In diesem Dokument wird beschrieben, wie Cisco IOS®-Router so konfiguriert werden, dass sie die Zertifizierungsstellen für mehrere Identitäten unterstützen. In einigen Situationen, z. B. bei einem gemeinsamen Projekt zwischen zwei Unternehmen oder zwei Geschäftseinheiten, müssen die Router auf beiden Seiten (die sich bei verschiedenen CAs anmelden, die keine Vertrauensbeziehung haben) über IPSec VPNs kommunizieren. Der Edge-Router muss möglicherweise über zwei Identitätszertifikatgruppen verfügen, um mit Routern auf beiden CA-Domänen zu kommunizieren. In diesem Dokument wird erläutert, wie Sie einen Cisco Router für verschiedene CA-Server registrieren, um mehrere Identitätszertifikate zu erhalten. Die Überprüfung erfolgt anhand eines einfachen Beispiels.
Diese Funktion wurde in der Cisco IOS® Software, Version 12.2(2)T, eingeführt. Ältere Versionen der Software können die in diesem Dokument angegebene Konfiguration nicht verwenden.
Die Informationen in diesem Dokument basieren auf den folgenden Software- und Hardwareversionen:
Cisco 7200 Router mit Cisco IOS Software, Version 12.2(4)T1
Microsoft CA-Server auf Windows 2000-Server
Vertraut CA-Server auf Windows NT-Server
Die Informationen in diesem Dokument wurden von den Geräten in einer bestimmten Laborumgebung erstellt. Alle in diesem Dokument verwendeten Geräte haben mit einer leeren (Standard-)Konfiguration begonnen. Wenn Ihr Netzwerk in Betrieb ist, stellen Sie sicher, dass Sie die potenziellen Auswirkungen eines Befehls verstehen.
Weitere Informationen zu Dokumentkonventionen finden Sie unter Cisco Technical Tips Conventions.
Im unten abgebildeten Diagramm sind SJhub, SJVPN und SJPKI drei Cisco 7200-Router, die mit dem Backbone-Netzwerk verbunden sind. Der SJhub ist der Hub-Router mit mehreren Identitätszertifikaten der CA-Server von Entrust und der Microsoft CA, die sich im Backbone-Netzwerk befinden. SJVPN meldet sich beim Entrust CA-Server an, und SJPKI meldet sich beim Microsoft CA-Server an.
In diesem Abschnitt erhalten Sie Informationen zum Konfigurieren der in diesem Dokument beschriebenen Funktionen.
Hinweis: Um weitere Informationen zu den in diesem Dokument verwendeten Befehlen zu erhalten, verwenden Sie das Command Lookup Tool (nur registrierte Kunden).
Hinweis: Einige der im folgenden Verfahren gezeigten Ausgaben wurden aus Platzhaltergründen in mehrere Zeilen eingeschlossen.
Generieren Sie RSA-Schlüssel auf dem Router.
SJhub#configure terminal Enter configuration commands, one per line. End with CNTL/Z. SJhub(config)#ip domain-name sjtac.com SJhub(config)#crypto key generate rsa The name for the keys will be: SJhub.sjtac.com Choose the size of the key modulus in the range of 360 to 2048 for your General Purpose Keys. Choosing a key modulus greater than 512 may take a few minutes. How many bits in the modulus [512]: Generating RSA keys ... [OK]
Definieren Sie die erste Crypto CA-Identität auf dem Router. Der hier verwendete Server ist ein Entrust CA-Server.
SJhub(config)#crypto ca identity EntrustPKI SJhub(ca-identity)#enrollment url http://171.69.89.16 SJhub(ca-identity)#enrollment mode ra SJhub(ca-identity)#query url ldap://171.69.89.16 SJhub(ca-identity)#exit
Rufen Sie die CA- und die RA-Zertifikate ab, und registrieren Sie den Router bei der Entrust CA.
SJhub(config)#crypto ca authenticate EntrustPKI Certificate has the following attributes: Fingerprint: 1FCDF2C8 2DEDA6AC 4819D4C4 B4CFF2F5 % Do you accept this certificate? [yes/no]: y SJhub(config)#crypto ca enroll EntrustPKI % % Start certificate enrollment .. % Create a challenge password. You will need to verbally provide this password to the CA Administrator in order to revoke your certificate. For security reasons your password will not be saved in the configuration. Please make a note of it. Password: Re-enter password: % The subject name in the certificate will be: SJhub.sjtac.com % Include the router serial number in the subject name? [yes/no]: n % Include an IP address in the subject name? [yes/no]: n Request certificate from CA? [yes/no]: y % Certificate request sent to Certificate Authority % The certificate request fingerprint will be displayed. % The 'show crypto ca certificate' command will also show the fingerprint. SJhub(config)# Fingerprint: B530BB30 70D2C565 E6F20A88 BB86A75A
Überprüfen Sie die Zertifikate.
SJhub#show crypto ca certificates Certificate Status: Available Certificate Serial Number: 3B2FD63F Key Usage: General Purpose Issuer: OU = sjvpn O = cisco C = us Subject Name Contains: Name: SJhub.sjtac.com CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 21:48:52 UTC Jan 9 2002 end date: 22:18:52 UTC Jan 9 2003 Associated Identity: EntrustPKI RA Signature Certificate Status: Available Certificate Serial Number: 3B2FD319 Key Usage: Signature Issuer: OU = sjvpn O = cisco C = us Subject: CN = First Officer OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:03:31 UTC Jun 19 2001 end date: 22:33:31 UTC Jun 19 2004 Associated Identity: EntrustPKI RA KeyEncipher Certificate Status: Available Certificate Serial Number: 3B2FD318 Key Usage: Encryption Issuer: OU = sjvpn O = cisco C = us Subject: CN = First Officer OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:03:31 UTC Jun 19 2001 end date: 22:33:31 UTC Jun 19 2004 Associated Identity: EntrustPKI CA Certificate Status: Available Certificate Serial Number: 3B2FD307 Key Usage: General Purpose Issuer: OU = sjvpn O = cisco C = us Subject: OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:02:40 UTC Jun 19 2001 end date: 22:32:40 UTC Jun 19 2021 Associated Identity: EntrustPKI
Definieren Sie die Crypto CA-Identität der zweiten CA auf dem Router. Hier wird ein Microsoft CA-Server verwendet.
SJhub(config)#crypto ca identity MicrosoftCA SJhub(ca-identity)#enrollment url http://171.69.89.182:80/certsrv/mscep/mscep.$ SJhub(ca-identity)#enrollment mode ra SJhub(ca-identity)#query url ldap://171.69.89.182 SJhub(ca-identity)#exit
Sichern Sie sich die CA- und RA-Zertifikate vom Microsoft CA-Server.
SJhub(config)#crypto ca authenticate MicrosoftCA Certificate has the following attributes: Fingerprint: 5FC47E85 9A2724A2 7242F172 BFB87F7E % Do you accept this certificate? [yes/no]: y
Melden Sie sich beim Microsoft CA-Server an, und erhalten Sie das Identitätszertifikat des Routers.
