<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Тоннель между Cisco 3845 и Cisco 1841</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html</link>
    <description>Всем здравствуйте.&lt;br&gt;&lt;br&gt;Есть два вышеозначенных роутера, соединённых напрямую патчкордом, на обоих поднят IPSEC и очень нужен GRE-тоннель, вывод комманды #show int tun0:&lt;br&gt;&lt;br&gt;Cisco 1841&lt;br&gt;&lt;br&gt;Tunnel0 is up, line protocol is up&lt;br&gt;  Hardware is Tunnel&lt;br&gt;  Description: ToMainOffice&lt;br&gt;  Internet address is 10.50.2.2/24&lt;br&gt;  MTU 1514 bytes, BW 9 Kbit, DLY 500000 usec,&lt;br&gt;     reliability 255/255, txload 1/255, rxload 1/255&lt;br&gt;  Encapsulation TUNNEL, loopback not set&lt;br&gt;  Keepalive set (10 sec), retries 3&lt;br&gt;  Tunnel source 10.100.2.2, destination 10.100.2.1&lt;br&gt;  Tunnel protocol/transport GRE/IP&lt;br&gt;    Key disabled, sequencing disabled&lt;br&gt;    Checksumming of packets disabled&lt;br&gt;  Tunnel TTL 255&lt;br&gt;  Fast tunneling disabled&lt;br&gt;  Tunnel transmit bandwidth 8000 (kbps)&lt;br&gt;  Tunnel receive bandwidth 8000 (kbps)&lt;br&gt;  Last input 00:00:04, output 00:00:03, output hang never&lt;br&gt;  Last clearing of &quot;show interface&quot; counters never&lt;br&gt;  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 151&lt;br&gt;  Queueing strategy: fifo&lt;br&gt;  Output queue: 0/0 (size/max)&lt;br&gt;</description>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (antacid)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#7</link>
    <pubDate>Wed, 08 Oct 2008 19:17:49 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ip mtu 1400 &lt;br&gt;&amp;gt;&amp;gt;&amp;gt; tunnel source 10.100.2.2 &lt;br&gt;&amp;gt;&amp;gt;&amp;gt; tunnel destination 10.100.2.1 &lt;br&gt;&amp;gt;&amp;gt;&amp;gt; tunnel protection ipsec profile some_profile &lt;br&gt;&amp;gt;&amp;gt;&amp;gt;end &lt;br&gt;&amp;gt;&amp;gt;&lt;br&gt;&amp;gt;&amp;gt;tunnel mode ipsec ipv4 на туннельных интерфейсах &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;сорри на дебаг внимание не обратил. &lt;br&gt;&amp;gt;crypto isakmp key SOMEVERYSECRETKEY address 10.100.2.1 no-xauth &lt;br&gt;&lt;br&gt;Господа, у всех прошу прощения, всё из-за невнимательности, ключ, на втором роутере, прописал на его же интерфейс.&lt;br&gt;Всем огромное спасибо.&lt;br&gt;</description>
</item>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (Eduard_k)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#6</link>
    <pubDate>Wed, 08 Oct 2008 15:06:00 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;&amp;gt;! &lt;br&gt;&amp;gt;&amp;gt;interface Tunnel0 &lt;br&gt;&amp;gt;&amp;gt; ip address 10.50.2.2 255.255.255.252 &lt;br&gt;&amp;gt;&amp;gt; ip mtu 1400 &lt;br&gt;&amp;gt;&amp;gt; tunnel source 10.100.2.2 &lt;br&gt;&amp;gt;&amp;gt; tunnel destination 10.100.2.1 &lt;br&gt;&amp;gt;&amp;gt; tunnel protection ipsec profile some_profile &lt;br&gt;&amp;gt;&amp;gt;end &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;tunnel mode ipsec ipv4 на туннельных интерфейсах &lt;br&gt;&lt;br&gt;сорри на дебаг внимание не обратил.&lt;br&gt;crypto isakmp key SOMEVERYSECRETKEY address 10.100.2.1 no-xauth&lt;br&gt;</description>
</item>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (Eduard_k)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#5</link>
    <pubDate>Wed, 08 Oct 2008 14:58:41 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;crypto ipsec profile some_profile &lt;br&gt;&amp;gt; set transform-set some_set &lt;br&gt;&amp;gt;! &lt;br&gt;&amp;gt;interface Tunnel0 &lt;br&gt;&amp;gt; ip address 10.50.2.2 255.255.255.252 &lt;br&gt;&amp;gt; ip mtu 1400 &lt;br&gt;&amp;gt; tunnel source 10.100.2.2 &lt;br&gt;&amp;gt; tunnel destination 10.100.2.1 &lt;br&gt;&amp;gt; tunnel protection ipsec profile some_profile &lt;br&gt;&amp;gt;end &lt;br&gt;&lt;br&gt;tunnel mode ipsec ipv4 на туннельных интерфейсах&lt;br&gt;</description>
</item>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (max2k1)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#4</link>
    <pubDate>Wed, 08 Oct 2008 09:58:58 GMT</pubDate>
