
āĻĒāϰāĻŋāϏā§āĻĨāĻŋāϤāĻŋ
āĻā§āĻāĻŋ. āĻāĻŽāĻŋ āĻāĻĢāĻŋ āĻĒāĻžāύ āĻāϰāĻŋ. āĻāĻžāϤā§āϰāĻāĻŋ āĻĻā§āĻāĻŋ āĻĒāϝāĻŧā§āύā§āĻā§āϰ āĻŽāϧā§āϝ⧠āĻāĻāĻāĻŋ āĻāĻŋāĻĒāĻŋāĻāύ āϏāĻāϝā§āĻ āϏā§āĻĨāĻžāĻĒāύ āĻāϰ⧠āĻ āĻĻā§āĻļā§āϝ āĻšāϝāĻŧā§ āĻā§āϞāĨ¤ āĻāĻŽāĻŋ āĻĒāϰā§āĻā§āώāĻž āĻāϰ⧠āĻĻā§āĻāϞāĻžāĻŽ: āĻāĻžāύā§āϞāĻāĻŋ āĻāϏāϞā§āĻ āĻāĻā§, āĻāĻŋāύā§āϤ⧠āĻāĻžāύā§āϞ⧠āĻā§āύ āĻā§āϰāĻžāĻĢāĻŋāĻ āύā§āĻāĨ¤ āĻāĻžāϤā§āϰ āĻāϞā§āϰ āĻāϤā§āϤāϰ āĻĻā§āϝāĻŧ āύāĻžāĨ¤
āĻāĻŽāĻŋ āĻā§āĻāϞāĻŋāĻāĻŋ āĻāĻžāϞ⧠āĻāϰā§āĻāĻŋ āĻāĻŦāĻ S-Terra āĻā§āĻāĻāϝāĻŧā§āϰ āϏāĻŽāϏā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ⧠āĻĄā§āĻŦ āĻĻāĻŋāϝāĻŧā§āĻāĻŋāĨ¤ āĻāĻŽāĻŋ āĻāĻŽāĻžāϰ āĻ
āĻāĻŋāĻā§āĻāϤāĻž āĻāĻŦāĻ āĻĒāĻĻā§āϧāϤāĻŋ āĻļā§āϝāĻŧāĻžāϰ āĻāϰāĻŋāĨ¤
āĻāĻžāĻāĻāĻž āϤāĻĨā§āϝ
āĻĻā§āĻāĻŋ āĻā§āĻāϞāĻŋāĻāĻāĻžāĻŦā§ āĻĒā§āĻĨāĻ āϏāĻžāĻāĻ āĻāĻāĻāĻŋ GRE āĻāĻžāύā§āϞ āĻĻā§āĻŦāĻžāϰāĻž āϏāĻāϝā§āĻā§āϤ āĻāϰāĻž āĻšāϝāĻŧ. GRE āĻāύāĻā§āϰāĻŋāĻĒā§āĻ āĻāϰāĻž āĻĒā§āϰāϝāĻŧā§āĻāύ:

āĻāĻŽāĻŋ āĻāĻŋāĻāϰāĻ āĻāĻžāύā§āϞā§āϰ āĻāϰā§āĻŽāĻā§āώāĻŽāϤāĻž āĻĒāϰā§āĻā§āώāĻž āĻāϰāĻŋāĨ¤ āĻāĻāĻŋ āĻāϰāĻžāϰ āĻāύā§āϝ, āĻāĻŽāĻŋ āĻĄāĻŋāĻāĻžāĻāϏ R1 āĻĨā§āĻā§ āĻĄāĻŋāĻāĻžāĻāϏ R2 āĻāϰ GRE āĻāύā§āĻāĻžāϰāĻĢā§āϏ⧠āĻĒāĻŋāĻ āĻāϰāĻž āĻļā§āϰ⧠āĻāϰāĻŋāĨ¤ āĻāĻāĻŋ āĻāύāĻā§āϰāĻŋāĻĒāĻļāύā§āϰ āĻāύā§āϝ āϞāĻā§āώā§āϝāϝā§āĻā§āϤ āĻā§āϰāĻžāĻĢāĻŋāĻāĨ¤ āĻāϤā§āϤāϰ āύā§āĻ:
root@R1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
--- 1.1.1.2 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3057msāĻāĻŽāĻŋ āĻā§āĻ 1 āĻāĻŦāĻ āĻā§āĻ 2 āĻāϰ āϞāĻāĻā§āϞāĻŋ āĻĻā§āĻāĻŋ⧎ āϞāĻāĻāĻŋ āĻāύāύā§āĻĻā§āϰ āϏāĻžāĻĨā§ āϰāĻŋāĻĒā§āϰā§āĻ āĻāϰ⧠āϝ⧠IPsec āĻāĻžāύā§āϞ āϏāĻĢāϞāĻāĻžāĻŦā§ āĻāĻ ā§ āĻāϏā§āĻā§, āĻā§āύ āϏāĻŽāϏā§āϝāĻž āύā§āĻ:
root@Gate1:~# cat /var/log/cspvpngate.log
