怎樣用DEBUG實(shí)現(xiàn)兩個(gè)路由器之間做LTL的(2)
怎樣用DEBUG實(shí)現(xiàn)兩個(gè)路由器之間做LTL的
next-payload : 8
type : 1
address : 202.102.1.1
protocol : 17
port : 500
length : 12
*Aug 8 20:20:40.423: ISAKMP:(1002):Total payload length: 12
*Aug 8 20:20:40.423: ISAKMP:(1002): sending packet to 202.102.1.2 my_port 500 p
eer_port 500 (I) MM_KEY_EXCH 第五個(gè)包
*Aug 8 20:20:40.423: ISAKMP:(1002):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPL
ETE
*Aug 8 20:20:40.423: ISAKMP:(1002):Old State = IKE_I_MM4 New State = IKE_I_MM5
*Aug 8 20:20:40.463: ISAKMP (0:1002): received packet from 202.102.1.2 dport 50
0 sport 500 Global (I) MM_KEY_EXCH MM_KEY_EXCH 第六個(gè)包
*Aug 8 20:20:40.467: ISA
r1#KMPL1002): processing ID payload. Message ID = 0
*Aug 8 20:20:40.467: ISAKMP (0:1002): ID payload
next-payload : 8
type : 1
address : 202.102.1.2
protocol : 17
port : 500
length : 12
*Aug 8 20:20:40.467: ISAKMPL0):: peer matches *none* of the profiles
*Aug 8 20:20:40.467: ISAKMPL1002): processing HASH payload. Message ID = 0
*Aug 8 20:20:40.467: ISAKMPL1002):SA authentication status:
Authenticated
*Aug 8 20:20:40.467: ISAKMPL1002):SA has been authenticated with 202.102.1.2(最后的結(jié)果認(rèn)證成功,第一階段成功了)
*Aug 8 20:20:40.467: ISAKMP: Trying to insert a peer 202.102.1.1/202.102.1.2/50
0/, and inserted successfully 6637AAAC.
*Aug 8 20:20:40.467: ISAKMP:(1002):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
*Aug 8 20:20:40.467: ISAKMP:(1002):Old State = IKE_I_MM5 New State = IKE_I_MM6
*Aug 8 20:20:40.467: ISAKMP:(1002):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_
MODE
*Aug 8 20:20:40.467: ISAKMP:(1002):Old State = IKE_I_MM6 New State = IKE_I_MM6
r1#*Aug 8 20:20:40.467: ISAKMP:(1002):Input = IKE_MESG_INTERNAL, IKE_PROCESS_CO
MPLETE
*Aug 8 20:20:40.467: ISAKMP:(1002):Old State = IKE_I_MM6 New State = IKE_P1_CO
MPLETE
*Aug 8 20:20:40.467: ISAKMP:(1002):beginning Quick Mode exchange, M-ID of 10935
59871
*Aug 8 20:20:40.467: ISAKMP:(1002):QM Initiator gets spi
*Aug 8 20:20:40.467: ISAKMP:(1002): sending packet to 202.102.1.2 my_port 500 p
eer_port 500 (I) QM_IDLE 發(fā)送第二創(chuàng)段開始的第一個(gè)包;QM代表快速模式
*Aug 8 20:20:40.467: ISAKMP:(1002):Node 1093559871, Input = IKE_MESG_INTERNAL,
IKE_INIT_QM
*Aug 8 20:20:40.467: ISAKMP:(1002):Old State = IKE_QM_READY New State = IKE_QM
_I_QM1
*Aug 8 20:20:40.467: ISAKMP:(1002):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLE
TE
*Aug 8 20:20:40.467: ISAKMP:(1002):Old State = IKE_P1_COMPLETE New State = IKE
_P1_COMPLETE
*Aug 8 20:20:40.511: ISAKMP (0:1002): received packet from 202.102.1.2 dport 50
0 sport 500 Global (I) QM_IDLE 收到對方的回應(yīng)
*Aug 8 20:20:40.519: ISAKMP:(1002): processing HASH payload. message ID = 10935
59871
r1#
*Aug 8 20:20:40.519: ISAKMP:(1002): processing SA payload. message ID = 1093559
871
*Aug 8 20:20:40.523: ISAKMP:(1002):Checking IPSec proposal 1
*Aug 8 20:20:40.523: ISAKMP: transform 1, ESP_DES
*Aug 8 20:20:40.527: ISAKMP: attributes in transform:
*Aug 8 20:20:40.527: ISAKMP: encaps is 1 (Tunnel)
*Aug 8 20:20:40.531: ISAKMP: SA life type in seconds
*Aug 8 20:20:40.531: ISAKMP: SA life duration (basic) of 3600
*Aug 8 20:20:40.531: ISAKMP: SA life type in kilobytes
*Aug 8 20:20:40.535: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0
*Aug 8 20:20:40.539: ISAKMP:(1002):atts are acceptable. 第二階段最終雙方都接受的結(jié)果
*Aug 8 20:20:40.543: ISAKMP:(1002): processing NONCE payload. message ID = 1093
559871
*Aug 8 20:20:40.547: ISAKMP:(1002): processing ID payload. message ID = 1093559
871
*Aug 8 20:20:40.551: ISAKMP:(1002): processing ID payload. message ID = 1093559
871
*Aug 8 20:20:40.551: ISAKMP:(1002): Creating IPSec SAs
*Aug 8 20:20:40.551: inboun
r1#d SA from 202.102.1.2 to 202.102.1.1 (f/i) 0/ 0
(proxy 192.168.20.0 to 192.168.10.0)
*Aug 8 20:20:40.551: has spi 0x866A05BA and conn_id 0 SPI是雙方最終協(xié)商的結(jié)果
*Aug 8 20:20:40.551: lifetime of 3600 seconds
*Aug 8 20:20:40.551: lifetime of 4608000 kilobytes
*Aug 8 20:20:40.551: outbound SA from 202.102.1.1 to 202.102.1.2 (f/i)
0/0
(proxy 192.168.10.0 to 192.168.20.0)
*Aug 8 20:20:40.551: has spi 0x2E48CED3 and conn_id 0
*Aug 8 20:20:40.551: lifetime of 3600 seconds
*Aug 8 20:20:40.551: lifetime of 4608000 kilobytes
*Aug 8 20:20:40.551: ISAKMP:(1002): sending packet to 202.102.1.2 my_port 500 p
eer_port 500 (I) QM_IDLE
*Aug 8 20:20:40.551: ISAKMP:(1002):deleting node 1093559871 error FALSE reason
"No Error"
*Aug 8 20:20:40.551: ISAKMP:(1002):Node 1093559871, Input = IKE_MESG_FROM_PEER,IKE_QM_EXCH
*Aug 8 20:20:40.551: ISAKMP:(1002):Old State = IKE_QM_I_QM1 New State = IKE_QM_PHASE2_COMPLETE
r1#show crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id slot status
202.102.1.2 202.102.1.1 QM_IDLE 1002 0 ACTIVE
IPv6 Crypto ISAKMP SA
r1#
*Aug 8 20:21:30.551: ISAKMP:(1002):purging node 1093559871
r1#