¶øÈç¹ûµ±³öÏÖ״̬ΪMM_SI1_WR1, MM_SA_SETUP¡¢MM_SI2_WR2, MM_VERIFY¡¢MM_SI3_WR3, MM_VERIFYʱºò£¬ËµÃ÷ISAKMP SAÎÞ·¨ÐÉ̳ɹ¦¡£
£¨¶þ£©×éÍøÍØÆË
£¨Èý£©¿ÉÄÜÔÒò
1¡¢Á¬Í¨ÐÔÒì³£
2¡¢³ö½Ó¿Úδµ÷ÓÃvpn¼ÓÃÜͼ
3¡¢×ܲ¿ºÍ·ÖÖ§policy²ßÂÔÅäÖò»Ò»ÖÂ
4¡¢Ô¤¹²ÏíÃÜÔ¿ÅäÖôíÎó
5¡¢FQDNÅäÖôíÎó
6¡¢ÔËÓªÉ̹ýÂË
7¡¢×ܲ¿Îª¶þ¼¶Â·ÓɵÄÇé¿öϳö¿ÚÉ豸ûÓÐÅäÖÃÓ³Éä
8¡¢¶àÏß·»·¾³ÏÂѡ·´íÎó
£¨ËÄ£©´¦Àí²½Öè
²½Öè1¡¢¶Ô±È·ÖÖ§ºÍ×ܲ¿ÅäÖÃ
È·ÈÏÔ¤¹²ÏíÃØÔ¿¡¢µÚÒ»½×ÐÉ̲ÎÊý¡¢µÚ¶þ½×¶ÎÐÉ̲ÎÊý¡¢¸ÐÐËȤÁ÷µÈÊÇ·ñÒ»ÖÂ
a¡¢ÅäÖÃIPsec µÚÒ»½×¶Î
²½Öè2¡¢È·¶¨VPNÊÇ·ñ½¨Á¢³É¹¦
a¡¢Web½çÃæÏÔʾÀ¶É«µÄÇé¿ö»òµã»÷ÏÔʾÒѽÓÈë

b¡¢ÃüÁîÐпÉÒÔͨ¹ýshow crypto state²é¿´VPNµÚÒ»½×¶ÎµÄÇé¿ö
show crypto is sa ²é¿´µÚÒ»½×¶Î½¨Á¢µÄÇé¿ö£¬IDLE״̬±íʾÊǽ¨Á¢Õý³£µÄ״̬

