<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: проблема создания IPSEC тунеля</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html</link>
    <description>сетка 10.0.1.0/24 внешний ip 192.168.1.1&lt;br&gt;сетка 10.0.2.0/24 внешний ip 192.168.2.1&lt;br&gt;&lt;br&gt;на стороне 192.168.1.1 стоит cisco 2811, на стороне 192.168.2.1 стоит openbsd.&lt;br&gt;ipsec vpn канал устанавливается.&lt;br&gt;traceroute с компа 10.0.1.17&lt;br&gt;traceroute to 10.1.6.17 (10.1.6.17), 30 hops max, 40 byte packets using UDP&lt;br&gt; 1  10.0.1.1 (10.0.1.1)  0.854 ms   0.862 ms   1.965 ms&lt;br&gt; 2  192.168.2.1 (192.168.2.1)  2.402 ms   6.567 ms   9.843 ms&lt;br&gt; 3  10.0.2.17 (10.0.2.17)  12.256 ms   8.601 ms   6.955 ms&lt;br&gt;traceroute с компа 10.0.2.17&lt;br&gt;traceroute to 10.1.6.17 (10.1.6.17), 30 hops max, 40 byte packets using UDP&lt;br&gt; 1  10.0.1.1 (10.0.1.1)  0.854 ms   0.862 ms   1.965 ms&lt;br&gt; 2  * * *&lt;br&gt; 3  * * *&lt;br&gt;причем&lt;br&gt;PING 10.0.1.17 (10.0.1.17): 56 data bytes&lt;br&gt;64 bytes from 192.168.1.1: icmp_seq=0 ttl=63 time=3.034 ms&lt;br&gt;64 bytes from 192.168.1.1: icmp_seq=1 ttl=63 time=1.690 ms&lt;br&gt;64 bytes from 192.168.1.1: icmp_seq=2 ttl=63 time=1.994 ms&lt;br&gt;&lt;br&gt;&lt;br&gt;помогите понять причину такой ерести.&lt;br&gt;&lt;br&gt;&lt;br&gt;конфиг cisco:&lt;br&gt;!&lt;br&gt;crypto isakmp policy 15&lt;br&gt; encr aes&lt;br&gt; authentication pre</description>

<item>
    <title>проблема создания IPSEC тунеля (ss2707)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#7</link>
    <pubDate>Wed, 07 Jul 2010 12:00:44 GMT</pubDate>
    <description>всем спасибо. :)&lt;br&gt;&lt;br&gt;изменения&lt;br&gt;&lt;br&gt;ip route 10.0.2.0 255.255.255.0 192.168.2.1&lt;br&gt;&lt;br&gt;ip nat inside source list 110 interface FastEthernet0/1 overload&lt;br&gt;access-list 110 deny ip 10.0.1.0 0.0.0.255 10.0.2.0 0.0.0.255&lt;br&gt;access-list 110 permit ip 10.0.1.0 0.0.0.255 any&lt;br&gt;</description>
</item>

<item>
    <title>проблема создания IPSEC тунеля (karen durinyan)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#6</link>
    <pubDate>Wed, 07 Jul 2010 11:40:17 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 &lt;br&gt;&amp;gt;#pkts decaps: 368, #pkts decrypt: 368, #pkts verify: 368&quot; &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;strochek vidno chto u vas tol&apos;ko decaps paket&#064;, to est&apos; pakiti vixodyat &lt;br&gt;&amp;gt;is ipsec tunelja, no tuda ne vxodjat. &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;u menja 2 predlozhenie. &lt;br&gt;&amp;gt;1. kak skazal na vremja udalite access-group iz tun interfeisax. &lt;br&gt;&amp;gt;2. postavte /30 network na tun interfeisax (eto pomozhet uvidet tun ip &lt;br&gt;&amp;gt;v traceroute a ne peer ip, cto delajet legche trablesuting.) &lt;br&gt;&lt;br&gt;esho zametil...&lt;br&gt;peremestite &quot;crypto map MSK-TEST&quot; iz tun6 k  FastEthernet0/1&lt;br&gt;</description>
</item>

<item>
    <title>проблема создания IPSEC тунеля (karen durinyan)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#5</link>
    <pubDate>Wed, 07 Jul 2010 11:15:38 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;lifetime (k/sec): (4501043/203) &lt;br&gt;&amp;gt;        IV size: 16 bytes &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;        replay detection support: Y &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;        Status: ACTIVE &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;     outbound ah sas: &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;     outbound pcp sas: &lt;br&gt;&lt;br&gt;jasno. no iz&lt;br&gt;#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 &lt;br&gt;#pkts decaps: 368, #pkts decrypt: 368, #pkts verify: 368&quot;&lt;br&gt;&lt;br&gt;strochek vidno chto u vas tol&apos;ko decaps paket&#064;, to est&apos; pakiti vixodyat is ipsec tunelja, no tuda ne vxodjat.&lt;br&gt;&lt;br&gt;u menja 2 predlozhenie.&lt;br&gt;1. kak skazal na vremja udalite access-group iz tun interfeisax.&lt;br&gt;2. postavte /30 network na tun interfeisax (eto pomozhet uvidet tun ip v traceroute a ne peer ip, cto delajet legche trablesuting.)&lt;br&gt;&lt;br&gt;&lt;br&gt;</description>
</item>

