- 积分
- 256
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 30
- 听众
- 收听
初级工程师
  
|

楼主 |
发表于 2013-3-22 12:20:21
|
显示全部楼层
刚刚不死心,又在锐捷的机器上做了实验,发现和cisco15.2一样的问题,虽然知道锐捷是抄袭思科的,但不能连工作模式都抄吧
大致拓扑如下:
172.16.1.1-R1-12.1.1.1——12.1.1.2-R2-23.1.1.2——23.1.1.3-R3-172.16.3.3
对端地址为物理口地址时:
R1#sh cry is sa
destination source state conn-id lifetime(second)
23.1.1.3 13.1.1.1 MM_SI1_WR1, MM_SA_SETUP 0 86387
R1#sh ver
System description : Ruijie Router (RSR20-18) by Ruijie Networks
System start time : 2013-03-22 7:22:26
System uptime : 0:4:45:2
System hardware version : 1.11
System software version : RGOS 10.3(5b6), Release(131709)
System BOOT version : 10.3.131709
对端地址改为tunnel口时:
R3#ping 172.16.1.1 sou 172.16.3.3
Sending 5, 100-byte ICMP Echoes to 172.16.1.1, timeout is 2 seconds:
< press Ctrl+C to break >
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 30/30/30 ms
R3#sh cry is sa
destination source state conn-id lifetime(second)
13.1.1.1 13.1.1.3 IKE_IDLE 0 86386
R3#sh cry ip sa
Interface: Tunnel 0
Crypto map tag:mymap
local ipv4 addr 13.1.1.3
media mtu 1476
==================================
sub_map type:static, seqno:10, id=0
local ident (addr/mask/prot/port): (172.16.3.0/0.0.0.255/0/0))
remote ident (addr/mask/prot/port): (172.16.1.0/0.0.0.255/0/0))
PERMIT
#pkts encaps: 4, #pkts encrypt: 4, #pkts digest 4
#pkts decaps: 4, #pkts decrypt: 4, #pkts verify 4
|
6#
2013-3-22 12:20:21
回复(0)
收起回复
|