Aug 5 16:14:23 localhost vpnsvc: 00100119 <4:1> IPSec connection 5 established, traffic selector 172.17.0.1->172.16.0.1, proto 47, peer 10.10.10.251, id "10.10.10.251", Filter
IPsec:Protect:CMAP:1:LIST, IPsecAction IPsecAction:CMAP:1, IKERule IKERule:CMAP:1Gate1 āĻ āĻāĻžāύā§āϞā§āϰ IPsec āĻĒāϰāĻŋāϏāĻāĻā§āϝāĻžāύā§, āĻāĻŽāĻŋ āĻĻā§āĻāϤ⧠āĻĒāĻžāĻā§āĻāĻŋ āϝ⧠āĻāĻžāύā§āϞāĻāĻŋ āϏāϤā§āϝāĻŋāĻ āĻŦāĻŋāĻĻā§āϝāĻŽāĻžāύ, āĻāĻŋāύā§āϤ⧠Rcvd āĻāĻžāĻāύā§āĻāĻžāϰāĻāĻŋ āĻļā§āύā§āϝ⧠āϰāĻŋāϏā§āĻ āĻāϰāĻž āĻšāϝāĻŧā§āĻā§:
root@Gate1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded
ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 3 (10.10.10.251,500)-(10.10.10.252,500) active 1070 1014
IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 3 (172.16.0.1,*)-(172.17.0.1,*) 47 ESP tunn 480 0āĻāĻŽāĻŋ āĻāĻāĻāĻžāĻŦā§ C-Terra āĻāϰ āϏāĻŽāϏā§āϝāĻžāϰ āϏāĻŽāĻžāϧāĻžāύ āĻāϰāĻŋ: R1 āĻĨā§āĻā§ R2 āϝāĻžāĻāϝāĻŧāĻžāϰ āĻĒāĻĨā§ āϞāĻā§āώā§āϝ āĻĒā§āϝāĻžāĻā§āĻāĻā§āϞāĻŋ āĻā§āĻĨāĻžāϝāĻŧ āĻšāĻžāϰāĻŋāϝāĻŧā§ āĻā§āĻā§ āϤāĻž āĻāĻŽāĻŋ āĻā§āĻāĻāĻāĻŋāĨ¤ āĻĒā§āϰāĻā§āϰāĻŋāϝāĻŧāĻžāϝāĻŧ (āϏā§āĻĒāϝāĻŧāϞāĻžāϰ) āĻāĻŽāĻŋ āĻāĻāĻāĻŋ āϤā§āϰā§āĻāĻŋ āĻā§āĻāĻā§ āĻĒāĻžāĻŦāĨ¤
āϏāĻŽāϏā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ
āϧāĻžāĻĒ 1: R1 āĻĨā§āĻā§ āĻā§āĻ1 āĻā§ āĻĒāĻžāϝāĻŧ
āĻāĻŽāĻŋ āĻŦāĻŋāϞā§āĻ-āĻāύ āĻĒā§āϝāĻžāĻā§āĻ āϏā§āύāĻŋāĻĢāĻžāϰ, tcpdump āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻŋāĨ¤ āĻāĻŽāĻŋ āϏā§āύāĻŋāĻĢāĻžāϰāĻāĻŋ āĻāύā§āĻāĻžāϰāύāĻžāϞ āύā§āĻāĻāϝāĻŧāĻžāϰā§āĻā§ (āϏāĻŋāϏāĻā§āϰ āĻŽāϤ⧠āύā§āĻā§āĻļāύ⧠Gi0/1 āĻ āĻĨāĻŦāĻž āĻāĻāϏ āύā§āĻā§āĻļāύ⧠eth1) āĻāĻžāϞāĻžāĻāĨ¤ Debian) āĻāύā§āĻāĻžāϰāĻĢā§āϏ:
root@Gate1:~# tcpdump -i eth1
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes
14:53:38.879525 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 1, length 64
14:53:39.896869 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 2, length 64
14:53:40.921121 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 3, length 64
14:53:41.944958 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 4, length 64āĻāĻŽāĻŋ āĻĻā§āĻāĻāĻŋ āϝ⧠Gate1 R1 GRE āĻĨā§āĻā§ āĻĒā§āϝāĻžāĻā§āĻāĻā§āϞāĻŋ āĻā§āϰāĻšāĻŖ āĻāϰā§āĨ¤ āĻāĻŽāĻŋ āĻāĻāĻŋāϝāĻŧā§ āϝāĻžāĻāĨ¤
āϧāĻžāĻĒ 2. GRE āĻĒā§āϝāĻžāĻā§āĻā§āϰ āϏāĻžāĻĨā§ Gate1 āĻāĻŋ āĻāϰā§
āĻāĻŽāĻŋ klogview āĻāĻāĻāĻŋāϞāĻŋāĻāĻŋ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻŋ GRE āĻĒā§āϝāĻžāĻā§āĻā§āϰ āĻā§āϤāϰ⧠āĻā§ āĻāĻāĻā§ āϤāĻž āĻĻā§āĻāĻžāϰ āĻāύā§āϝāĨ¤ āĻāĻŋāĻĒāĻŋāĻāύ āĻāϏ-āĻā§āϰāĻž āĻĄā§āϰāĻžāĻāĻāĻžāϰ:
root@Gate1:~# klogview -f 0xffffffff
filtration result for out packet 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0: chain 4 "IPsecPolicy:CMAP", filter 8, event id IPsec:Protect:CMAP:1:LIST, status PASS
encapsulating with SA 31: 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0
passed out packet 10.10.10.251->10.10.10.252, proto 50, len 160, if eth0: encapsulated
āĻāĻŽāĻŋ āĻĻā§āĻāĻāĻŋ āϝ⧠āϞāĻā§āώā§āϝ āĻāĻŋāĻāϰāĻ āĻā§āϰā§āϝāĻžāĻĢāĻŋāĻ (āĻĒā§āϰā§āĻā§ 47) 172.16.0.1 -> 172.17.0.1 CMAP āĻā§āϰāĻŋāĻĒā§āĻā§āĻŽā§āϝāĻžāĻĒā§ āϤāĻžāϞāĻŋāĻāĻž āĻāύāĻā§āϰāĻŋāĻĒāĻļāύ āύāĻŋāϝāĻŧāĻŽā§āϰ āĻ āϧā§āύ⧠āĻĒāĻĄāĻŧā§ (PASS) āĻāĻŦāĻ āĻāύāĻā§āϰāĻŋāĻĒā§āĻ āĻāϰāĻž āĻšāϝāĻŧā§āĻā§ (āĻāύāĻā§āϝāĻžāĻĒāϏā§āϞā§āĻā§āĻĄ)āĨ¤ āĻāϰ āĻĒāϰā§, āĻĒā§āϝāĻžāĻā§āĻāĻāĻŋ āϰāĻžāĻāĻ āĻāϰāĻž āĻšāϝāĻŧā§āĻāĻŋāϞ (āĻĒāĻžāϏ āĻāĻāĻ)āĨ¤ klogview āĻāĻāĻāĻĒā§āĻā§ āĻā§āύ āϰāĻŋāĻāĻžāϰā§āύ āĻā§āϰāĻžāĻĢāĻŋāĻ āύā§āĻ.