¡¾²¹³ä¡¿
Ò»½×¶Î½¨Á¢²»³É¹¦×´Ì¬ÏÔʾ
1¡¢·ÖÖ§µÄ״̬»úΪMM_SI1_WR1, MM_SA_SETUP£¬¶ø×ܲ¿Ã»ÓÐ״̬»úÐÅÏ¢
µÚÒ»¸ö±¨ÎÄ·¢³ö£¬×ܲ¿Ã»ÓÐÊÕµ½
2¡¢·ÖÖ§µÄ״̬»úΪMM_SI1_WR1, MM_SA_SETUP£¬¶øÇÒ´òÓ¡Send ISAKMP negotiate message failed, errno:148, No route to host syslog
µÚÒ»¸ö±¨ÎÄ·¢³ö£¬µ«ÊÇ·ÓÉѡ·ʧ°Ü£¨¼ì²éÏÂת·¢Â·ÓÉ£©
3¡¢·ÖÖ§ºÍ×ܲ¿µÄ״̬»ú¶¼Îª£ºMM_SI1_WR1, MM_SA_SETUP
¿ÉÒÔͨ¹ýdebug cry is²é¿´£¬ÈôÌáʾno proposal chosen£¬ÐÉ̲ÎÊý²»Ò»Ö£»ÈôÊÇÐèÒªÅäÖÃfqdn£¬ÐèҪʹÓÃÒ°Âùģʽ¶Ô½Ó
4¡¢·ÖÖ§ºÍ×ܲ¿µÄ״̬»ú¶¼Îª£ºMM_SI2_WR2, MM_VERIFY
¿¨ÔÚÈýËı¨ÎĽ»»¥£¬¿ÉÒÔͨ¹ýdebug cry isÐÅÏ¢²é¿´ÈÕÖ¾£¬Ò»°ãÀ´ËµÊDZ¨ÎÄÖØ´«£¬»òÕßʹÓÃÖ¤ÊéÐÉÌ£¬Ö¤Êé°²×°´æÔÚÎÊÌâ
5¡¢·ÖÖ§ºÍ×ܲ¿µÄ״̬»ú¶¼Îª£ºMM_SI3_WR3, MM_VERIFY
Ô¤¹²ÏíÃÜÔ¿²»Ò»Ö£¬Éí·ÝÑé֤ʧ°Ü£¬nat»·¾³³öÏÖ¶ª°ü£¬Í¨¹ýdebug cry is²é¿´ÐÉ̵ÄÇé¿ö£¬ÒÔ¼°É豸ÍâÍø¿Ú×¥°ü¿ÉÒÔ½øÒ»²½²é¿´ÏÂ
²½Öè3¡¢¼ì²é×ܲ¿ºÍ·ÖÖ§ÊÇ·ñÁ¬Í¨ÐÔÒì³£
a¡¢×ܲ¿ºÍ·Ö²¿½¨Á¢VPNÊ×ÏÈÒª±£Ö¤×Ü·Ö²¿µÄ¹«ÍøµØÖ·Á¬Í¨ÐÔÕý³££¬ÈçÏÂͼ£¬¼ÙÉèÏÂͼÁ½Ì¨É豸¶¼Îª³ö¿Ú£¬½Ó¿ÚÉϵÄÅäÖõÄÊǹ«ÍøµØÖ·×ܲ¿³ö¿ÚIP
³ö¿ÚµØÖ·Á¬Í¨ÐÔ²âÊÔ£¬ÃüÁîÐÐÉÏ´ø¶ÔÓ¦½Ó¿ÚµØÖ·ÎªÔ´ping¶Ô¶Ë¹«ÍøµØÖ·£¬ÈçÏÂͼ

b¡¢Èç¹û×Ü·Ö²¿ÁªÍ¨ÐÔ²»Í¨£¬show crypto stateÊÇûÓдòÓ¡ÐÅÏ¢µÄ

²½Öè4¡¢¼ì²éVPNÆ¥Åä¶ÔÓ¦µÄ³ö½Ó¿ÚÏÂÊÇ·ñµ÷ÓÃVPN¼ÓÃÜͼ
a¡¢ÃüÁîÐÐϵ÷ÓüÓÃÜͼµÄÃüÁî

×ܲ¿Èç¹ûûÓе÷ÓüÓÃÜͼµÄÇé¿öÏ£¬×ܲ¿show crypto stateûÓдòÓ¡ÐÅÏ¢£¬·Ö²¿show crypto state¿¨ÔÚµÚÒ»¡¢¶þ±¨ÎĽ»»¥×´Ì¬
·Ö²¿£º
·Ö²¿Ã»Óе÷ÓüÓÃÜͼµÄÇé¿öÏ£¬×Ü·Ö²¿show crypto state¶¼Ã»ÓдòÓ¡ÐÅÏ¢×ܲ¿£º
·Ö²¿£º
²½Öè5¡¢¼ì²é×ܲ¿ºÍ·ÖÖ§policy²ßÂÔÅäÖò»Ò»ÖÂ×Ü·Ö²¿Ö®¼äisa²ßÂÔ²ÎÊýÐèÒªÒ»Ò»¶ÔÓ¦£¬Èç¹û²»Ò»ÑùÊǽ¨Á¢²»ÆðÀ´µÄ£¬¾ßÌåÈçÏÂͼ

