- 积分
- 502
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 40
- 听众
- 收听
中级工程师
   
|
20鸿鹄币
两台路由器建立IPSEC VPN,一端是cisco,另外一端是huawei,已经对比过第一阶段和第二阶段的配置两端完全相同,但是cisco这边有报错信息,信息如下- Mar 15 15:58:50.094: %CRYPTO-4-IKMP_NO_SA: IKE message from 172.18.220.99 has no SA and is not an initialization offer
- Mar 15 16:10:35.927: %CRYPTO-4-IKMP_NO_SA: IKE message from 172.18.220.98 has no SA and is not an initialization offer
- Mar 16 08:47:14.861: %CRYPTO-4-IKMP_NO_SA: IKE message from 172.18.220.99 has no SA and is not an initialization offer
- Mar 16 08:58:44.130: %CRYPTO-4-IKMP_NO_SA: IKE message from 172.18.220.98 has no SA and is not an initialization offer
- Mar 16 14:14:23.340: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.18.220.1, prot=51, spi=0xEE2E4D70(3996011888), srcaddr=172.18.220.19, input interface=GigabitEthernet0/1
- Mar 16 14:53:10.679: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.18.220.1, prot=51, spi=0x11BCDAD(18599341),
复制代码 第一阶段两端均显示已建立成功,第二阶段只有华为显示建立成功,思科没成功,求大神解答一下这是什么原因?
两台设备配置已经添加到附件
|
最佳答案
查看完整内容
第一阶段能建立,说明配置5要素没问题的。
第二阶段
检查模式/与共享密钥/tras-set名称/peer地址/
|