SJhub(config)#crypto ca enroll MicrosoftCA % % Start certificate enrollment .. % Create a challenge password. You will need to verbally provide this password to the CA Administrator in order to revoke your certificate. For security reasons your password will not be saved in the configuration. Please make a note of it. Password: Re-enter password: % The subject name in the certificate will be: SJhub.sjtac.com % Include the router serial number in the subject name? [yes/no]: n % Include an IP address in the subject name? [yes/no]: n Request certificate from CA? [yes/no]: y % Certificate request sent to Certificate Authority % The certificate request fingerprint will be displayed. % The 'show crypto ca certificate' command will also show the fingerprint. SJhub(config)# Fingerprint: 4046052F 2D32A725 235D55E9 694DF3EA
Überprüfen Sie die Zertifikate. Es sollten zwei Zertifikatssätze angezeigt werden.
SJhub#show crypto ca certificates Certificate Status: Available Certificate Serial Number: 132BD14C00000000000B Key Usage: General Purpose Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject Name Contains: Name: SJhub.sjtac.com CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services, CN=Configuration,DC=sjpki, DC=com?certificateRevocationList?base? objectclass=cRLDistributionPoint Validity Date: start date: 18:36:23 UTC Jan 13 2002 end date: 18:36:23 UTC Jan 13 2004 Associated Identity: MicrosoftCA RA Signature Certificate Status: Available Certificate Serial Number: 054E60AD000000000002 Key Usage: Signature Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject: CN = SJVPNRA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki, DC=com?certificateRevocationList?base? objectclass=cRLDistributionPoint Validity Date: start date: 01:59:27 UTC Jan 11 2002 end date: 01:59:27 UTC Jan 11 2004 Associated Identity: MicrosoftCA RA KeyEncipher Certificate Status: Available Certificate Serial Number: 054E63CE000000000003 Key Usage: Encryption Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject: CN = SJVPNRA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki, DC=com?certificateRevocationList?base? objectclass=cRLDistributionPoint Validity Date: start date: 01:59:28 UTC Jan 11 2002 end date: 01:59:28 UTC Jan 11 2004 Associated Identity: MicrosoftCA CA Certificate Status: Available Certificate Serial Number: 091B47AEE8CFE2A94D3E8B38F292F5AF Key Usage: General Purpose Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki, DC=com?certificateRevocationList?base? objectclass=cRLDistributionPoint Validity Date: start date: 01:51:39 UTC Jan 11 2002 end date: 02:00:04 UTC Jan 11 2007 Associated Identity: MicrosoftCA CA Certificate Status: Available Certificate Serial Number: 3B2FD307 Key Usage: General Purpose Issuer: OU = sjvpn O = cisco C = us Subject: OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:02:40 UTC Jun 19 2001 end date: 22:32:40 UTC Jun 19 2021 Associated Identity: EntrustPKI RA KeyEncipher Certificate Status: Available Certificate Serial Number: 3B2FD318 Key Usage: Encryption Issuer: OU = sjvpn O = cisco C = us Subject: CN = First Officer OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:03:31 UTC Jun 19 2001 end date: 22:33:31 UTC Jun 19 2004 Associated Identity: EntrustPKI RA Signature Certificate Status: Available Certificate Serial Number: 3B2FD319 Key Usage: Signature Issuer: OU = sjvpn O = cisco C = us Subject: CN = First Officer OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:03:31 UTC Jun 19 2001 end date: 22:33:31 UTC Jun 19 2004 Associated Identity: EntrustPKI Certificate Status: Available Certificate Serial Number: 3B2FD63F Key Usage: General Purpose Issuer: OU = sjvpn O = cisco C = us Subject Name Contains: Name: SJhub.sjtac.com CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 21:48:52 UTC Jan 9 2002 end date: 22:18:52 UTC Jan 9 2003 Associated Identity: EntrustPKI
In diesem Abschnitt wird anhand einer einfachen Konfiguration überprüft, wie IOS-Router mehrere Identitätszertifikate verarbeiten. Das Netzwerkdiagramm oben zeigt drei 7200-Router, die eine Hub-and-Spoke-Topologie bilden. Der Hub-Router (SJhub) verfügt über zwei Identitätszertifikate - eines von einem Entrust CA-Server und eines von einem Microsoft CA-Server. Der Spoke-Router (SJVPN) verfügt über ein Identitätszertifikat desselben Entrust CA-Servers und der andere Spoke-Router (SJPKI) über ein Identitätszertifikat desselben Microsoft CA-Servers. In diesem Beispiel simuliert der Hub-Router den Verbindungspunkt zweier Unternehmen in einem gemeinsamen Projekt. Mithilfe der Unterstützung von CAs mit mehreren Identitäten kann der Hub mit beiden Seiten kommunizieren, obwohl die Stationen für verschiedene CAs angemeldet sind.
Die Konfigurationen aller Router werden nachfolgend als Referenz aufgeführt.
