ISAKMP Policies supported by Win7

本文记录了一次因IKE策略不匹配导致的连接失败案例。详细分析了提出的五个转换中加密算法、密钥长度、散列算法、DH组及认证方式等参数与策略之间的冲突。最终指出仅当使用特定策略时(如最后一个例子所示),配置才被接受。

Sep 15 12:00:36.589: ISAKMP:(0):Checking ISAKMP transform 1 against priority 5 policy
Sep 15 12:00:36.589: ISAKMP:      encryption AES-CBC
Sep 15 12:00:36.589: ISAKMP:      keylength of 256
Sep 15 12:00:36.589: ISAKMP:      hash SHA
Sep 15 12:00:36.589: ISAKMP:      unknown DH group 20
Sep 15 12:00:36.589: ISAKMP:      auth pre-share
Sep 15 12:00:36.589: ISAKMP:      life type in seconds
Sep 15 12:00:36.589: ISAKMP:      life duration (VPI) of  0x0 0x0 0x70 0x80

Sep 15 12:00:36.589: ISAKMP:(0):Diffie-Hellman group offered does not match policy!
Sep 15 12:00:36.589: ISAKMP:(0):atts are not acceptable. Next payload is 3
Sep 15 12:00:36.589: ISAKMP:(0):Checking ISAKMP transform 2 against priority 5 policy
Sep 15 12:00:36.589: ISAKMP:      encryption AES-CBC
Sep 15 12:00:36.589: ISAKMP:      keylength of 128
Sep 15 12:00:36.589: ISAKMP:      hash SHA
Sep 15 12:00:36.589: ISAKMP:      unknown DH group 19
Sep 15 12:00:36.589: ISAKMP:      auth pre-share
Sep 15 12:00:36.589: ISAKMP:      life type in seconds
Sep 15 12:00:36.593: ISAKMP:      life duration (VPI) of  0x0 0x0 0x70 0x80

Sep 15 12:00:36.593: ISAKMP:(0):Proposed key length does not match policy
Sep 15 12:00:36.593: ISAKMP:(0):atts are not acceptable. Next payload is 3
Sep 15 12:00:36.593: ISAKMP:(0):Checking ISAKMP transform 3 against priority 5 policy
Sep 15 12:00:36.593: ISAKMP:      encryption AES-CBC
Sep 15 12:00:36.593: ISAKMP:      keylength of 256
Sep 15 12:00:36.593: ISAKMP:      hash SHA
Sep 15 12:00:36.593: ISAKMP:      unknown DH group 14
Sep 15 12:00:36.593: ISAKMP:      auth pre-share
Sep 15 12:00:36.593: ISAKMP:      life type in seconds
Sep 15 12:00:36.593: ISAKMP:      life duration (VPI) of  0x0 0x0 0x70 0x80

Sep 15 12:00:36.593: ISAKMP:(0):Diffie-Hellman group offered does not match policy!
Sep 15 12:00:36.593: ISAKMP:(0):atts are not acceptable. Next payload is 3
Sep 15 12:00:36.593: ISAKMP:(0):Checking ISAKMP transform 4 against priority 5 policy
Sep 15 12:00:36.593: ISAKMP:      encryption 3DES-CBC
Sep 15 12:00:36.593: ISAKMP:      hash SHA
Sep 15 12:00:36.593: ISAKMP:      unknown DH group 14
Sep 15 12:00:36.593: ISAKMP:      auth pre-share
Sep 15 12:00:36.593: ISAKMP:      life type in seconds
Sep 15 12:00:36.593: ISAKMP:      life duration (VPI) of  0x0 0x0 0x70 0x80

Sep 15 12:00:36.593: ISAKMP:(0):Encryption algorithm offered does not match policy!
Sep 15 12:00:36.593: ISAKMP:(0):atts are not acceptable. Next payload is 3
Sep 15 12:00:36.593: ISAKMP:(0):Checking ISAKMP transform 5 against priority 5 policy
Sep 15 12:00:36.593: ISAKMP:      encryption 3DES-CBC
Sep 15 12:00:36.593: ISAKMP:      hash SHA
Sep 15 12:00:36.593: ISAKMP:      default group 2
Sep 15 12:00:36.593: ISAKMP:      auth pre-share
Sep 15 12:00:36.593: ISAKMP:      life type in seconds
Sep 15 12:00:36.593: ISAKMP:      life duration (VPI) of  0x0 0x0 0x70 0x80

Sep 15 12:00:36.593: ISAKMP:(0):Encryption algorithm offered does not match policy!
Sep 15 12:00:36.593: ISAKMP:(0):atts are not acceptable. Next payload is 0

 

On some platforms of Cisco Routers, only the last policy (green) is acceptable.

Beacuse the IOS only support DH Group 1, 2 and 5.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值