Gate1 āĻĄāĻŋāĻāĻžāĻāϏ⧠āĻ ā§āϝāĻžāĻā§āϏā§āϏ āϤāĻžāϞāĻŋāĻāĻž āĻĒāϰā§āĻā§āώāĻž āĻāϰāĻž āĻšāĻā§āĻā§āĨ¤ āĻāĻŽāĻŋ āĻāĻāĻāĻŋ LIST āĻ ā§āϝāĻžāĻā§āϏā§āϏ āϤāĻžāϞāĻŋāĻāĻž āĻĻā§āĻāϤ⧠āĻĒāĻžāĻā§āĻāĻŋ, āϝāĻž āĻāύāĻā§āϰāĻŋāĻĒāĻļāύā§āϰ āĻāύā§āϝ āϞāĻā§āώā§āϝ āĻā§āϰā§āϝāĻžāĻĢāĻŋāĻ āύāĻŋāϰā§āϧāĻžāϰāĻŖ āĻāϰā§, āϝāĻžāϰ āĻ āϰā§āĻĨ āĻšāϞ ME āύāĻŋāϝāĻŧāĻŽāĻā§āϞāĻŋ āĻāύāĻĢāĻŋāĻāĻžāϰ āĻāϰāĻž āύā§āĻ:
Gate1#show access-lists
Extended IP access list LIST
10 permit gre host 172.16.0.1 host 172.17.0.1āĻāĻĒāϏāĻāĻšāĻžāϰ: āϏāĻŽāϏā§āϝāĻžāĻāĻŋ Gate1 āĻĄāĻŋāĻāĻžāĻāϏ⧠āύāϝāĻŧāĨ¤
klogview āϏāĻŽā§āĻĒāϰā§āĻā§ āĻāϰā§
VPN āĻĄā§āϰāĻžāĻāĻāĻžāϰ āϏāĻŽāϏā§āϤ āύā§āĻāĻāϝāĻŧāĻžāϰā§āĻ āĻā§āϰā§āϝāĻžāĻĢāĻŋāĻ āĻĒāϰāĻŋāĻāĻžāϞāύāĻž āĻāϰā§, āĻļā§āϧā§āĻŽāĻžāϤā§āϰ āϝā§āĻā§āϞāĻŋāĻā§ āĻāύāĻā§āϰāĻŋāĻĒā§āĻ āĻāϰāĻž āĻĻāϰāĻāĻžāϰ āϤāĻž āύāϝāĻŧāĨ¤ āĻāĻŋāĻĒāĻŋāĻāύ āĻĄā§āϰāĻžāĻāĻāĻžāϰ āϝāĻĻāĻŋ āύā§āĻāĻāϝāĻŧāĻžāϰā§āĻ āĻā§āϰā§āϝāĻžāĻĢāĻŋāĻ āĻĒā§āϰāĻā§āϰāĻŋāϝāĻŧāĻž āĻāϰ⧠āĻāĻŦāĻ āĻĒā§āϞā§āĻāύ āĻā§āĻā§āϏāĻā§ āĻĒāĻžāĻ āĻžāϝāĻŧ āϤāĻžāĻšāϞ⧠āĻā§āϞā§āĻāĻāĻŋāĻāϤ⧠āĻĻā§āĻāĻž āĻŦāĻžāϰā§āϤāĻžāĻā§āϞāĻŋ āĻāĻāĻžāύ⧠āϰāϝāĻŧā§āĻā§:
root@R1:~# ping 172.17.0.1 -c 4root@Gate1:~# klogview -f 0xffffffff
filtration result for out packet 172.16.0.1->172.17.0.1, proto 1, len 84, if eth0: chain 4 "IPsecPolicy:CMAP": no match
passed out packet 172.16.0.1->172.17.0.1, proto 1, len 84, if eth0: filteredāĻāĻŽāĻŋ āĻĻā§āĻāĻāĻŋ āϝ⧠ICMP āĻā§āϰā§āϝāĻžāĻĢāĻŋāĻ (āĻĒā§āϰā§āĻā§ 1) 172.16.0.1->172.17.0.1 CMAP āĻā§āϰāĻŋāĻĒā§āĻā§āĻŽā§āϝāĻžāĻĒā§āϰ āĻāύāĻā§āϰāĻŋāĻĒāĻļāύ āύāĻŋāϝāĻŧāĻŽā§āϰ āĻŽāϧā§āϝ⧠āĻĒāĻĄāĻŧā§āύāĻŋ (āĻā§āύāĻ āĻŽāĻŋāϞ āύā§āĻ)āĨ¤ āĻĒā§āϝāĻžāĻā§āĻāĻāĻŋ āĻĒāϰāĻŋāώā§āĻāĻžāϰāĻāĻžāĻŦā§ āϰāĻžāĻāĻ āĻāϰāĻž āĻšāϝāĻŧā§āĻāĻŋāϞ (āĻĒāĻžāϏ āĻāĻāĻ)āĨ¤
