>>покажи
>>sh crypto ipsec sa
>>и крестики зачем на серых ИП??
>нашел косяк с pre-shared key
теперь так выглядит:
ROUTER 2
interface: FastEthernet4
Crypto map tag: rtp, local addr 10.0.100.10
protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.64.16/255.255.255.240/0/0)
remote ident (addr/mask/prot/port): (192.168.64.0/255.255.255.240/0/0)
current_peer 10.0.100.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 14, #pkts encrypt: 14, #pkts digest: 14
#pkts decaps: 14, #pkts decrypt: 14, #pkts verify: 14
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0
#pkts not decompressed: 0, #pkts decompress failed: 0
#send errors 35, #recv errors 0
local crypto endpt.: 10.0.100.10, remote crypto endpt.: 10.0.100.2
path mtu 1500, ip mtu 1500
current outbound spi: 0xB20509D3(2986674643)
inbound esp sas:
spi: 0x67087057(1728606295)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
conn id: 2001, flow_id: C87X_MBRD:1, crypto map: rtp
sa timing: remaining key lifetime (k/sec): (4468172/3480)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0xB20509D3(2986674643)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
conn id: 2002, flow_id: C87X_MBRD:2, crypto map: rtp
sa timing: remaining key lifetime (k/sec): (4468172/3480)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
outbound ah sas:
outbound pcp sas:
Router 1
interface: FastEthernet4
Crypto map tag: rtp, local addr 10.0.100.2
protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.64.0/255.255.255.240/0/0)
remote ident (addr/mask/prot/port): (192.168.64.16/255.255.255.240/0/0)
current_peer 10.0.100.10 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 14, #pkts encrypt: 14, #pkts digest: 14
#pkts decaps: 14, #pkts decrypt: 14, #pkts verify: 14
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0
#pkts not decompressed: 0, #pkts decompress failed: 0
#send errors 1, #recv errors 0
local crypto endpt.: 10.0.100.2, remote crypto endpt.: 10.0.100.10
path mtu 1500, ip mtu 1500
current outbound spi: 0x67087057(1728606295)
inbound esp sas:
spi: 0xB20509D3(2986674643)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
conn id: 2001, flow_id: C87X_MBRD:1, crypto map: rtp
sa timing: remaining key lifetime (k/sec): (4598605/3364)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0x67087057(1728606295)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
conn id: 2002, flow_id: C87X_MBRD:2, crypto map: rtp
sa timing: remaining key lifetime (k/sec): (4598605/3364)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
outbound ah sas:
outbound pcp sas:
Но за тонелем из этой сети всё равно никто не пингуется... :(