SJhub (Hub-Router) |
---|
SJhub#write terminal Building configuration... Current configuration : 19665 bytes ! ! Last configuration change at 18:40:55 UTC Sun Jan 13 2002 ! NVRAM config last updated at 18:41:45 UTC Sun Jan 13 2002 ! version 12.2 no parser cache service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname SJhub ! enable password cisco ! ip subnet-zero ip cef ! ! ip telnet source-interface Loopback88 no ip domain-lookup ip domain-name sjtac.com ! ip audit notify log ip audit po max-events 100 ip ssh time-out 120 ip ssh authentication-retries 3 ! crypto ca identity EntrustPKI enrollment mode ra enrollment url http://171.69.89.16:80 query url ldap://171.69.89.16 ! crypto ca identity MicrosoftCA enrollment mode ra enrollment url http://171.69.89.182:80/certsrv/mscep/mscep.dll query url ldap://171.69.89.182 crl optional crypto ca certificate chain EntrustPKI certificate ca 3B2FD307 308202E4 3082024D A0030201 0202043B 2FD30730 0D06092A 864886F7 0D010105 0500302D 310B3009 06035504 06130275 73310E30 0C060355 040A1305 63697363 6F310E30 0C060355 040B1305 736A7670 6E301E17 0D303130 36313932 32303234 305A170D 32313036 31393232 33323430 5A302D31 0B300906 03550406 13027573 310E300C 06035504 0A130563 6973636F 310E300C 06035504 0B130573 6A76706E 30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00E8C25B EDF4A6EE A352B142 C16578F4 FBDAF45E 4F2F7733 8D2B8879 96138C63 1DB713BF 753BF845 2D7E600F AAF4D75B 9E959513 BB13FF13 36696F48 86C464F2 CF854A66 4F8E83F8 025F216B A44D4BB2 39ADD1A5 1BCCF812 09A19BDC 468EEAE1 B6C2A378 69C81348 1A9CD61C 551216F2 8B168FBB 94CBEF37 E1D9A8F7 80BBC17F D1020301 0001A382 010F3082 010B3011 06096086 480186F8 42010104 04030200 07304F06 03551D1F 04483046 3044A042 A040A43E 303C310B 30090603 55040613 02757331 0E300C06 0355040A 13056369 73636F31 0E300C06 0355040B 1305736A 76706E31 0D300B06 03550403 13044352 4C31302B 0603551D 10042430 22800F32 30303130 36313932 32303234 305A810F 32303231 30363139 32323332 34305A30 0B060355 1D0F0404 03020106 301F0603 551D2304 18301680 1446C160 9CDBEA53 EE80A480 601A9658 3B0DF80D 2F301D06 03551D0E 04160414 46C1609C DBEA53EE 80A48060 1A96583B 0DF80D2F 300C0603 551D1304 05300301 01FF301D 06092A86 4886F67D 07410004 10300E1B 0856352E 303A342E 30030204 90300D06 092A8648 86F70D01 01050500 03818100 7E3DBAC4 8CAE7D5A B19C0625 8780D222 F965A1A2 C0C25B84 CBC5A203 BF50FAC4 9656699A 52D8CB46 40776237 87163118 8F3C0F47 D2CAA36B 6AB34F99 AB71269E 78C0AC10 DA0B9EC5 AE448B46 701254CF 3EBC64C1 5DBB2EE5 56C0140B B0C83497 D79FB148 80018F51 3A4B6174 590B85AA 9CE3B391 629406AA 7CE9CC0D 01593E6B quit certificate ra-encryptquit certificate ra-signquit certificatequit crypto ca certificate chain MicrosoftCA certificatequit certificate ra-signquit certificate ra-encryptquit certificate caquit ! crypto isakmp policy 1 hash md5 ! crypto isakmp identity hostname crypto isakmp keepalive 10 ! ! crypto ipsec transform-set myset esp-des esp-md5-hmac crypto mib ipsec flowmib history tunnel size 200 crypto mib ipsec flowmib history failure size 200 ! crypto map vpn 10 ipsec-isakmp set peer 172.16.172.52 set transform-set myset match address 101 crypto map vpn 20 ipsec-isakmp set peer 172.16.172.10 set transform-set myset match address 102 ! ! interface Loopback1 ip address 20.1.1.1 255.255.255.0 ! interface Loopback88 no ip address ! interface FastEthernet0/0 no ip address no keepalive shutdown duplex half media-type MII ! interface Ethernet4/0 ip address 172.16.172.69 255.255.255.240 ip route-cache same-interface no ip mroute-cache duplex half crypto map vpn ! interface Ethernet4/1 no ip address duplex half ! interface Ethernet4/2 no ip address shutdown duplex half ! interface Ethernet4/3 no ip address shutdown duplex half ! ip default-gateway 172.16.172.65 ip classless ip route 0.0.0.0 0.0.0.0 172.16.172.65 ip http server ip pim bidir-enable ! access-list 101 permit ip 20.1.1.0 0.0.0.255 50.1.1.0 0.0.0.255 access-list 102 permit ip 20.1.1.0 0.0.0.255 10.1.1.0 0.0.0.255 ! ! call rsvp-sync ! ! mgcp profile default ! dial-peer cor custom ! ! ! ! gatekeeper shutdown ! ! line con 0 exec-timeout 0 0 line aux 0 line vty 0 4 password cisco login line vty 5 15 login ! no scheduler max-task-time ! end |
SJVPN (Spoke-Router für den Entrust CA-Server registriert) |
---|
SJVPN#write terminal Building configuration... Current configuration : 8980 bytes ! ! Last configuration change at 10:28:19 UTC Sun Jan 13 2002 ! NVRAM config last updated at 10:28:20 UTC Sun Jan 13 2002 ! version 12.2 service timestamps debug uptime service timestamps log uptime no service password-encryption service udp-small-servers service tcp-small-servers no service dhcp ! hostname SJVPN ! enable password cisco ! ip subnet-zero ip cef ! ! no ip domain-lookup ip domain-name sjvpn.com ! ip audit notify log ip audit po max-events 100 ip ssh time-out 120 ip ssh authentication-retries 3 ! crypto ca identity EntrustPKI enrollment mode ra enrollment url http://171.69.89.16:80 query url ldap://171.69.89.16 crypto ca certificate chain EntrustPKI certificate ca 3B2FD307 308202E4 3082024D A0030201 0202043B 2FD30730 0D06092A 864886F7 0D010105 0500302D 310B3009 06035504 06130275 73310E30 0C060355 040A1305 63697363 6F310E30 0C060355 040B1305 736A7670 6E301E17 0D303130 36313932 32303234 305A170D 32313036 31393232 33323430 5A302D31 0B300906 03550406 13027573 310E300C 06035504 0A130563 6973636F 310E300C 06035504 0B130573 6A76706E 30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00E8C25B EDF4A6EE A352B142 C16578F4 FBDAF45E 4F2F7733 8D2B8879 96138C63 1DB713BF 753BF845 2D7E600F AAF4D75B 9E959513 BB13FF13 36696F48 86C464F2 CF854A66 4F8E83F8 025F216B A44D4BB2 39ADD1A5 1BCCF812 09A19BDC 468EEAE1 B6C2A378 69C81348 1A9CD61C 551216F2 8B168FBB 94CBEF37 E1D9A8F7 80BBC17F D1020301 0001A382 010F3082 010B3011 06096086 480186F8 42010104 04030200 07304F06 03551D1F 04483046 3044A042 A040A43E 303C310B 30090603 55040613 02757331 0E300C06 0355040A 13056369 73636F31 0E300C06 0355040B 1305736A 76706E31 0D300B06 03550403 13044352 4C31302B 0603551D 10042430 22800F32 30303130 36313932 32303234 305A810F 32303231 30363139 32323332 34305A30 0B060355 1D0F0404 03020106 301F0603 551D2304 18301680 1446C160 9CDBEA53 EE80A480 601A9658 3B0DF80D 2F301D06 03551D0E 04160414 46C1609C DBEA53EE 80A48060 1A96583B 0DF80D2F 300C0603 551D1304 05300301 01FF301D 06092A86 4886F67D 07410004 10300E1B 0856352E 303A342E 30030204 90300D06 092A8648 86F70D01 01050500 03818100 7E3DBAC4 8CAE7D5A B19C0625 8780D222 F965A1A2 C0C25B84 CBC5A203 BF50FAC4 9656699A 52D8CB46 40776237 87163118 8F3C0F47 D2CAA36B 6AB34F99 AB71269E 78C0AC10 DA0B9EC5 AE448B46 701254CF 3EBC64C1 5DBB2EE5 56C0140B B0C83497 D79FB148 80018F51 3A4B6174 590B85AA 9CE3B391 629406AA 7CE9CC0D 