āϧāĻžāĻĒ 3. āĻā§āĻ2 āĻā§āĻ1 āĻĨā§āĻā§ āĻā§ āĻĒāĻžāϝāĻŧ
āĻāĻŽāĻŋ WAN (eth0) āĻāύā§āĻāĻžāϰāĻĢā§āϏ Gate2 āĻ āϏā§āύāĻŋāĻĢāĻžāϰ āĻļā§āϰ⧠āĻāϰāĻŋ:
root@Gate2:~# tcpdump -i eth0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
16:05:45.104195 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x1), length 140
16:05:46.093918 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x2), length 140
16:05:47.117078 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x3), length 140
16:05:48.141785 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x4), length 140āĻāĻŽāĻŋ āĻĻā§āĻāĻāĻŋ āϝ⧠Gate2 Gate1 āĻĨā§āĻā§ ESP āĻĒā§āϝāĻžāĻā§āĻ āĻĒāĻžāĻā§āĻā§āĨ¤
āϧāĻžāĻĒ 4. ESP āĻĒā§āϝāĻžāĻā§āĻā§āϰ āϏāĻžāĻĨā§ Gate2 āĻāĻŋ āĻāϰā§
āĻāĻŽāĻŋ Gate2 āĻ klogview āĻāĻāĻāĻŋāϞāĻŋāĻāĻŋ āĻāĻžāϞāĻžāĻ:
root@Gate2:~# klogview -f 0xffffffff
filtration result for in packet 10.10.10.251->10.10.10.252, proto 50, len 160, if eth0: chain 17 "FilterChain:L3VPN", filter 21, status DROP
dropped in packet 10.10.10.251->10.10.10.252, proto 50, len 160, if eth0: firewall
āĻāĻŽāĻŋ āĻĻā§āĻāĻāĻŋ āϝ⧠āĻĢāĻžāϝāĻŧāĻžāϰāĻāϝāĻŧāĻžāϞ (āĻĢāĻžāϝāĻŧāĻžāϰāĻāϝāĻŧāĻžāϞ) āĻāϰ āĻāĻāĻāĻŋ āύāĻŋāϝāĻŧāĻŽ (L50VPN) āĻĻā§āĻŦāĻžāϰāĻž ESP āĻĒā§āϝāĻžāĻā§āĻ (āĻĒā§āϰā§āĻā§ 3) āĻĄā§āϰāĻĒ (āĻĄā§āϰāĻĒ) āĻāϰāĻž āĻšāϝāĻŧā§āĻā§āĨ¤ āĻāĻŽāĻŋ āύāĻŋāĻļā§āĻāĻŋāϤ āϝ⧠Gi0 / 0 āϏāϤā§āϝāĻŋāĻ L3VPN āĻ ā§āϝāĻžāĻā§āϏā§āϏ āϤāĻžāϞāĻŋāĻāĻžāϰ āϏāĻžāĻĨā§ āĻāĻŦāĻĻā§āϧ:
Gate2#show ip interface gi0/0
GigabitEthernet0/0 is up, line protocol is up
