<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Непонятная проблема с классическим ipsec</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/1356.html</link>
    <description>Всем привет, может кто сталкивался.&lt;br&gt;Ситуация следующая: Есть 2821, на ней терминируются порядка 100 ipsec тунелей site-to-site.&lt;br&gt;Все реализовано на crypto map. все прекрасно и все хорошо работает уже не один месяц, но.... в какой то момент все тунели падают в одно время.&lt;br&gt;&lt;br&gt;конфиг касающийся тунелей на 2821:&lt;br&gt;&lt;br&gt;crypto isakmp invalid-spi-recovery&lt;br&gt;crypto isakmp keepalive 20 5 periodic&lt;br&gt;crypto isakmp nat keepalive 10&lt;br&gt;&lt;br&gt;crypto isakmp policy 2&lt;br&gt; encr 3des&lt;br&gt; hash md5&lt;br&gt; authentication pre-share&lt;br&gt; group 2&lt;br&gt;&lt;br&gt;crypto ipsec transform-set 3DES_MD5 esp-3des esp-md5-hmac&lt;br&gt;crypto ipsec transform-set 3DES_SHA esp-3des esp-sha-hmac&lt;br&gt;&lt;br&gt;crypto map Inet 1 ipsec-isakmp&lt;br&gt; description ---&lt;br&gt; set peer A.A.A.A&lt;br&gt; set transform-set 3DES_MD5&lt;br&gt; match address 124&lt;br&gt; reverse-route static&lt;br&gt;&lt;br&gt;interface GigabitEthernet0/1&lt;br&gt; description --- Internet ---&lt;br&gt; ip address B.B.B.B&lt;br&gt; standby version 2&lt;br&gt; standby 2 ip C.C.C.C&lt;br&gt; standby 2 priority 200&lt;br&gt; standby 2 preempt&lt;br&gt; standby 2 name Internet&lt;br&gt; duplex auto&lt;br&gt; speed auto&lt;br&gt; crypto map Inet redundancy I</description>

<item>
    <title>Непонятная проблема с классическим ipsec (vidershpan)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/1356.html#1</link>
    <pubDate>Tue, 27 May 2014 05:04:40 GMT</pubDate>
    <description>debug crypto isa c 870ой железки:&lt;br&gt;&lt;br&gt;*May 27 12:44:11: ISAKMP:(0): SA request profile is (NULL)&lt;br&gt;*May 27 12:44:11: ISAKMP: Found a peer struct for C.C.C.C, peer port 500&lt;br&gt;*May 27 12:44:11: ISAKMP: Locking peer struct 0x83F14820, refcount 3 for isakmp_initiator&lt;br&gt;*May 27 12:44:11: ISAKMP: local port 500, remote port 500&lt;br&gt;*May 27 12:44:11: ISAKMP: set new node 0 to QM_IDLE&lt;br&gt;*May 27 12:44:11: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 8571A10C&lt;br&gt;*May 27 12:44:11: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.&lt;br&gt;*May 27 12:44:11: ISAKMP:(0):found peer pre-shared key matching C.C.C.C&lt;br&gt;*May 27 12:44:11: ISAKMP:(0): constructed NAT-T vendor-rfc3947 ID&lt;br&gt;*May 27 12:44:11: ISAKMP:(0): constructed NAT-T vendor-07 ID&lt;br&gt;*May 27 12:44:11: ISAKMP:(0): constructed NAT-T vendor-03 ID&lt;br&gt;*May 27 12:44:11: ISAKMP:(0): constructed NAT-T vendor-02 ID&lt;br&gt;*May 27 12:44:11: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM&lt;br&gt;*May 27 12:44:11: ISAKMP:(0):Old State = IKE_READY  New State = IKE_I_MM1</description>
</item>

</channel>
</rss>