01593E6B quit certificate ra-encryptquit certificate ra-signquit certificatequit ! crypto isakmp policy 1 hash md5 ! crypto isakmp identity hostname crypto isakmp keepalive 10 ! ! crypto ipsec transform-set myset esp-des esp-md5-hmac crypto mib ipsec flowmib history tunnel size 200 crypto mib ipsec flowmib history failure size 200 ! crypto map vpn 10 ipsec-isakmp set peer 172.16.172.69 set transform-set myset match address 101 ! ! ! ! ! ! ! ! ! controller ISA 3/1 ! ! ! ! interface Ethernet1/0 ip address 172.16.172.52 255.255.255.248 no ip redirects duplex half crypto map vpn ! interface Ethernet1/1 ip address 50.1.1.1 255.255.255.0 no ip redirects duplex half ! interface Ethernet1/2 no ip address shutdown duplex half ! interface Ethernet1/3 no ip address shutdown duplex half ! ip classless ip route 0.0.0.0 0.0.0.0 172.16.172.49 no ip http server ip pim bidir-enable ! access-list 101 permit ip 50.1.1.0 0.0.0.255 20.1.1.0 0.0.0.255 ! snmp-server community public RO ! call rsvp-sync ! ! mgcp profile default ! dial-peer cor custom ! ! ! ! gatekeeper shutdown ! ! line con 0 exec-timeout 0 0 line aux 0 line vty 0 4 password cisco no login line vty 5 15 login ! no scheduler max-task-time ! end SJVPN#show crypto ca certificates CA Certificate Status: Available Certificate Serial Number: 3B2FD307 Key Usage: General Purpose Issuer: OU = sjvpn O = cisco C = us Subject: OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:02:40 UTC Jun 19 2001 end date: 22:32:40 UTC Jun 19 2021 Associated Identity: EntrustPKI RA KeyEncipher Certificate Status: Available Certificate Serial Number: 3B2FD318 Key Usage: Encryption Issuer: OU = sjvpn O = cisco C = us Subject: CN = First Officer OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:03:31 UTC Jun 19 2001 end date: 22:33:31 UTC Jun 19 2004 Associated Identity: EntrustPKI RA Signature Certificate Status: Available Certificate Serial Number: 3B2FD319 Key Usage: Signature Issuer: OU = sjvpn O = cisco C = us Subject: CN = First Officer OU = sjvpn O = cisco C = us CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 22:03:31 UTC Jun 19 2001 end date: 22:33:31 UTC Jun 19 2004 Associated Identity: EntrustPKI Certificate Status: Available Certificate Serial Number: 3B2FD65B Key Usage: General Purpose Issuer: OU = sjvpn O = cisco C = us Subject Name Contains: Name: SJVPN.sjvpn.com CRL Distribution Point: CN = CRL1, OU = sjvpn, O = cisco, C = us Validity Date: start date: 20:16:08 UTC Jan 11 2002 end date: 20:46:08 UTC Jan 11 2003 Associated Identity: EntrustPKI |
SJPKI (Spoke-Router für Microsoft CA-Server registriert) |
---|
SJPKI#write terminal Building configuration... Current configuration : 12452 bytes ! ! Last configuration change at 18:40:41 UTC Sun Jan 13 2002 ! NVRAM config last updated at 18:42:15 UTC Sun Jan 13 2002 ! version 12.2 service timestamps debug uptime service timestamps log uptime no service password-encryption service udp-small-servers service tcp-small-servers ! hostname SJPKI ! ! ip subnet-zero ip cef ! ! ip domain-name sjtac ! ip audit notify log ip audit po max-events 100 ip ssh time-out 120 ip ssh authentication-retries 3 ! crypto ca identity MicrosoftPKI enrollment mode ra enrollment url http://171.69.89.182:80/certsrv/mscep/mscep.dll query url ldap://171.69.89.182 crl optional ! ! crypto ca certificate chain MicrosoftPKI certificate caquit certificate ra-encryptquit certificate ra-signquit certificatequit ! crypto isakmp policy 1 hash md5 ! crypto isakmp identity hostname crypto isakmp keepalive 10 ! ! crypto ipsec transform-set myset esp-des esp-md5-hmac crypto mib ipsec flowmib history tunnel size 200 crypto mib ipsec flowmib history failure size 200 ! crypto map vpn 10 ipsec-isakmp set peer 172.16.172.69 set transform-set myset match address 101 ! ! ! ! ! ! ! ! ! controller ISA 2/1 ! ! ! ! interface Ethernet1/0 ip address 172.16.172.10 255.255.255.240 ip broadcast-address 172.16.172.0 no ip redirects duplex half crypto map vpn ! interface Ethernet1/1 ip address 10.1.1.2 255.255.255.0 ip broadcast-address 10.1.1.0 duplex half ! interface Ethernet1/2 no ip address ip broadcast-address 0.0.0.0 shutdown duplex half ! interface Ethernet1/3 no ip address ip broadcast-address 0.0.0.0 shutdown duplex half ! router ospf 1 log-adjacency-changes redistribute static subnets network 10.1.1.0 0.0.0.255 area 0 ! ip classless ip route 0.0.0.0 0.0.0.0 172.16.172.1 no ip http server ip pim bidir-enable ! access-list 101 permit ip 10.1.1.0 0.0.0.255 20.1.1.0 0.0.0.255 ! route-map tftp permit 10 match ip address 150 ! ! call rsvp-sync ! ! mgcp profile default ! dial-peer cor custom ! ! ! ! gatekeeper shutdown ! ! line con 0 exec-timeout 0 0 line aux 0 line vty 0 4 login line vty 5 15 login ! ! end SJPKI#show crypto ca cert CA Certificate Status: Available Certificate Serial Number: 091B47AEE8CFE2A94D3E8B38F292F5AF Key Usage: General Purpose Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki,DC=com? certificateRevocationList?base?objectclass=cRLDistributionPoint Validity Date: start date: 01:51:39 UTC Jan 11 2002 end date: 02:00:04 UTC Jan 11 2007 Associated Identity: MicrosoftPKI RA KeyEncipher Certificate Status: Available Certificate Serial Number: 054E63CE000000000003 Key Usage: Encryption Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject: CN = SJVPNRA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki,DC=com? certificateRevocationList?base?objectclass=cRLDistributionPoint Validity Date: start date: 01:59:28 UTC Jan 11 2002 end date: 01:59:28 UTC Jan 11 2004 Associated Identity: MicrosoftPKI RA Signature Certificate Status: Available Certificate Serial Number: 054E60AD000000000002 Key Usage: Signature Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject: CN = SJVPNRA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki,DC=com? certificateRevocationList?base?objectclass=cRLDistributionPoint Validity Date: start date: 01:59:27 UTC Jan 11 2002 end date: 01:59:27 UTC Jan 11 2004 Associated Identity: MicrosoftPKI Certificate Status: Available Certificate Serial Number: 0961EAC400000000000A Key Usage: General Purpose Issuer: CN = SJPKICA OU = SJPKI O = SJTAC L = SAN JOSE ST = CA C = US Subject Name Contains: Name: SJPKI.sjtac CRL Distribution Point: ldap:///CN=SJPKICA,CN=sjvpnmspki,CN=CDP,CN=Public%20Key%20Services, CN=Services,CN=Configuration,DC=sjpki,DC=com? certificateRevocationList?base?objectclass=cRLDistributionPoint Validity Date: start date: 20:59:17 UTC Jan 11 2002 end date: 20:59:17 UTC Jan 11 2004 Associated Identity: MicrosoftPKI |
Sie können einige IPSec-bezogene IOS-Debugbefehle verwenden, um zu sehen, wie die IKE-Aushandlung (Internet Key Exchange) mit mehreren Identitätszertifikaten funktioniert.
