l2tp vpn增加ipsec相關配置後,ike sa建立正常(狀態RD),但ipsec sa不能建立,報錯:
Reason: An IKE SA deletion message was received from peer.
Reason: Failed to get IPsec policy as phase 2 responder.
Reason: The policy contains incorrect ACL or IKE profile configuration.
Reason: Getting SP by L3 interface: Failed to match SP because SP negotiation not complete.
l2tp vpn用於移動辦公的,客戶端ip地址不固定,是否需要定義security acl?
大佬給個V7火牆的l2tp over ipsec示例,已經試了幾個,但都不成功。
H3C Comware Software, Version 7.1.064, Release 9660P29
Copyright (c) 2004-2022 New H3C Technologies Co., Ltd. All rights reserved.
H3C SecPath F5000-AI-20
(0)
最佳答案
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作
舉報
×
侵犯我的權益
×
侵犯了我企業的權益
×
抄襲了我的內容
×
原文鏈接或出處
誹謗我
×
對根叔社區有害的內容
×
不規範轉載
×
舉報說明
暫無評論