·Ö²¿£º

¡¾²¹³ä¡¿
µÚÒ»½×¶ÎÐÉ̲ÎÊý¶ÔÓ¦ÃüÁîÐÐΪshow crypto isa policy
b¡¢Èç¹ûÒòΪµÚÒ»½×¶ÎÐÉ̲ÎÊý²»Ò»Ö£¬µ¼ÖÂshow crypto state¿¨ÔÚµÚÒ»¡¢¶þ±¨ÎĽ»»¥×´Ì¬
Ö÷ģʽÐÉÌʧ°Ü£¬show crypto state·¢ÏÖ·ÖÖ§µÄ״̬»úΪMM_SI1_WR1, MM_SA_SETUP£¬¶ø×ܲ¿Ã»ÓÐ״̬»úÐÅÏ¢
²½Öè6¡¢¼ì²éÔ¤¹²ÏíÃÜÔ¿ÅäÖÃÊÇ·ñ´íÎó
Ô¤¹²ÏíÃÜÔ¿ÅäÖôíÎóµ¼ÖÂIPsecµÚÒ»½×¶ÎÐÉÌÎå¡¢Áù¸ö±¨ÎĽ»»¥²»³É¹¦£¬ÔÚ×Ü·Ö²¿ÉÏͨ¹ýshow crypto state¿´µ½µÄ״̬·Ö±ðΪ
·Ö²¿£º
×ܲ¿£º
¡¾²¹³ä¡¿
11.xµÄÉ豸¿ÉÒԲ鿴µ±Ç°ÅäÖõÄÔ¤¹²ÏíÃÜÔ¿ÊǶàÉÙ£¬Í¨¹ýÃüÁîshow crypto isa key decrypt


²½Öè7¡¢¼ì²éÊÇ·ñQDNÅäÖôíÎó
·Ö²¿ÏÔʾÎåÁù¸ö±¨ÎĽ»»¥×´Ì¬
×ܲ¿ÏÔʾµÚÒ»½×¶Î½¨Á¢Íê³É
×ܲ¿ÅäÖãº
·ÖÖ§FQDN¶ÔÓ¦µÄÃüÁîÐÐÅäÖÃΪ£ºself-identity fqdn EG3000GE
·Ö²¿ÅäÖãº
×ܲ¿FQDNÅäÖÃΪ£º
self-identity fqdn EG3000SE
crypto isakmp key 7 151b5f7246 hostname EG3000GE
crypto map gi0/7 1 ipsec-isakmp
set peer EG3000GE
·Ö²¿ÉϵĶԶËIDÐèÒªºÍ×ܲ¿µÄ±¾»úIDÒ»ÖÂ
²½Öè8¡¢¼ì²éÊÇ·ñÔËÓªÉ̹ýÂË
¿ÉÒÔͨ¹ýshow ip f f | in 500²é¿´¶ÔÓ¦µÄÁ÷±íÐÅÏ¢ÊÇ·ñÓе½EG£¬Èç¹ûûÓУ¬²¢ÇÒÉ豸Éϲ¢Ã»ÓÐip session filterµÄÅäÖýøÐйýÂË£¬¿ÉÒÔ»³ÒÉÔËÓªÉÌÎÊÌâ.

