vpn ipsec down hacia router Cisco
Publicado: 08 Oct 2021, 23:26
Buen Dia, tengo un foritgate 1500D que se actualizo de la version 6.0 a la 6.4.5 con todos los saltos respectivos, pero tuna Vpn Ipsec hacia un router cisco quedo Down, volvi a configurar la VPN pero la falla persiste y no se que mas pruebas puedo realizar para restablecer la VPN
Muchas gracias
vpn ipsec downFW1500D # diagnose vpn tunnel list
list all ipsec tunnel in vd 0
------------------------------------------------------
name=VPN_Tosite2 ver=1 serial=1 190.60.250.78:0->45.7.135.230:0 dst_mtu=0
bound_if=25 lgwy=static/1 tun=intf/0 mode=auto/1 encap=none/536 options[0218]=npu create_dev frag-rfc accept_traffic=1 overlay_id=0
proxyid_num=1 child_num=0 refcnt=10 ilast=10 olast=10 ad=/0
stat: rxp=0 txp=0 rxb=0 txb=0
dpd: mode=on-idle on=0 idle=20000ms retry=3 count=0 seqno=0
natt: mode=none draft=0 interval=0 remote_port=0
proxyid=VPN_Tosite2 proto=0 sa=0 ref=1 serial=1
src: 0:0.0.0.0/0.0.0.0:0
dst: 0:0.0.0.0/0.0.0.0:0
FW1500D # diagnose vpn ipsec status
All ipsec crypto devices in use:
NP6_0:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NP6_1:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NPU Host Offloading:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
CP8:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
SOFTWARE:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
FW1500D # diagnose vpn ike log-filter dst-addr4 45.7.135.230
FW1500D # diagnose debug application ike -1
Debug messages will be on for 30 minutes.
FW1500D # diagnose debug enable
FW1500D # ike 0:VPN_Tosite2
out 186F07BE9F46857D00000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=186f07be9f46857d/0000000000000000
ike 0:VPN_Tosite2
negotiation timeout, deleting
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike shrank heap by 159744 bytes
ike 0:VPN_Tosite2
initiator: main mode is sending 1st message...
ike 0:VPN_Tosite2
cookie c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (ident_i1send): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
negotiation timeout, deleting
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike 0:VPN_Tosite2
initiator: main mode is sending 1st message...
ike 0:VPN_Tosite2
cookie e5282139166300c4/0000000000000000
ike 0:VPN_Tosite2
out E5282139166300C400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2FW1500D # diagnose vpn tunnel list
list all ipsec tunnel in vd 0
------------------------------------------------------
name=VPN_Tosite2 ver=1 serial=1 190.60.250.78:0->45.7.135.230:0 dst_mtu=0
bound_if=25 lgwy=static/1 tun=intf/0 mode=auto/1 encap=none/536 options[0218]=npu create_dev frag-rfc accept_traffic=1 overlay_id=0
proxyid_num=1 child_num=0 refcnt=10 ilast=10 olast=10 ad=/0
stat: rxp=0 txp=0 rxb=0 txb=0
dpd: mode=on-idle on=0 idle=20000ms retry=3 count=0 seqno=0
natt: mode=none draft=0 interval=0 remote_port=0
proxyid=VPN_Tosite2 proto=0 sa=0 ref=1 serial=1
src: 0:0.0.0.0/0.0.0.0:0
dst: 0:0.0.0.0/0.0.0.0:0
FW1500D # diagnose vpn ipsec status
All ipsec crypto devices in use:
NP6_0:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NP6_1:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NPU Host Offloading:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
CP8:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
SOFTWARE:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
FW1500D # diagnose vpn ike log-filter dst-addr4 45.7.135.230
FW1500D # diagnose debug application ike -1
Debug messages will be on for 30 minutes.
FW1500D # diagnose debug enable
FW1500D # ike 0:VPN_Tosite2
out 186F07BE9F46857D00000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=186f07be9f46857d/0000000000000000
ike 0:VPN_Tosite2
negotiation timeout, deleting
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike shrank heap by 159744 bytes
ike 0:VPN_Tosite2
initiator: main mode is sending 1st message...
ike 0:VPN_Tosite2
cookie c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (ident_i1send): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
out C670828CDEA9452100000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=c670828cdea94521/0000000000000000
ike 0:VPN_Tosite2
negotiation timeout, deleting
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike 0:VPN_Tosite2
initiator: main mode is sending 1st message...
ike 0:VPN_Tosite2
cookie e5282139166300c4/0000000000000000
ike 0:VPN_Tosite2
out E5282139166300C400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (ident_i1send): 190.60.250.78:500->45.7.135.230:500, len=168, id=e5282139166300c4/0000000000000000
ike 0:VPN_Tosite2
out E5282139166300C400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=e5282139166300c4/0000000000000000
ike 0:VPN_Tosite2
out E5282139166300C400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=e5282139166300c4/0000000000000000
ike 0:VPN_Tosite2
out E5282139166300C400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=e5282139166300c4/0000000000000000
FW1500D # ike 0:VPN_Tosite2
negotiation timeout, deleting
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike 0:VPN_Tosite2
initiator: main mode is sending 1st message...