Bestimmte show-Befehle werden vom Output Interpreter Tool unterstützt (nur registrierte Kunden), mit dem Sie eine Analyse der show-Befehlsausgabe anzeigen können.
Hinweis: Bevor Sie Debugbefehle ausgeben, lesen Sie Wichtige Informationen über Debug-Befehle.
debug crypto isakmp: Zeigt Meldungen über IKE-Ereignisse an.
debug crypto ipsec: Zeigt IPSec-Ereignisse an.
debug crypto pki transaction - Zeigt Debugmeldungen für die Verfolgung der Interaktion (Meldungstyp) zwischen der CA und dem Router an.
debug crypto pki message (crypto pki-Nachricht): Zeigt Debugmeldungen für die Details der Interaktion (Message Dump) zwischen der CA und dem Router an.
Die folgenden DebuggingInnen wurden auf SJVPN und SJhub gesammelt. In der Regel versucht SJVPN, den IPSec-Tunnel zum Hub-Router SJhub zu initiieren. SJhub sendet eine CERT_REQ-Payload für jede von ihm unterstützte CA-Domäne. Jede CERT_REQ-Payload enthält den DN des Zertifikatsausstellers. SJVPN versucht dann, die DN im CERT_REQ zuzuordnen und eigene Zertifikate an den SJhub zu senden.
In den folgenden Beispielen sendet der SJhub-Router seine Zertifikate basierend auf dem vom SJVPN-Router gesendeten CERT_REQ. Zertifikate des Entrust CA-Servers werden verwendet.
00:02:24: IPSEC(sa_request): , (key eng. msg.) src= 172.16.172.52, dest= 172.16.172.69, src_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xFA8261EB(4202848747), conn_id= 0, keysize= 0, flags= 0x4004 00:02:24: ISAKMP: received ke message (1/1) 00:02:24: ISAKMP: local port 500, remote port 500 00:02:24: ISAKMP (0:2): Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM Old State = IKE_READY New State = IKE_I_MM1 00:02:24: ISAKMP (0:2): beginning Main Mode exchange 00:02:24: ISAKMP (0:2): sending packet to 172.16.172.69 (I) MM_NO_STATE 00:02:24: ISAKMP (0:2): received packet from 172.16.172.69 (I) MM_NO_STATE 00:02:24: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_I_MM1 New State = IKE_I_MM2 00:02:24: ISAKMP (0:2): processing SA payload. message ID = 0 00:02:24: ISAKMP (0:2): Checking ISAKMP transform 1 against priority 1 policy 00:02:24: ISAKMP: encryption DES-CBC 00:02:24: ISAKMP: hash MD5 00:02:24: ISAKMP: default group 1 00:02:24: ISAKMP: auth RSA sig 00:02:24: ISAKMP: life type in seconds 00:02:24: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80 00:02:24: ISAKMP (0:2): atts are acceptable. Next payload is 0 00:02:24: ISAKMP (0:2): SA is doing RSA signature authentication using id type ID_FQDN 00:02:24: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_I_MM2 New State = IKE_I_MM2 00:02:24: ISAKMP (0:2): sending packet to 172.16.172.69 (I) MM_SA_SETUP 00:02:24: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_I_MM2 New State = IKE_I_MM3 00:02:24: ISAKMP (0:2): received packet from 172.16.172.69 (I) MM_SA_SETUP 00:02:24: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH .ld State = IKE_I_MM3 New State = IKE_I_MM4 00:02:24: ISAKMP (0:2): processing KE payload. message ID = 0 00:02:24: ISAKMP (0:2): processing NONCE payload. message ID = 0 00:02:24: ISAKMP (0:2): SKEYID state generated 00:02:24: ISAKMP (0:2): processing CERT_REQ payload. message ID = 0 00:02:24: ISAKMP (0:2): peer wants a CT_X509_SIGNATURE cert 00:02:24: ISAKMP (0:2): peer want cert issued by CN = SJPKICA, OU = SJPKI, O = SJTAC, L = SAN JOSE, ST = CA, C = US 00:02:24: ISAKMP (0:2): can't find router cert for signature! 00:02:24: ISAKMP (2): issuer name is not a trusted root. 00:02:24: ISAKMP (0:2): processing CERT_REQ payload. message ID = 0 00:02:24: ISAKMP (0:2): peer wants a CT_X509_SIGNATURE cert 00:02:24: ISAKMP (0:2): peer want cert issued by OU = sjvpn, O = cisco, C = us 00:02:24: ISAKMP (0:2): processing vendor id payload 00:02:24: ISAKMP (0:2): speaking to another IOS box! 00:02:24: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_I_MM4 New State = IKE_I_MM4 00:02:24: ISAKMP (2): ID payload next-payload : 6 type : 2 protocol : 17 port : 500 length : 19 00:02:24: ISAKMP (2): Total payload length: 23 00:02:24: ISAKMP (0:2): sending packet to 172.16.172.69 (I) MM_KEY_EXCH 00:02:24: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_I_MM4 New State = IKE_I_MM5 . 00:02:26: ISAKMP (0:2): received packet from 172.16.172.69 (I) MM_KEY_EXCH 00:02:26: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_I_MM5 New State = UNKNOWN 00:02:26: ISAKMP (0:2): processing ID payload. message ID = 0 00:02:26: ISAKMP (0:2): processing CERT payload. message ID = 0 00:02:26: ISAKMP (0:2): processing a CT_X509_SIGNATURE cert 00:02:26: CRYPTO_PKI: status = 0: poll CRL 00:02:27: CRYPTO_PKI: ldap_bind() succeeded. 00:02:27: CRYPTO_PKI: set CRL update timer with delay: 46206 00:02:27: CRYPTO_PKI: the current router time: 13:07:32 UTC Jan 14 2002 00:02:27: CRYPTO_PKI: the last CRL update time: 00:57:38 UTC Jan 14 2002 00:02:27: CRYPTO_PKI: the next CRL update time: 01:57:38 UTC Jan 15 2002 00:02:27: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:27: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:27: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:27: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:27: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:27: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:28: CRYPTO_PKI: transaction GetCRL completed 00:02:28: CRYPTO_PKI: blocking callback received status: 105 00:02:28: CRYPTO_PKI: Certificate verified, chain status= 1 00:02:28: ISAKMP (0:2): processing SIG payload. message ID = 0 00:02:28: ISAKMP (2): sa->peer.name = , sa->peer_id.id.id_fqdn.fqdn = SJhub.sjtac.com 00:02:28: ISAKMP:received payload type 14 00:02:28: ISAKMP (0:2): processing keep alive: proposal=10/2 sec., actual=10/2 sec. 00:02:28: ISA.!! Success rate is 40 percent (2/5), round-trip min/avg/max = 1/2/4 ms SJVPN#KMP (0:2): peer knows about the keepalive extension mechanism. 