<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Проблема с настройкой впн CentOS-Cisco</title>
    <link>https://ssl.opennet.dev/openforum/vsluhforumID1/92206.html</link>
    <description>Привет!&lt;br&gt;Не могу никак понять в чем проблема с поднятием site-to-site впн-а между центос и циской.&lt;br&gt;Конфиги и логи:&lt;br&gt;&lt;br&gt;Со стороны центоса:&lt;br&gt;&#091;root&#064;gate racoon&#093;# uname &amp;#8211;r&lt;br&gt;2.6.18-164.2.my&lt;br&gt;&#091;root&#064;gate racoon&#093;# yum list &amp;#124; grep ipsec&lt;br&gt;ipsec-tools.i386                          0.6.5-14.el5_5.5             installed&lt;br&gt;&lt;br&gt;Сеть &amp;#8211; 192.168.2.0/23&lt;br&gt;Шлюз &amp;#8211; 192.168.2.3&lt;br&gt;Внешний адрес &amp;#8211; 217.217.217.217&lt;br&gt;&lt;br&gt;/etc/sysconfig/network-scripts/ifcfg-ipsec0:&lt;br&gt;&lt;br&gt;&#091;code&#093;DSTGW=172.16.1.1&lt;br&gt;SRCGW=192.168.2.3&lt;br&gt;DSTNET=172.16.1.0/24&lt;br&gt;SRCNET=192.168.2.0/23&lt;br&gt;DST=97.97.97.97&lt;br&gt;TYPE=IPSEC&lt;br&gt;ONBOOT=yes&lt;br&gt;IKE_METHOD=PSK&#091;/code&#093;&lt;br&gt;&lt;br&gt;/etc/sysconfig/network-scripts/key-ipsec0:&lt;br&gt;&lt;br&gt;&#091;code&#093;IKE_PSK=very_secure_key&#091;/code&#093;&lt;br&gt;&lt;br&gt;/etc/raccoon/racoon.conf:&lt;br&gt;&lt;br&gt;&#091;code&#093;path include &quot;/etc/racoon&quot;;&lt;br&gt;path pre_shared_key &quot;/etc/racoon/psk.txt&quot;;&lt;br&gt;path certificate &quot;/etc/racoon/certs&quot;;&lt;br&gt;&lt;br&gt;log debug ;&lt;br&gt;&lt;br&gt;remote anonymous&lt;br&gt;&#123;&lt;br&gt;    exchange_mode main ;&lt;br&gt;    my_identifier address 97.97.97.97 ;&lt;br&gt;    initial_contact on ;&lt;br&gt;    situation identity_only ;&lt;br&gt;    pr</description>

<item>
    <title>Проблема с настройкой впн CentOS-Cisco (Петр)</title>
    <link>https://ssl.opennet.dev/openforum/vsluhforumID1/92206.html#2</link>
    <pubDate>Wed, 08 May 2013 12:19:25 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;         &#125; &lt;br&gt;&amp;gt;  crypto isakmp policy 25 &lt;br&gt;&amp;gt;  authentication pre-share &lt;br&gt;&amp;gt;  encryption 3des &lt;br&gt;&amp;gt;  hash md5 &lt;br&gt;&amp;gt; ------------------- &lt;br&gt;&amp;gt; access-list outside2_2_cryptomap extended permit ip 172.16.1.0 255.255.255.0 &lt;br&gt;&amp;gt; в acl используется не маска 0.0.0.255 &lt;br&gt;&amp;gt; ------------------- &lt;br&gt;&amp;gt; Может поможет &lt;br&gt;&lt;br&gt;это PIX или ASAшка ACL написан правильно,!!!!!!!!!!!!!&lt;br&gt;</description>
</item>

<item>
    <title>Проблема с настройкой впн CentOS-Cisco (sergv)</title>
    <link>https://ssl.opennet.dev/openforum/vsluhforumID1/92206.html#1</link>
    <pubDate>Tue, 06 Sep 2011 06:48:53 GMT</pubDate>
    <description>Я не знаток, но:&lt;br&gt;----------&lt;br&gt;proposal &#123;&lt;br&gt;                encryption_algorithm 3des;&lt;br&gt;                hash_algorithm sha1;&lt;br&gt;                authentication_method pre_shared_key;&lt;br&gt;                dh_group 2;&lt;br&gt;        &#125;&lt;br&gt;&lt;br&gt; crypto isakmp policy 25 &lt;br&gt; authentication pre-share &lt;br&gt; encryption 3des &lt;br&gt; hash md5 &lt;br&gt;-------------------&lt;br&gt;access-list outside2_2_cryptomap extended permit ip 172.16.1.0 255.255.255.0 &lt;br&gt;&lt;br&gt;в acl используется не маска 0.0.0.255&lt;br&gt;&lt;br&gt;-------------------&lt;br&gt;&lt;br&gt;Может поможет&lt;br&gt;</description>
</item>

</channel>
</rss>