ike 0:VPN_Tosite2
cookie beb1ccdeac675764/0000000000000000
ike 0:VPN_Tosite2
out BEB1CCDEAC67576400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (ident_i1send): 190.60.250.78:500->45.7.135.230:500, len=168, id=beb1ccdeac675764/0000000000000000
FW1500D #
FW1500D # ike 0:VPN_Tosite2
out BEB1CCDEAC67576400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=beb1ccdeac675764/0000000000000000
iagnose debug
Unknown action 0
FW1500D #
FW1500D # diagnose debug ike 0:VPN_Tosite2
out BEB1CCDEAC67576400000000000000000110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E010080030001800200028004000E0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_Tosite2
sent IKE msg (P1_RETRANSMIT): 190.60.250.78:500->45.7.135.230:500, len=168, id=beb1ccdeac675764/0000000000000000
disable
Muchas gracias
vpn ipsec downFW1500D # diagnose vpn tunnel list
list all ipsec tunnel in vd 0
------------------------------------------------------
name=VPN_Tosite2 ver=1 serial=1 190.60.250.78:0->45.7.135.230:0 dst_mtu=0
bound_if=25 lgwy=static/1 tun=intf/0 mode=auto/1 encap=none/536 options[0218]=npu create_dev frag-rfc accept_traffic=1 overlay_id=0
proxyid_num=1 child_num=0 refcnt=10 ilast=10 olast=10 ad=/0
stat: rxp=0 txp=0 rxb=0 txb=0
dpd: mode=on-idle on=0 idle=20000ms retry=3 count=0 seqno=0
natt: mode=none draft=0 interval=0 remote_port=0
proxyid=VPN_Tosite2 proto=0 sa=0 ref=1 serial=1
src: 0:0.0.0.0/0.0.0.0:0
dst: 0:0.0.0.0/0.0.0.0:0
FW1500D # diagnose vpn ipsec status
All ipsec crypto devices in use:
NP6_0:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NP6_1:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NPU Host Offloading:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
CP8:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
SOFTWARE:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
FW1500D # diagnose vpn ike log-filter dst-addr4 45.7.135.230
FW1500D # diagnose debug application ike -1
Debug messages will be on for 30 minutes.
FW1500D # diagnose debug enable
FW1500D # ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike shrank heap by 159744 bytes
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
list all ipsec tunnel in vd 0
------------------------------------------------------
name=VPN_Tosite2 ver=1 serial=1 190.60.250.78:0->45.7.135.230:0 dst_mtu=0
bound_if=25 lgwy=static/1 tun=intf/0 mode=auto/1 encap=none/536 options[0218]=npu create_dev frag-rfc accept_traffic=1 overlay_id=0
proxyid_num=1 child_num=0 refcnt=10 ilast=10 olast=10 ad=/0
stat: rxp=0 txp=0 rxb=0 txb=0
dpd: mode=on-idle on=0 idle=20000ms retry=3 count=0 seqno=0
natt: mode=none draft=0 interval=0 remote_port=0
proxyid=VPN_Tosite2 proto=0 sa=0 ref=1 serial=1
src: 0:0.0.0.0/0.0.0.0:0
dst: 0:0.0.0.0/0.0.0.0:0
FW1500D # diagnose vpn ipsec status
All ipsec crypto devices in use:
NP6_0:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NP6_1:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
NPU Host Offloading:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
CP8:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
SOFTWARE:
Encryption (encrypted/decrypted)
null : 0 0
des : 0 0
3des : 0 0
aes : 0 0
aes-gcm : 0 0
aria : 0 0
seed : 0 0
chacha20poly1305 : 0 0
Integrity (generated/validated)
null : 0 0
md5 : 0 0
sha1 : 0 0
sha256 : 0 0
sha384 : 0 0
sha512 : 0 0
FW1500D # diagnose vpn ike log-filter dst-addr4 45.7.135.230
FW1500D # diagnose debug application ike -1
Debug messages will be on for 30 minutes.
FW1500D # diagnose debug enable
FW1500D # ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike shrank heap by 159744 bytes
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
FW1500D # ike 0:VPN_Tosite2
ike 0:VPN_Tosite2: connection expiring due to phase1 down
ike 0:VPN_Tosite2: deleting
ike 0:VPN_Tosite2: deleted
ike 0:VPN_Tosite2: schedule auto-negotiate
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
FW1500D #
FW1500D # ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
iagnose debug
Unknown action 0
FW1500D #
FW1500D # diagnose debug ike 0:VPN_Tosite2
ike 0:VPN_Tosite2
disable