首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >Google发布Cisco ASA密码

Google发布Cisco ASA密码
EN

Server Fault用户
提问于 2019-02-05 14:02:59
回答 1查看 427关注 0票数 0

我正试图在Cisco上建立一个IPSec隧道。在我在google上的路线中,我可以看到只有172.0.99.0/24和172.0.100.0/24应该通过这个隧道路由。

谷歌似乎要求所有通过这条隧道的交通路线

思科日志:

代码语言:javascript
复制
%ASA-7-715047: Group = 35.234.136.243, IP = 35.234.136.243, processing hash payload
%ASA-7-715047: Group = 35.234.136.243, IP = 35.234.136.243, processing SA payload
%ASA-7-715047: Group = 35.234.136.243, IP = 35.234.136.243, processing nonce payload
%ASA-7-715047: Group = 35.234.136.243, IP = 35.234.136.243, processing ke payload
%ASA-7-713906: Group = 35.234.136.243, IP = 35.234.136.243, processing ISA_KE for PFS in phase 2
%ASA-7-715047: Group = 35.234.136.243, IP = 35.234.136.243, processing ID payload
%ASA-7-714011: Group = 35.234.136.243, IP = 35.234.136.243, ID_IPV4_ADDR_SUBNET ID received--0.0.0.0--0.0.0.0
%ASA-7-713035: Group = 35.234.136.243, IP = 35.234.136.243, Received remote IP Proxy Subnet data in ID Payload:   Address 0.0.0.0, Mask 0.0.0.0, Protocol 0, Port 0
%ASA-7-715047: Group = 35.234.136.243, IP = 35.234.136.243, processing ID payload
%ASA-7-714011: Group = 35.234.136.243, IP = 35.234.136.243, ID_IPV4_ADDR_SUBNET ID received--0.0.0.0--0.0.0.0
%ASA-7-713034: Group = 35.234.136.243, IP = 35.234.136.243, Received local IP Proxy Subnet data in ID Payload:   Address 0.0.0.0, Mask 0.0.0.0, Protocol 0, Port 0
%ASA-7-713906: Group = 35.234.136.243, IP = 35.234.136.243, QM IsRekeyed old sa not found by addr
%ASA-7-713221: Group = 35.234.136.243, IP = 35.234.136.243, Static Crypto Map check, checking map = outside_map, seq = 1...
%ASA-7-713222: Group = 35.234.136.243, IP = 35.234.136.243, Static Crypto Map check, map = outside_map, seq = 1, ACL does not match proxy IDs src:0.0.0.0 dst:0.0.0.0
%6.243, processing ID payload
%ASA-7-714011: Group = 35.234.136.243, IP = 35.234.136.243, ID_IPV4_ADDR_SUBNET ID received--0.0.0.0--0.0.0.0

google日志显示连接已经建立,然后Cisco在建立Quickmode时发送一个delete。

EN

回答 1

Server Fault用户

发布于 2019-02-05 21:58:12

您可能在GCP中使用路由隧道,默认情况下它会将0.0.0.0/0作为有趣的通信量或加密域进行宣传。我建议使用基于策略的隧道,并且只在需要时为172.0.99.0/24和172.0.100.0/24做广告。

票数 1
EN
页面原文内容由Server Fault提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://serverfault.com/questions/952393

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档