    <description>Пример конфига для организации GRE over IPSEC.&lt;br&gt;&lt;br&gt;Роутер A:&lt;br&gt;&lt;br&gt;crypto isakmp policy 10&lt;br&gt; encr 3des&lt;br&gt; authentication pre-share&lt;br&gt; group 2&lt;br&gt;!&lt;br&gt;crypto isakmp key SOMEVERYSECRETKEY address 10.100.2.2&lt;br&gt;!&lt;br&gt;crypto ipsec transform-set some_set esp-3des esp-sha-hmac&lt;br&gt; mode transport&lt;br&gt;!&lt;br&gt;crypto ipsec profile some_profile&lt;br&gt; set transform-set some_set&lt;br&gt;!&lt;br&gt;interface Tunnel0&lt;br&gt; ip address 10.50.2.1 255.255.255.252&lt;br&gt; ip mtu 1400&lt;br&gt; tunnel source 10.100.2.1&lt;br&gt; tunnel destination 10.100.2.2&lt;br&gt; tunnel protection ipsec profile some_profile&lt;br&gt;end&lt;br&gt;&lt;br&gt;Роутер B:&lt;br&gt;&lt;br&gt;crypto isakmp policy 10&lt;br&gt; encr 3des&lt;br&gt; authentication pre-share&lt;br&gt; group 2&lt;br&gt;!&lt;br&gt;crypto isakmp key SOMEVERYSECRETKEY address 10.100.2.1&lt;br&gt;!&lt;br&gt;crypto ipsec transform-set some_set esp-3des esp-sha-hmac&lt;br&gt; mode transport&lt;br&gt;!&lt;br&gt;crypto ipsec profile some_profile&lt;br&gt; set transform-set some_set&lt;br&gt;!&lt;br&gt;interface Tunnel0&lt;br&gt; ip address 10.50.2.2 255.255.255.252&lt;br&gt; ip mtu 1400&lt;br&gt; tunnel source 10.100.2.2&lt;br&gt; tunnel destination 10.100.2.1&lt;br&gt; tunnel protection ipsec profile some_profile&lt;br&gt;end&lt;br&gt;</description>
</item>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (max2k1)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#3</link>
    <pubDate>Wed, 08 Oct 2008 09:49:52 GMT</pubDate>
    <description>&amp;gt;*Oct  7 07:50:09.643: ISAKMP (0:134217729): ID payload &lt;br&gt;&amp;gt;*Oct  7 07:50:09.643: ISAKMP:(0:1:SW:1):: peer matches *none* of the profiles &lt;br&gt;&amp;gt;*Oct  7 07:50:09.643: ISAKMP:(0:1:SW:1): processing SIG payload. message ID = 0 &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;*Oct  7 07:50:09.643: &#037;CRYPTO-3-IKMP_QUERY_KEY: Querying key pair failed. &lt;br&gt;&amp;gt;*Oct  7 07:50:09.643:  ISAKMP (0:134217729): process_rsa_sig: Querying key pair failed. &lt;br&gt;&amp;gt;Что они от меня хотят? &lt;br&gt;&amp;gt;Спасибо. &lt;br&gt;&lt;br&gt;Либо крипто-карты не совпадают, либо ключи, либо и то и то. &lt;br&gt;</description>
</item>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (antacid)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#2</link>
    <pubDate>Tue, 07 Oct 2008 07:52:40 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;&amp;gt;&lt;br&gt;&amp;gt;&amp;gt;     0 output errors, 0 collisions, 0 interface &lt;br&gt;&amp;gt;&amp;gt;resets &lt;br&gt;&amp;gt;&amp;gt;     0 output buffer failures, 0 output buffers &lt;br&gt;&amp;gt;&amp;gt;swapped out &lt;br&gt;&amp;gt;&amp;gt;&lt;br&gt;&amp;gt;&amp;gt;Почему в случае с 3845 &quot;line protocol is down&quot;? &lt;br&gt;&amp;gt;&amp;gt;Что такое &quot;Fast tunneling enabled/disabled&quot;, и как этой опцией управлять? &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;Проверяйте маршрутизацию. &lt;br&gt;&lt;br&gt;проверил, выяснилось, что не работает ipsec :)&lt;br&gt;перенастроил, всё равно не работает&lt;br&gt;&lt;br&gt;ping router1 -&amp;gt; router2&lt;br&gt;&lt;br&gt;router1#debug crypto isakmp&lt;br&gt;*Oct  7 07:15:58.907: ISAKMP: received ke message (1/1)&lt;br&gt;*Oct  7 07:15:58.907: ISAKMP:(0:0:N/A:0): SA request profile is (NULL)&lt;br&gt;*Oct  7 07:15:58.907: ISAKMP: Created a peer struct for 10.100.2.1, peer port 500&lt;br&gt;*Oct  7 07:15:58.911: ISAKMP: New peer created peer = 0x637F639C peer_handle = 0x80000007&lt;br&gt;*Oct  7 07:15:58.911: ISAKMP: Locking peer struct 0x637F639C, IKE refcount 1 for isakmp_initiator&lt;br&gt;*Oct  7 07:15:58.911: ISAKMP: local port 500, remote port 500&lt;br&gt;*Oct  7 07:15:58.911: ISAKMP: set new node 0 to QM_IDLE&lt;br&gt;*Oct  7 07:15:58.911: insert sa </description>
</item>

<item>
    <title>Тоннель между Cisco 3845 и Cisco 1841 (Pistonov)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID6/17299.html#1</link>
    <pubDate>Fri, 03 Oct 2008 07:46:46 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;0 overrun, 0 ignored, 0 abort &lt;br&gt;&amp;gt;     15172 packets output, 728256 bytes, 0 underruns &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;     0 output errors, 0 collisions, 0 interface &lt;br&gt;&amp;gt;resets &lt;br&gt;&amp;gt;     0 output buffer failures, 0 output buffers &lt;br&gt;&amp;gt;swapped out &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;Почему в случае с 3845 &quot;line protocol is down&quot;? &lt;br&gt;&amp;gt;Что такое &quot;Fast tunneling enabled/disabled&quot;, и как этой опцией управлять? &lt;br&gt;&lt;br&gt;Проверяйте маршрутизацию.&lt;br&gt;&lt;br&gt;</description>
</item>

</channel>
</rss>