00:02:28: ISAKMP (0:2): read keepalive extended attribute VPI: /0x2/0x4 00:02:28: ISAKMP (0:2): peer keepalives capabilities: 0x1 00:02:28: ISAKMP (0:2): SA has been authenticated with 172.16.172.69 00:02:28: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = UNKNOWN New State = UNKNOWN 00:02:28: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = UNKNOWN New State = IKE_P1_COMPLETE 00:02:28: ISAKMP (0:2): beginning Quick Mode exchange, M-ID of -304515331 00:02:28: ISAKMP (0:2): sending packet to 172.16.172.69 (I) QM_IDLE 00:02:28: ISAKMP (0:2): Node -304515331, Input = IKE_MESG_INTERNAL, IKE_INIT_QM Old State = IKE_QM_READY New State = IKE_QM_I_QM1 00:02:28: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:02:28: ISAKMP (0:2): received packet from 172.16.172.69 (I) QM_IDLE 00:02:28: ISAKMP (0:2): processing HASH payload. message ID = -304515331 00:02:28: ISAKMP (0:2): processing SA payload. message ID = -304515331 00:02:28: ISAKMP (0:2): Checking IPSec proposal 1 00:02:28: ISAKMP: transform 1, ESP_DES 00:02:28: ISAKMP: attributes in transform: 00:02:28: ISAKMP: encaps is 1 00:02:28: ISAKMP: SA life type in seconds 00:02:28: ISAKMP: SA life duration (basic) of 3600 00:02:28: ISAKMP: SA life type in kilobytes 00:02:28: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0 00:02:28: ISAKMP: authenticator is HMAC-MD5 00:02:28: ISAKMP (0:2): atts are acceptable. 00:02:28: IPSEC(validate_proposal_request): proposal part #1, (key eng. msg.) dest= 172.16.172.69, src= 172.16.172.52, dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 0s and 0kb, spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x4 00:02:28: ISAKMP (0:2): processing NONCE payload. message ID = -304515331 00:02:28: ISAKMP (0:2): processing ID payload. message ID = -304515331 00:02:28: ISAKMP (0:2): processing ID payload. message ID = -304515331 00:02:28: ISAKMP (0:2): Creating IPSec SAs 00:02:28: inbound SA from 172.16.172.69 to 172.16.172.52 (proxy 20.1.1.0 to 50.1.1.0) 00:02:28: has spi 0xFA8261EB and conn_id 2029 and flags 4 00:02:28: lifetime of 3600 seconds 00:02:28: lifetime of 4608000 kilobytes 00:02:28: outbound SA from 172.16.172.52 to 172.16.172.69 (proxy 50.1.1.0 to 20.1.1.0 ) 00:02:28: has spi 206728450 and conn_id 2030 and flags 4 00:02:28: lifetime of 3600 seconds 00:02:28: lifetime of 4608000 kilobytes 00:02:28: IPSEC(key_engine): got a queue event... 00:02:28: IPSEC(initialize_sas): , (key eng. msg.) dest= 172.16.172.52, src= 172.16.172.69, dest_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xFA8261EB(4202848747), conn_id= 2029, keysize= 0, flags= 0x4 00:02:28: IPSEC(initialize_sas): , (key eng. msg.) src= 172.16.172.52, dest= 172.16.172.69, src_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xC526D02(206728450), conn_id= 2030, keysize= 0, flags= 0x4 00:02:28: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.52, sa_prot= 50, sa_spi= 0xFA8261EB(4202848747), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2029 00:02:28: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.69, sa_prot= 50, sa_spi= 0xC526D02(206728450), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2030 00:02:28: ISAKMP (0:2): sending packet to 172.16.172.69 (I) QM_IDLE 00:02:28: ISAKMP (0:2): deleting node -304515331 error FALSE reason "" 00:02:28: ISAKMP (0:2): Node -304515331, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH Old State = IKE_QM_I_QM1 New State = IKE_QM_PHASE2_COMPLETE 00:02:36: ISAKMP (0:2): received packet from 172.16.172.69 (I) QM_IDLE 00:02:36: ISAKMP (0:2): processing HASH payload. message ID = -2051070354 00:02:36: ISAKMP (0:2): processing NOTIFY ITS_ALIVE protocol 1 spi 0, message ID = -2051070354, sa = 62DF2768 00:02:36: ISAKMP (0:2): deleting node -2051070354 error FALSE reason "informational (in) state 1" 00:02:36: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:02:36: ISAKMP (0:2): sending packet to 172.16.172.69 (I) QM_IDLE 00:02:36: ISAKMP (0:2): purging node -739583249 00:02:36: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
00:02:18: ISAKMP (0:0): received packet from 172.16.172.52 (N) NEW SA 00:02:18: ISAKMP: local port 500, remote port 500 00:02:18: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_READY New State = IKE_R_MM1 00:02:18: ISAKMP (0:2): processing SA payload. message ID = 0 00:02:18: ISAKMP (0:2): Checking ISAKMP transform 1 against priority 1 policy 00:02:18: ISAKMP: encryption DES-CBC 00:02:18: ISAKMP: hash MD5 00:02:18: ISAKMP: default group 1 00:02:18: ISAKMP: auth RSA sig 00:02:18: ISAKMP: life type in seconds 00:02:18: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80 00:02:18: ISAKMP (0:2): atts are acceptable. Next payload is 3 00:02:18: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_R_MM1 New State = IKE_R_MM1 00:02:18: ISAKMP (0:2): SA is doing RSA signature authentication using id type ID_FQDN 00:02:18: ISAKMP (0:2): sending packet to 172.16.172.52 (R) MM_SA_SETUP 00:02:18: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_R_MM1 New State = IKE_R_MM2 00:02:18: ISAKMP (0:2): received packet from 172.16.172.52 (R) MM_SA_SETUP 00:02:18: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_R_MM2 New State = IKE_R_MM3 00:02:18: ISAKMP (0:2): processing KE payload. message ID = 0 00:02:19: ISAKMP (0:2): processing NONCE payload. message ID = 0 00:02:19: ISAKMP (0:2): SKEYID state generated 00:02:19: ISAKMP (0:2): processing CERT_REQ payload. message ID = 0 00:02:19: ISAKMP (0:2): peer wants a CT_X509_SIGNATURE cert 00:02:19: ISAKMP (0:2): peer want cert issued by OU = sjvpn, O = cisco, C = us 00:02:19: ISAKMP (0:2): processing vendor id payload 00:02:19: ISAKMP (0:2): speaking to another IOS box! 00:02:19: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_R_MM3 New State = IKE_R_MM3 00:02:19: ISAKMP (0:2): sending packet to 172.16.172.52 (R) MM_KEY_EXCH 00:02:19: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_R_MM3 New State = IKE_R_MM4 00:02:19: ISAKMP (0:2): received packet from 172.16.172.52 (R) MM_KEY_EXCH 00:02:19: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_R_MM4 New State = IKE_R_MM5 00:02:19: ISAKMP (0:2): processing ID payload. message ID = 0 00:02:19: ISAKMP (0:2): processing CERT payload. message ID = 0 00:02:19: ISAKMP (0:2): processing a CT_X509_SIGNATURE cert 00:02:19: CRYPTO_PKI: status = 0: poll CRL 00:02:19: CRYPTO_PKI: ldap_bind() succeeded. 