> и сделайте вывод команд:
> sho crypto isa sa
> sho crypto ips sa На данный момент у меня ACL и NAT-0 выглядят так:
ASA1:
access-list l2l_list extended permit ip 10.80.225.0 255.255.255.0 10.80.226.0 255.255.255.0
access-list l2l_list extended permit ip 10.80.221.0 255.255.255.0 10.80.222.0 255.255.255.0
object network test1
host 10.80.221.13
object network test2
host 10.80.222.13
nat (servers,internet) source static test1 test1 destination static test2 test2
-----------------------------------
asa1# sho crypto isa sa
IKEv1 SAs:
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 95.168.71.198
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
There are no IKEv2 SAs
-----------------------------------
asa1# sho crypto ips sa
interface: internet
Crypto map tag: abcmap, seq num: 1, local addr: 5.151.38.94
access-list l2l_list extended permit ip 10.80.222.0 255.255.255.0 10.80.221.0 255.255.255.0
local ident (addr/mask/prot/port): (10.80.222.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (10.80.221.0/255.255.255.0/0/0)
current_peer: 95.168.71.198
#pkts encaps: 21774, #pkts encrypt: 21774, #pkts digest: 21774
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 21774, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#send errors: 0, #recv errors: 0
local crypto endpt.: 5.151.38.94/0, remote crypto endpt.: 95.168.71.198/0
path mtu 1500, ipsec overhead 58, media mtu 1500
current outbound spi: 26742134
current inbound spi : BBF90391
inbound esp sas:
spi: 0xBBF90391 (3153658769)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3915000/4863)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
outbound esp sas:
spi: 0x26742134 (645144884)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3914173/4863)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
Crypto map tag: abcmap, seq num: 1, local addr: 5.151.38.94
access-list l2l_list extended permit ip 10.80.226.0 255.255.255.0 10.80.225.0 255.255.255.0
local ident (addr/mask/prot/port): (10.80.226.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (10.80.225.0/255.255.255.0/0/0)
current_peer: 91.198.71.198
#pkts encaps: 2, #pkts encrypt: 2, #pkts digest: 2
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 2, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#send errors: 0, #recv errors: 0
local crypto endpt.: 5.151.38.94/0, remote crypto endpt.: 95.168.71.198/0
path mtu 1500, ipsec overhead 58, media mtu 1500
current outbound spi: 65AC7C89
current inbound spi : F6FABDA8
inbound esp sas:
spi: 0xF6FABDA8 (4143627688)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3915000/27475)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
outbound esp sas:
spi: 0x65AC7C89 (1705802889)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3914999/27474)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
===============================================================================
ASA2:
access-list l2l_list extended permit ip 10.80.226.0 255.255.255.0 10.80.225.0 255.255.255.0
access-list l2l_list extended permit ip 10.80.222.0 255.255.255.0 10.80.221.0 255.255.255.0
object network test1
host 10.80.221.13
object network test2
host 10.80.222.13
nat (servers,internet) source static test2 test2 destination static test1 test1
-----------------------------------
asa2# sho crypto isa sa
IKEv1 SAs:
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 95.168.71.198
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
-----------------------------------
asa2# sho crypto ips sa
interface: internet
Crypto map tag: abcmap, seq num: 1, local addr: 5.151.38.94
access-list l2l_list extended permit ip 10.80.222.0 255.255.255.0 10.80.221.0 255.255.255.0
local ident (addr/mask/prot/port): (10.80.222.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (10.80.221.0/255.255.255.0/0/0)
current_peer: 95.168.71.198
#pkts encaps: 21774, #pkts encrypt: 21774, #pkts digest: 21774
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 21774, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#send errors: 0, #recv errors: 0
local crypto endpt.: 5.151.38.94/0, remote crypto endpt.: 95.168.71.198/0
path mtu 1500, ipsec overhead 58, media mtu 1500
current outbound spi: 26742134
current inbound spi : BBF90391
inbound esp sas:
spi: 0xBBF90391 (3153658769)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3915000/4863)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
outbound esp sas:
spi: 0x26742134 (645144884)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3914173/4863)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
Crypto map tag: abcmap, seq num: 1, local addr: 5.151.38.94
access-list l2l_list extended permit ip 10.80.226.0 255.255.255.0 10.80.225.0 255.255.255.0
local ident (addr/mask/prot/port): (10.80.226.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (10.80.225.0/255.255.255.0/0/0)
current_peer: 95.168.71.198
#pkts encaps: 2, #pkts encrypt: 2, #pkts digest: 2
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 2, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#send errors: 0, #recv errors: 0
local crypto endpt.: 5.151.38.94/0, remote crypto endpt.: 95.168.71.198/0
path mtu 1500, ipsec overhead 58, media mtu 1500
current outbound spi: 65AC7C89
current inbound spi : F6FABDA8
inbound esp sas:
spi: 0xF6FABDA8 (4143627688)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3915000/27475)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
outbound esp sas:
spi: 0x65AC7C89 (1705802889)
transform: esp-des esp-md5-hmac no compression
in use settings ={L2L, Tunnel, }
slot: 0, conn_id: 446464, crypto-map: abcmap
sa timing: remaining key lifetime (kB/sec): (3914999/27474)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001