开发者社区> 问答> 正文

ECS内建 l2tp+ipsec 连接问题

"L2TP-PSK-NAT"[2] 122.96.44.113 #3: responding to Main Mode from unknown peer 122.96.44.113 on port 46212 Jul 21 10:50:53 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: WARNING: connection L2TP-PSK-NAT PSK length of 6 bytes is too short for sha2_256 PRF in FIPS mode (16 bytes required) Jul 21 10:50:53 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: STATE_MAIN_R1: sent MR1, expecting MI2 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: STATE_MAIN_R2: sent MR2, expecting MI3 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: ignoring informational payload IPSEC_INITIAL_CONTACT, msgid=00000000, length=28 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: | ISAKMP Notification Payload Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: | 00 00 00 1c 00 00 00 01 01 10 60 02 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: Peer ID is ID_IPV4_ADDR: '10.55.44.204' Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=PRESHARED_KEY cipher=aes_256 integ=sha2_256 group=MODP2048} Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: the peer proposed: 47.101.64.207/32:17/1701 -> 10.55.44.204/32:17/0 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: NAT-Traversal: received 2 NAT-OA. Using first, ignoring others Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #4: responding to Quick Mode proposal {msgid:51d35df9} Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #4: us: 172.19.129.109<172.19.129.109>:17/1701 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #4: them: 122.96.44.113:17/61613===10.55.44.204/32 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #4: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2 transport mode {ESP/NAT=>0x01864d1a <0x1907e9f8 xfrm=AES_CBC_256-HMAC_SHA1_96 NATOA=10.55.44.204 NATD=122.96.44.113:45221 DPD=active} Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #4: STATE_QUICK_R2: IPsec SA established transport mode {ESP/NAT=>0x01864d1a <0x1907e9f8 xfrm=AES_CBC_256-HMAC_SHA1_96 NATOA=10.55.44.204 NATD=122.96.44.113:45221 DPD=active} Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #3: received Delete SA(0x01864d1a) payload: deleting IPSEC State #4 Jul 21 10:50:54 iZuf68x5n54wbdkm88m2bkZ pluto[18643]: "L2TP-PSK-NAT"[2] 122.96.44.113 #4: deleting other state #4 (STATE_QUICK_R2) and sending notification

展开
收起
游客czqv72sg3uue4 2020-07-21 11:38:28 1863 0
0 条回答
写回答
取消 提交回答
问答排行榜
最热
最新

相关电子书

更多
如何运维千台以上游戏云服务器 立即下载
网站/服务器取证 实践与挑战 立即下载
ECS计算与存储分离架构实践 立即下载