时间是 07:37


Powered by vBulletin® 版本 3.8.3
版权所有 ©2000 - 2018,Jelsoft Enterprises Ltd.
增强包 [3.4] 制作: PHP源动力   官方中文站: vBulletin 中文
Copyright © 2003 - 2013 Net130.com, All Rights Reserved 备案号:皖ICP备11007528号