Internet address is 10.10.10.252/24
MTU is 1500 bytes
Outgoing access list is not set
Inbound access list is L3VPNāϏāĻŽāϏā§āϝāĻž āĻā§āĻāĻā§ āĻĒā§āϝāĻŧā§āĻāĻŋāĨ¤
āϧāĻžāĻĒ 5: āĻ
ā§āϝāĻžāĻā§āϏā§āϏ āϞāĻŋāϏā§āĻā§ āĻā§ āϏāĻŽāϏā§āϝāĻž āĻāĻā§
L3VPN āĻ
ā§āϝāĻžāĻā§āϏā§āϏ āϤāĻžāϞāĻŋāĻāĻžāĻāĻŋ āĻā§ āϤāĻž āĻāĻŽāĻŋ āĻĻā§āĻāĻŋ:
Gate2#show access-list L3VPN
Extended IP access list L3VPN
10 permit udp host 10.10.10.251 any eq isakmp
20 permit udp host 10.10.10.251 any eq non500-isakmp
30 permit icmp host 10.10.10.251 anyāĻāĻŽāĻŋ āĻĻā§āĻāĻāĻŋ āϝ⧠ISAKMP āĻĒā§āϝāĻžāĻā§āĻāĻā§āϞāĻŋ āĻ āύā§āĻŽā§āĻĻāĻŋāϤ, āϤāĻžāĻ āĻāĻāĻāĻŋ IPsec āĻāĻžāύā§āϞ āϏā§āĻĨāĻžāĻĒāύ āĻāϰāĻž āĻšāĻā§āĻā§ā§ˇ āĻāĻŋāύā§āϤ⧠ESP-āĻāϰ āĻāύā§āϝ āĻā§āύ⧠āĻ āύā§āĻŽāϤāĻŋāĻŽā§āϞāĻ āύāĻŋāϝāĻŧāĻŽ āύā§āĻāĨ¤ āϏā§āĻĒāώā§āĻāϤāĻ, āĻāĻžāϤā§āϰāĻāĻŋ icmp āĻāĻŦāĻ esp āĻā§ āĻŦāĻŋāĻā§āϰāĻžāύā§āϤ āĻāϰā§āĻā§āĨ¤
āĻ ā§āϝāĻžāĻā§āϏā§āϏ āϤāĻžāϞāĻŋāĻāĻž āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž:
Gate2(config)#
ip access-list extended L3VPN
no 30
30 permit esp host 10.10.10.251 anyāϧāĻžāĻĒ 6. āĻāĻŽāĻŋ āĻāϰā§āĻŽāĻā§āώāĻŽāϤāĻž āĻĒāϰā§āĻā§āώāĻž
āĻĒā§āϰāĻĨāĻŽāϤ, āĻāĻŽāĻŋ āύāĻŋāĻļā§āĻāĻŋāϤ āĻāϰāĻŋ āϝ⧠L3VPN āĻ ā§āϝāĻžāĻā§āϏā§āϏ āϤāĻžāϞāĻŋāĻāĻž āϏāĻ āĻŋāĻ:
Gate2#show access-list L3VPN
Extended IP access list L3VPN
10 permit udp host 10.10.10.251 any eq isakmp
20 permit udp host 10.10.10.251 any eq non500-isakmp
30 permit esp host 10.10.10.251 anyāĻāĻāύ āĻāĻŽāĻŋ R1 āĻĄāĻŋāĻāĻžāĻāϏ āĻĨā§āĻā§ āϞāĻā§āώā§āϝāϝā§āĻā§āϤ āĻā§āϰāĻžāĻĢāĻŋāĻ āĻāĻžāϞ⧠āĻāϰāĻŋ:
