linux ikev2 端口,ipsec使用的500端口和4500端口可以似乎被封杀了?

从几周前开始突然连不上了,ipsec start --nofork 前台运行打印的日志显示

15[NET] received packet: from 116.253.84.217[500] to 162.243.153.127[500] (604 bytes)

15[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]

15[IKE] 116.253.84.217 is initiating an IKE_SA

15[IKE] remote host is behind NAT

15[IKE] sending cert request for "C=CN, O=TrustAsia Technologies, Inc., OU=Domain Validated SSL, CN=TrustAsia TLS RSA CA G8"

15[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(FRAG_SUP) N(MULT_AUTH) ]

15[NET] sending packet: from 162.243.153.127[500] to 116.253.84.217[500] (473 bytes)

16[NET] received packet: from 116.253.84.217[500] to 162.243.153.127[500] (604 bytes)

16[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]

16[IKE] received retransmit of request with ID 0, retransmitting response

16[NET] sending packet: from 162.243.153.127[500] to 116.253.84.217[500] (473 bytes)

12[NET] received packet: from 116.253.84.217[500] to 162.243.153.127[500] (604 bytes)

12[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]

12[IKE] received retransmit of request with ID 0, retransmitting response

12[NET] sending packet: from 162.243.153.127[500] to 116.253.84.217[500] (473 bytes)

15[JOB] deleting half open IKE_SA after timeout

似乎是握手超时?各种客户端都试了,差不多都这样。

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值