00:02:20: CRYPTO_PKI: set CRL update timer with delay: 49920 00:02:20: CRYPTO_PKI: the current router time: 12:05:38 UTC Jan 14 2002 00:02:20: CRYPTO_PKI: the last CRL update time: 00:57:38 UTC Jan 14 2002 00:02:20: CRYPTO_PKI: the next CRL update time: 01:57:38 UTC Jan 15 2002 00:02:20: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:20: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:20: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:20: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:20: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:20: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:20: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:20: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:20: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:20: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:20: CRYPTO_PKI: status = 0: failed to get public key from the storage 00:02:20: CRYPTO_PKI: status = 65535: failed to get issuer pubkey in cert 00:02:21: CRYPTO_PKI: transaction GetCRL completed 00:02:21: CRYPTO_PKI: blocking callback received status: 105 00:02:21: CRYPTO_PKI: Certificate verified, chain status= 1 00:02:21: ISAKMP (0:2): processing SIG payload. message ID = 0 00:02:21: ISAKMP (2): sa->peer.name = , sa->peer_id.id.id_fqdn.fqdn = SJVPN.sjvpn.com 00:02:21: ISAKMP:received payload type 14 00:02:21: ISAKMP (0:2): processing keep alive: proposal=10/2 sec., actual=10/2 sec. 00:02:21: ISAKMP (0:2): peer knows about the keepalive extension mechanism. 00:02:21: ISAKMP (0:2): read keepalive extended attribute VPI: /0x2/0x4 00:02:21: ISAKMP (0:2): peer keepalives capabilities: 0x1 00:02:21: ISAKMP (0:2): SA has been authenticated with 172.16.172.52 00:02:21: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_R_MM5 New State = IKE_R_MM5 00:02:21: ISAKMP (2): ID payload next-payload : 6 type : 2 protocol : 17 port : 500 length : 19 00:02:21: ISAKMP (2): Total payload length: 23 00:02:21: ISAKMP (0:2): sending packet to 172.16.172.52 (R) QM_IDLE 00:02:21: ISAKMP (0:2): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_R_MM5 New State = IKE_P1_COMPLETE 00:02:23: ISAKMP (0:2): received packet from 172.16.172.52 (R) QM_IDLE 00:02:23: ISAKMP (0:2): processing HASH payload. message ID = -304515331 00:02:23: ISAKMP (0:2): processing SA payload. message ID = -304515331 00:02:23: ISAKMP (0:2): Checking IPSec proposal 1 00:02:23: ISAKMP: transform 1, ESP_DES 00:02:23: ISAKMP: attributes in transform: 00:02:23: ISAKMP: encaps is 1 00:02:23: ISAKMP: SA life type in seconds 00:02:23: ISAKMP: SA life duration (basic) of 3600 00:02:23: ISAKMP: SA life type in kilobytes 00:02:23: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0 00:02:23: ISAKMP: authenticator is HMAC-MD5 00:02:23: ISAKMP (0:2): atts are acceptable. 00:02:23: IPSEC(validate_proposal_request): proposal part #1, (key eng. msg.) dest= 172.16.172.69, src= 172.16.172.52, dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 0s and 0kb, spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x4 00:02:23: ISAKMP (0:2): processing NONCE payload. message ID = -304515331 00:02:23: ISAKMP (0:2): processing ID payload. message ID = -304515331 00:02:23: ISAKMP (2): ID_IPV4_ADDR_SUBNET src 50.1.1.0/255.255.255.0 prot 0 port 0 00:02:23: ISAKMP (0:2): processing ID payload. message ID = -304515331 00:02:23: ISAKMP (2): ID_IPV4_ADDR_SUBNET dst 20.1.1.0/255.255.255.0 prot 0 port 0 00:02:23: ISAKMP (0:2): asking for 1 spis from ipsec 00:02:23: ISAKMP (0:2): Node -304515331, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH Old State = IKE_QM_READY New State = IKE_QM_SPI_STARVE 00:02:23: IPSEC(key_engine): got a queue event... 00:02:23: IPSEC(spi_response): getting spi 206728450 for SA from 172.16.172.52 to 172.16.172.69 for prot 3 00:02:23: ISAKMP: received ke message (2/1) 00:02:23: ISAKMP (0:2): sending packet to 172.16.172.52 (R) QM_IDLE 00:02:23: ISAKMP (0:2): Node -304515331, Input = IKE_MESG_FROM_IPSEC, IKE_SPI_REPLY Old State = IKE_QM_SPI_STARVE New State = IKE_QM_R_QM2 00:02:23: ISAKMP (0:2): received packet from 172.16.172.52 (R) QM_IDLE 00:02:23: ISAKMP (0:2): Creating IPSec SAs 00:02:23: inbound SA from 172.16.172.52 to 172.16.172.69 (proxy 50.1.1.0 to 20.1.1.0) 00:02:23: has spi 0xC526D02 and conn_id 2000 and flags 4 00:02:23: lifetime of 3600 seconds 00:02:23: lifetime of 4608000 kilobytes 00:02:23: outbound SA from 172.16.172.69 to 172.16.172.52 (proxy 20.1.1.0 to 50.1.1.0 ) 00:02:23: has spi -92118549 and conn_id 2001 and flags 4 00:02:23: lifetime of 3600 seconds 00:02:23: lifetime of 4608000 kilobytes 00:02:23: ISAKMP (0:2): deleting node -304515331 error FALSE reason "quick mode done (await()" 00:02:23: ISAKMP (0:2): Node -304515331, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH Old State = IKE_QM_R_QM2 New State = IKE_QM_PHASE2_COMPLETE 00:02:23: IPSEC(key_engine): got a queue event... 00:02:23: IPSEC(initialize_sas): , (key eng. msg.) dest= 172.16.172.69, src= 172.16.172.52, dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xC526D02(206728450), conn_id= 2000, keysize= 0, flags= 0x4 00:02:23: IPSEC(initialize_sas): , (key eng. msg.) src= 172.16.172.69, dest= 172.16.172.52, src_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), dest_proxy= 50.