root@R1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=35.3 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=3.01 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=2.65 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=2.87 ms
--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 2.650/10.970/35.338/14.069 msāĻŦāĻŋāĻāϝāĻŧāĨ¤ GRE āĻāĻžāύā§āϞ āϏā§āĻĨāĻžāĻĒāύ āĻāϰāĻž āĻšāϝāĻŧā§āĻā§āĨ¤ IPsec āĻĒāϰāĻŋāϏāĻāĻā§āϝāĻžāύ⧠āĻāύāĻāĻžāĻŽāĻŋāĻ āĻā§āϰāĻžāĻĢāĻŋāĻ āĻāĻžāĻāύā§āĻāĻžāϰ āĻ -āĻļā§āύā§āϝ:
root@Gate1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded
ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 3 (10.10.10.251,500)-(10.10.10.252,500) active 1474 1350
IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 4 (172.16.0.1,*)-(172.17.0.1,*) 47 ESP tunn 1920 480Gate2 āĻā§āĻāĻāϝāĻŧā§āϤā§, klogview āĻāĻāĻāĻĒā§āĻā§, āĻŦāĻžāϰā§āϤāĻžāĻā§āϞāĻŋ āĻāĻĒāϏā§āĻĨāĻŋāϤ āĻšāϝāĻŧā§āĻāĻŋāϞ āϝ⧠āϞāĻā§āώā§āϝ āĻā§āϰāĻžāĻĢāĻŋāĻ 172.16.0.1-> 172.17.0.1 āϏāĻĢāϞāĻāĻžāĻŦā§ (PASS) CMAP āĻā§āϰāĻŋāĻĒā§āĻā§āĻŽā§āϝāĻžāĻĒā§ āϤāĻžāϞāĻŋāĻāĻž āύāĻŋāϝāĻŧāĻŽ āĻĻā§āĻŦāĻžāϰāĻž āĻĄāĻŋāĻā§āϝāĻžāĻĒāϏā§āϞā§āĻ āĻāϰāĻž āĻšāϝāĻŧā§āĻā§:
root@Gate2:~# klogview -f 0xffffffff
filtration result for in packet 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0: chain 18 "IPsecPolicy:CMAP", filter 25, event id IPsec:Protect:CMAP:1:LIST, status PASS
passed in packet 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0: decapsulatedāĻĢāϞāĻžāĻĢāϞ
āĻā§āĻāĻŋāϰ āĻĻāĻŋāύāĻāĻž āύāώā§āĻ āĻāϰ⧠āĻĻāĻŋāϞ āĻāĻžāϤā§āϰāĨ¤
ME āĻāϰ āύāĻŋāϝāĻŧāĻŽā§āϰ āϏāĻžāĻĨā§ āϏāϤāϰā§āĻ āĻĨāĻžāĻā§āύāĨ¤
āĻŦā§āύāĻžāĻŽā§ āĻĒā§āϰāĻā§āĻļāϞā§
t.me/anonymous_engineer
āĻāϤā§āϏ: www.habr.com