²½Öè9¡¢×ܲ¿Îª¶þ¼¶Â·ÓɵÄÇé¿öϳö¿ÚÉ豸ûÓÐÅäÖÃÓ³Éä
ÍøÂçÍØÆËΪ³ö¿Ú·ÓÉÏÂÁªEGÏÂÁªÄÚÍø£¬EG×÷Ϊ¶þ¼¶Â·ÓÉÅäÖÃIPsec×ܲ¿£¬ÐèÒªÔÚ×ܲ¿³ö¿ÚÅäÖÃÓ³ÉäUDP4500ºÍ500
¶ÔÓ¦web½çÃæÅäÖãº
¶ÔÓ¦ÃüÁîÐÐÅäÖãº
²½Öè10¡¢¶àÏß·»·¾³ÏÂѡ·´íÎó
¿ÉÒÔͨ¹ý²é¿´Á÷±íµÄ³ö½Ó¿ÚÅжÏÊÇ·ñÊÇÀ´»ØÂ·¾¶²»Ò»ÖÂ
½â¾ö¹«º£²Ê´¬¡¤6600¹ÙÍø£º¶àÏß·µÄÇé¿öÏÂÓпÉÄܵ¼ÖÂÀ´»ØÂ·¾¶²»Ò»Ö£¬½¨ÒéÅäÖÃÒ»Ìõ¾²Ì¬Â·ÓÉ£¬Ä¿µÄµØÖ·Ö¸Ïò¶Ô¶Ë¹«ÍøµØÖ·×ß¶ÔÓ¦µÄÏÂÒ»Ìø£¬±£Ö¤À´»ØÂ·¾¶Ò»ÖÂ
¾ßÌåÅäÖÃÈçÏ£º
²é¿´IPSEC±¨ÎÄѡ··½·¨£º
sh ip f m | in FLOW-AUDIT-K ---show³öÀ´ºó£¬²é¿´µÚÒ»ÁеÄÊýÖµ
sh ip f pri ÊýÖµ | in 500

£¨Î壩ÐÅÏ¢ÊÕ¼¯
Èç¹ûÉÏÊö·½·¨½øÐÐÅäÖüì²éºóÒÀ¾ÉÎÞ·¨Õý³£½¨Á¢IPSec VPN£¬¿ÉÒÔÊÕ¼¯ÒÔÏÂÐÅÏ¢Ö®ºó·´À¡ 4008-111-000¹¤³Ìʦ£¬ÐÖúÄú½øÒ»²½ÅŲé¹ÊÕÏ¡£
show version
show int usage
sh tcp connect
sh ip udp
sh memory
sh cpu | ex 0.00
sh exec
show coredump file
show run
show log reverse
show ip interface brief
show ip route
show crypto state £¨ÊÕ¼¯3´Î£¬Ã¿´Î¼ä¸ô5s£©
show ip fpm flow | in 500 £¨ÊÕ¼¯3´Î£¬Ã¿´Î¼ä¸ô5s£©
show ip fpm pri 1 | in 500
show crypto log
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
IPSEC·ÖÖ§ÐÅÏ¢ÊÕ¼¯£º
debug cry isa
debug cry ipsec
terminal monitor
ÊÕ¼¯5·ÖÖÓ×óÓÒ
Undebug all --ÊÕ¼¯ÍêÐèÒª¹Ø±ÕdebugÐÅÏ¢
IPSEC×ܲ¿ÐÅÏ¢ÊÕ¼¯£º£¨ÍƼö×ܲ¿Ö»ÓÐһ·IPSEC¿ÉÒÔ¿ªÆôÊÕ¼¯£¬³¬¹ýһ·ÒÔÉϽ÷É÷¿ªÆôdebug£¬ÒÔÃâÓ°ÏìÒµÎñ£©
debug cry isa
debug cry ipsec
terminal monitor
ÊÕ¼¯5·ÖÖÓ×óÓÒ
Undebug all --ÊÕ¼¯ÍêÐèÒª¹Ø±ÕdebugÐÅÏ¢
£¨Áù£©×ܽáÓ뽨Òé
IKE SA½¨Á¢Ê§°Ü³£¼ûÔÒòÊÇIKEÐÉ̱¨ÎIJ»¿É´ï£¬ºÍIKE SAÁ½¶Ë²ßÂÔ£¨¼ÓÃÜËã·¨¡¢DH×é¡¢Ô¤¹²ÏíÃØÔ¿¡¢Éí·ÝÈÏÖ¤·½·¨£©²»Æ¥Åä
ÈçÓö¸Ã¹ÊÕÏÎÞ·¨¶¨Î»½â¾öµÄ¿Éµã»÷£ºÊÛºóÉÁµçÍà ´¦Àí