<item>
    <title>проблема создания IPSEC тунеля (ss2707)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#4</link>
    <pubDate>Wed, 07 Jul 2010 10:04:09 GMT</pubDate>
    <description>&amp;gt;&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;3. 10.1.6.17 ne popodaet v MSK-TEST ACL &lt;br&gt;&lt;br&gt;я тормознул. :( должно быть так:&lt;br&gt;&lt;br&gt;traceroute с компа 10.0.1.17&lt;br&gt;traceroute to 10.0.2.17 (10.0.2.17), 30 hops max, 40 byte packets using UDP&lt;br&gt;1  10.0.1.1 (10.0.1.1)  0.854 ms   0.862 ms   1.965 ms&lt;br&gt;2  192.168.2.1 (192.168.2.1)  2.402 ms   6.567 ms   9.843 ms&lt;br&gt;3  10.0.2.17 (10.0.2.17)  12.256 ms   8.601 ms   6.955 ms&lt;br&gt;traceroute с компа 10.0.2.17&lt;br&gt;traceroute to 10.0.1.17 (10.0.1.17), 30 hops max, 40 byte packets using UDP&lt;br&gt;1  10.0.1.1 (10.0.1.1)  0.854 ms   0.862 ms   1.965 ms&lt;br&gt;2  * * *&lt;br&gt;3  * * *&lt;br&gt;</description>
</item>

<item>
    <title>проблема создания IPSEC тунеля (ss2707)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#3</link>
    <pubDate>Wed, 07 Jul 2010 09:55:07 GMT</pubDate>
    <description>&amp;gt;&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;1. iz vashego traceroute ja ne vizhu chto ipsec tunnel ustanovlen tak &lt;br&gt;&amp;gt;kak ja vizhu tam peer address chto v principe ne dolzhen &lt;br&gt;&amp;gt;bit tam. &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;2. esli vse taki ja ne prav na schet 1. :) uberite &lt;br&gt;&amp;gt;&quot;ip access-group INET in&quot; iz tun6 interfeisa na vremja dlja testa. &lt;br&gt;&lt;br&gt;interface: Tunnel6&lt;br&gt;    Crypto map tag: MSK-TEST, local addr 192.168.1.1&lt;br&gt;   protected vrf: (none)&lt;br&gt;   local  ident (addr/mask/prot/port): (10.0.1.0/255.255.255.0/0/0)&lt;br&gt;   remote ident (addr/mask/prot/port): (10.0.2.0/255.255.255.0/0/0)&lt;br&gt;   current_peer 192.168.2.1 port 500&lt;br&gt;     PERMIT, flags=&#123;origin_is_acl,&#125;&lt;br&gt;    #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0&lt;br&gt;    #pkts decaps: 368, #pkts decrypt: 368, #pkts verify: 368&lt;br&gt;    #pkts compressed: 0, #pkts decompressed: 0&lt;br&gt;    #pkts not compressed: 0, #pkts compr. failed: 0&lt;br&gt;    #pkts not decompressed: 0, #pkts decompress failed: 0&lt;br&gt;    #send errors 0, #recv errors 0&lt;br&gt;&lt;br&gt;     local crypto endpt.: 192.168.1.1, remote crypto endpt.: 192.168.2.1&lt;br&gt;     path mtu 1476, ip m</description>
</item>

<item>
    <title>проблема создания IPSEC тунеля (karen durinyan)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#2</link>
    <pubDate>Wed, 07 Jul 2010 09:36:18 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;1. iz vashego traceroute ja ne vizhu chto ipsec tunnel ustanovlen tak &lt;br&gt;&amp;gt;kak ja vizhu tam peer address chto v principe ne dolzhen &lt;br&gt;&amp;gt;bit tam. &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;2. esli vse taki ja ne prav na schet 1. :) uberite &lt;br&gt;&amp;gt;&quot;ip access-group INET in&quot; iz tun6 interfeisa na vremja dlja testa. &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;udachi &lt;br&gt;&lt;br&gt;3. 10.1.6.17 ne popodaet v MSK-TEST ACL &lt;br&gt;&lt;br&gt;</description>
</item>

<item>
    <title>проблема создания IPSEC тунеля (karen durinyan)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/21273.html#1</link>
    <pubDate>Wed, 07 Jul 2010 09:28:30 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;ip access-list extended LAN_INTERFACE &lt;br&gt;&amp;gt; permit ip 10.0.1.0 0.0.0.255 10.0.2.0 0.0.0.255 &lt;br&gt;&amp;gt; permit ip 10.0.1.0 0.0.0.255 host 192.168.2.1 &lt;br&gt;&amp;gt;! &lt;br&gt;&amp;gt;ip access-list extended WAN_INTERFACE &lt;br&gt;&amp;gt; permit ip 192.168.2.1 host 192.168.1.1 &lt;br&gt;&amp;gt; permit esp 192.168.2.1 host 192.168.1.1 &lt;br&gt;&amp;gt; permit gre 192.168.2.1 host 192.168.1.1 &lt;br&gt;&amp;gt;! &lt;br&gt;&amp;gt;ip route 10.0.2.0 255.255.255.0 Tunnel6 &lt;br&gt;&lt;br&gt;privet.&lt;br&gt;&lt;br&gt;1. iz vashego traceroute ja ne vizhu chto ipsec tunnel ustanovlen tak kak ja vizhu tam peer address chto v principe ne dolzhen bit tam.&lt;br&gt;&lt;br&gt;2. esli vse taki ja ne prav na schet 1. :) uberite &quot;ip access-group INET in&quot; iz tun6 interfeisa na vremja dlja testa.&lt;br&gt;&lt;br&gt;udachi&lt;br&gt;</description>
</item>

</channel>
</rss>
