usainbold21
(usa Red Hat)
Enviado em 12/08/2015 - 00:04h
Boa noite,
se alguém puder dar uma dica.
Estou com problema semelhante.
A conexão fecha o tunel mas não navega. Não consigo fazer ping nem telnet.
telnet 170.66.50.50 9023 (não responde)
a topologia é esta
eth0 - 192.168.100.90
eth1 - 192.168.0.5
modem/router - 192.168.0.1
ip real - modem/router - 177.82.171.x
Minhas configurações são estas:
/etc/ipsec.conf
version 2.0
config setup
nat_traversal=yes
virtual_private=%v4:170.66.50.0/24,%v4:192.168.0.0/24,%v4:192.168.100.0/24
oe=off
plutodebug=all
plutostderrlog=/var/log/pluto.log
interfaces=%defaultroute
protostack=netkey
#
conn bb
keyexchange=ike
auth=esp
authby=secret
pfs=yes
auto=start
keyingtries=0
type=tunnel
ike=aes128-sha1;modp1024!
ikelifetime=86400s
phase2alg=aes128-sha1;modp1024
keylife=4608000s
#minharede
left=192.168.0.5
leftid=177.82.171.x
leftsubnet=177.82.171.x/32
#bb
right=170.66.6.31
rightsubnet=170.66.50.0/24
/etc/ipsec.d/bb.secrets
177.82.171.x 170.66.6.31: PSK "teste123"
Status:
[root@lnxfw ~]# /etc/init.d/ipsec status
IPsec running - pluto pid: 3073
pluto pid 3073
1 tunnels up
some eroutes exist
rotas
[root@lnxfw ~]# route
Tabela de Roteamento IP do Kernel
Destino Roteador MáscaraGen. Opções Métrica Ref Uso Iface
192.168.100.0 * 255.255.255.0 U 0 0 0 eth0
172.66.50.0 192.168.0.5 255.255.255.0 UG 0 0 0 eth1
192.168.0.0 * 255.255.255.0 U 0 0 0 eth1
172.16.0.0 * 255.255.0.0 U 0 0 0 eth0
default 192.168.0.1 0.0.0.0 UG 0 0 0 eth1
[root@lnxfw ~]#
um trecho do log:
tail -f /var/log/pluto.log -n200
| route_and_eroute: instance "bb", setting eroute_owner {spd=0x2b24b3b5ff60,sr=0x2b24b3b5ff60} to #2 (was #0) (newest_ipsec_sa=#0)
| encrypting:
| 00 00 00 18 6d f6 68 08 39 8a 6c 1b 2b 13 48 36
| e7 9c 7d f3 e8 b2 cd de
| IV:
| 28 6a ee ce ce 7d c4 9d 68 cf 99 84 d1 1d be ff
| unpadded size is: 24
| emitting 8 zero bytes of encryption padding into ISAKMP Message
| encrypting 32 using OAKLEY_AES_CBC
| NSS do_aes: enter
| NSS do_aes: exit
| next IV: d6 fd bc 09 76 8d 49 25 14 c6 9d 1c c7 16 39 d7
| emitting length of ISAKMP Message: 60
| inR1_outI2: instance bb[0], setting newest_ipsec_sa to #2 (was #0) (spd.eroute=#2)
| complete state transition with STF_OK
"bb" #2: transition from state STATE_QUICK_I1 to state STATE_QUICK_I2
| deleting event for #2
| sending reply packet to 170.66.6.31:500 (from port 500)
| sending 60 bytes for STATE_QUICK_I1 through eth1:500 to 170.66.6.31:500 (using #2)
| a1 69 1f 80 a1 c4 46 48 38 16 20 e4 ff 86 2e e2
| 08 10 20 01 3b 85 bb 11 00 00 00 3c be e8 2a 9d
| a2 2a 74 23 17 ea 2a a2 a3 c0 0f 80 d6 fd bc 09
| 76 8d 49 25 14 c6 9d 1c c7 16 39 d7
| inserting event EVENT_SA_REPLACE, timeout in 85648 seconds for #2
| event added after event EVENT_SA_REPLACE for #1
"bb" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0x336229e6 <0x16fabc2c xfrm=AES_128-HMAC_SHA1 NATOA=none NATD=none DPD=none}
| modecfg pull: noquirk policy:push not-client
| phase 1 is done, looking for phase 2 to unpend
| * processed 1 messages from cryptographic helpers
| next event EVENT_PENDING_DDNS in 59 seconds
| next event EVENT_PENDING_DDNS in 59 seconds
|
| *received whack message
| kernel_alg_esp_enc_ok(12,0): alg_id=12, alg_ivlen=8, alg_minbits=128, alg_maxbits=256, res=0, ret=1
| kernel_alg_esp_auth_keylen(auth=2, sadb_aalg=3): a_keylen=20
| get esp.336229e6@170.66.6.31
| get esp.16fabc2c@192.168.0.5
| * processed 0 messages from cryptographic helpers
| next event EVENT_PENDING_DDNS in 53 seconds
| next event EVENT_PENDING_DDNS in 53 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 60 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added at head of queue
| next event EVENT_PENDING_DDNS in 60 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 0 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added after event EVENT_PENDING_PHASE2
| handling event EVENT_PENDING_PHASE2
| event after this is EVENT_PENDING_DDNS in 60 seconds
| inserting event EVENT_PENDING_PHASE2, timeout in 120 seconds
| event added after event EVENT_PENDING_DDNS
| pending review: connection "bb" checked
| next event EVENT_PENDING_DDNS in 60 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 60 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added at head of queue
| next event EVENT_PENDING_DDNS in 60 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 0 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added after event EVENT_PENDING_PHASE2
| handling event EVENT_PENDING_PHASE2
| event after this is EVENT_PENDING_DDNS in 60 seconds
| inserting event EVENT_PENDING_PHASE2, timeout in 120 seconds
| event added after event EVENT_PENDING_DDNS
| pending review: connection "bb" checked
| next event EVENT_PENDING_DDNS in 60 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 60 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added at head of queue
| next event EVENT_PENDING_DDNS in 60 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 0 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added after event EVENT_PENDING_PHASE2
| handling event EVENT_PENDING_PHASE2
| event after this is EVENT_PENDING_DDNS in 60 seconds
| inserting event EVENT_PENDING_PHASE2, timeout in 120 seconds
| event added after event EVENT_PENDING_DDNS
| pending review: connection "bb" checked
| next event EVENT_PENDING_DDNS in 60 seconds
|
| *received whack message
| kernel_alg_esp_enc_ok(12,0): alg_id=12, alg_ivlen=8, alg_minbits=128, alg_maxbits=256, res=0, ret=1
| kernel_alg_esp_auth_keylen(auth=2, sadb_aalg=3): a_keylen=20
| get esp.336229e6@170.66.6.31
| get esp.16fabc2c@192.168.0.5
| * processed 0 messages from cryptographic helpers
| next event EVENT_PENDING_DDNS in 54 seconds
| next event EVENT_PENDING_DDNS in 54 seconds
|
| next event EVENT_PENDING_DDNS in 0 seconds
| *time to handle event
| handling event EVENT_PENDING_DDNS
| event after this is EVENT_PENDING_PHASE2 in 60 seconds
| inserting event EVENT_PENDING_DDNS, timeout in 60 seconds
| event added at head of queue
| next event EVENT_PENDING_DDNS in 60 seconds
Se alguém puder contribuir, agradeço qualquer ajuda.
Obrigado
Abraço;