Problema VPN IPSEC CON 2 FIREWALL ASA 5505
Inviato: ven 11 lug , 2008 3:21 pm
Salve a tutti!!!!!!!!
Ho un problema con una VPN ipsec tra due sedi.
ogni giorno mi cade la vpn, e ogni volta mi tocca uscire dal programma e collegarmi di nuovo per poter accedere al server.
sul server è installato windows server 2000 sui client ho windows xp o 2000 professional.
la cosa strana quando la vpn cade, riesco a pingare sia il firewall che il router dove si bloccano gli utenti.
ho anche il log degli errori che mi da il firewall quando perde la vpn:
sh log
Syslog logging: enabled
Facility: 20
Timestamp logging: disabled
Standby logging: disabled
Deny Conn when Queue Full: disabled
Console logging: list VPN, 235366 messages logged
Monitor logging: disabled
Buffer logging: list VPN, class vpn, 235366 messages logged
Trap logging: disabled
History logging: disabled
Device ID: disabled
Mail logging: disabled
ASDM logging: level informational, class vpn, 363561 messages logged
D R-U-THERE (seq number 0x5eea10d5)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d5)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=83e4774) wi
th payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE RECEIVED Message (msgid=c155b7fc)
with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing hash payloa
d
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing notify payl
oad
%ASA-7-715075: Group = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of
type DPD R-U-THERE (seq number 0x5eea10d6)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d6)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
% = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of type DPD R-U-THERE
(seq number 0x5eea10da)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10da)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=29b4e40b) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
R-U-THERE (seq number 0x5eea10d7)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d7)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=7839b956) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE RECEIVED Message (msgid=c99b6cf0)
with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing hash payloa
d
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing notify payl
oad
%ASA-7-715075: Group = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of
type DPD R-U-THERE (seq number 0x5eea10d8)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d8)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=461e6ee4) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE RECEIVED Message (msgid=c00b7354)
with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing hash payloa
d
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing notify payl
oad
%ASA-7-715075: Group = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of
type DPD R-U-THERE (seq number 0x5eea10d9)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d9)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=4f880712) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
Ho un problema con una VPN ipsec tra due sedi.
ogni giorno mi cade la vpn, e ogni volta mi tocca uscire dal programma e collegarmi di nuovo per poter accedere al server.
sul server è installato windows server 2000 sui client ho windows xp o 2000 professional.
la cosa strana quando la vpn cade, riesco a pingare sia il firewall che il router dove si bloccano gli utenti.
ho anche il log degli errori che mi da il firewall quando perde la vpn:
sh log
Syslog logging: enabled
Facility: 20
Timestamp logging: disabled
Standby logging: disabled
Deny Conn when Queue Full: disabled
Console logging: list VPN, 235366 messages logged
Monitor logging: disabled
Buffer logging: list VPN, class vpn, 235366 messages logged
Trap logging: disabled
History logging: disabled
Device ID: disabled
Mail logging: disabled
ASDM logging: level informational, class vpn, 363561 messages logged
D R-U-THERE (seq number 0x5eea10d5)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d5)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=83e4774) wi
th payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE RECEIVED Message (msgid=c155b7fc)
with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing hash payloa
d
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing notify payl
oad
%ASA-7-715075: Group = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of
type DPD R-U-THERE (seq number 0x5eea10d6)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d6)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
% = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of type DPD R-U-THERE
(seq number 0x5eea10da)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10da)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=29b4e40b) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
R-U-THERE (seq number 0x5eea10d7)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d7)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=7839b956) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE RECEIVED Message (msgid=c99b6cf0)
with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing hash payloa
d
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing notify payl
oad
%ASA-7-715075: Group = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of
type DPD R-U-THERE (seq number 0x5eea10d8)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d8)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=461e6ee4) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE RECEIVED Message (msgid=c00b7354)
with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing hash payloa
d
%ASA-7-715047: Group = 81.117.204.66, IP = 81.117.204.66, processing notify payl
oad
%ASA-7-715075: Group = 81.117.204.66, IP = 81.117.204.66, Received keep-alive of
type DPD R-U-THERE (seq number 0x5eea10d9)
%ASA-7-715036: Group = 81.117.204.66, IP = 81.117.204.66, Sending keep-alive of
type DPD R-U-THERE-ACK (seq number 0x5eea10d9)
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing blank has
h payload
%ASA-7-715046: Group = 81.117.204.66, IP = 81.117.204.66, constructing qm hash p
ayload
%ASA-7-713236: IP = 81.117.204.66, IKE_DECODE SENDING Message (msgid=4f880712) w
ith payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 80