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xFA8261EB(4202848747), conn_id= 2001, keysize= 0, flags= 0x4 00:02:23: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.69, sa_prot= 50, sa_spi= 0xC526D02(206728450), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2000 00:02:23: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.52, sa_prot= 50, sa_spi= 0xFA8261EB(4202848747), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2001 00:02:31: ISAKMP (0:2): sending packet to 172.16.172.52 (R) QM_IDLE 00:02:31: ISAKMP (0:2): purging node -2051070354 00:02:31: ISAKMP (0:2): Input = IKE_MESG_FROM_TIMER, IKE_TIMER_IM_ALIVE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:02:31: ISAKMP (0:2): received packet from 172.16.172.52 (R) QM_IDLE 00:02:31: ISAKMP (0:2): processing HASH payload. message ID = -739583249 00:02:31: ISAKMP (0:2): processing NOTIFY ITS_ALIVE_ACK protocol 1 spi 0, message ID = -739583249, sa = 62DF5324 00:02:31: ISAKMP (0:2): peer 172.16.172.52 is alive! 00:02:31: ISAKMP (0:2): deleting node -739583249 error FALSE reason "informational (in) state 1" 00:02:31: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
SJVPN#show crypto ca crls CRL Issuer Name: OU = sjvpn, O = cisco, C = us LastUpdate: 00:57:38 UTC Jan 14 2002 NextUpdate: 01:57:38 UTC Jan 15 2002 Retrieved from CRL Distribution Point: LDAP: CN = CRL1, OU = sjvpn, O = cisco, C = us SJhub#show crypto ca crls CRL Issuer Name: OU = sjvpn, O = cisco, C = us LastUpdate: 00:57:38 UTC Jan 14 2002 NextUpdate: 01:57:38 UTC Jan 15 2002 Retrieved from CRL Distribution Point: LDAP: CN = CRL1, OU = sjvpn, O = cisco, C = us
Die folgenden DebuggingInnen wurden während der IKE-Aushandlung auf SJPKI und SJhub gesammelt. Nachdem SJPKI die erste CERT_REQ-Payload überprüft hat, werden in der Datenbank bereits übereinstimmende Zertifikate gefunden, sodass die zweite CERT_REQ-Payload nicht mehr untersucht wird. In diesem Fall werden Zertifikate des Microsoft CA-Servers für die IKE-Authentifizierung verwendet.
2d21h: IPSEC(sa_request): , (key eng. msg.) src= 172.16.172.10, dest= 172.16.172.69, src_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xE8559075(3897921653), conn_id= 0, keysize= 0, flags= 0x4004 2d21h: ISAKMP: received ke message (1/1) 2d21h: ISAKMP: local port 500, remote port 500 2d21h: ISAKMP (0:1): Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM Old State = IKE_READY New State = IKE_I_MM1 2d21h: ISAKMP (0:1): beginning Main Mode exchange 2d21h: ISAKMP (0:1): sending packet to 172.16.172.69 (I) MM_NO_STATE 2d21h: ISAKMP (0:1): received packet from 172.16.172.69 (I) MM_NO_STATE 2d21h: ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_I_MM1 New State = IKE_I_MM2 2d21h: ISAKMP (0:1): processing SA payload. message ID = 0 2d21h: ISAKMP (0:1): Checking ISAKMP transform 1 against priority 1 policy 2d21h: ISAKMP: encryption DES-CBC 2d21h: ISAKMP: hash MD5 2d21h: ISAKMP: default group 1 2d21h: ISAKMP: auth RSA sig 2d21h: ISAKMP: life type in seconds 2d21h: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80 2d21h: ISAKMP (0:1): atts are acceptable. Next payload is 0 2d21h: ISAKMP (0:1): SA is doing RSA signature authentication using id type ID_FQDN 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_I_MM2 New State = IKE_I_MM2 2d21h: ISAKMP (0:1): sending packet to 172.16.172.69 (I) MM_SA_SETUP 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_I_MM2 New State = IKE_I_MM3 2d21h: ISAKMP (0:1): received packet from 172.16.172.69 (I) MM_SA_SETUP 2d21h: ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_I_MM3 New State = IKE_I_MM4 2d21h: ISAKMP (0:1): processing KE payload. message ID = 0 2d21h:.!!!! Success rate is 80 percent (4/5), round-trip min/avg/max = 1/3/4 ms SJPKI# ISAKMP (0:1): processing NONCE payload. message ID = 0 2d21h: ISAKMP (0:1): SKEYID state generated 2d21h: ISAKMP (0:1): processing CERT_REQ payload. message ID = 0 2d21h: ISAKMP (0:1): peer wants a CT_X509_SIGNATURE cert 2d21h: ISAKMP (0:1): peer want cert issued by CN = SJPKICA, OU = SJPKI, O = SJTAC, L = SAN JOSE, ST = CA, C = US 2d21h: ISAKMP (0:1): already have a matching cert for this peer. Finish processing cert req. 2d21h: ISAKMP (0:1): processing vendor id payload 2d21h: ISAKMP (0:1): speaking to another IOS box! 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_I_MM4 New State = IKE_I_MM4 2d21h: ISAKMP (1): ID payload next-payload : 6 type : 2 protocol : 17 port : 500 length : 15 2d21h: ISAKMP (1): Total payload length: 19 2d21h: ISKAMP: growing send buffer from 1024 to 3072 2d21h: ISAKMP (0:1): sending packet to 172.16.172.69 (I) MM_KEY_EXCH 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_I_MM4 New State = IKE_I_MM5 2d21h: ISAKMP (0:1): received packet from 172.16.172.69 (I) MM_KEY_EXCH 2d21h: ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_I_MM5 New State = UNKNOWN 2d21h: ISAKMP (0:1): processing ID payload. message ID = 0 2d21h: ISAKMP (0:1): processing CERT payload. message ID = 0 2d21h: ISAKMP (0:1): processing a CT_X509_SIGNATURE cert 2d21h: CRYPTO_PKI: status = 0: crl check ignored 2d21h: CRYPTO_PKI: WARNING: Certificate, private key or CRL was not found while selecting CRL 2d21h: CRYPTO_PKI: cert revocation status unknown. 2d21h: ISAKMP (0:1): cert approved with warning 2d21h: ISAKMP (0:1): processing SIG payload. message ID = 0 2d21h: ISAKMP (1): sa->peer.name = , sa->peer_id.id.id_fqdn.fqdn = SJhub.sjtac.com 2d21h: ISAKMP:received payload type 14 2d21h: ISAKMP (0:1): processing keep alive: proposal=10/2 sec., actual=10/2 sec. 2d21h: ISAKMP (0:1): peer knows about the keepalive extension mechanism. 2d21h: ISAKMP (0:1): read keepalive extended attribute VPI: /0x2/0x4 2d21h: ISAKMP (0:1): peer keepalives capabilities: 0x1 2d21h: ISAKMP (0:1): SA has been authenticated with 172.16.172.69 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = UNKNOWN New State = UNKNOWN 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = UNKNOWN New State = IKE_P1_COMPLETE 2d21h: ISAKMP (0:1): beginning Quick Mode exchange, M-ID of -1644677681 2d21h: ISAKMP (0:1): sending packet to 172.16.172.69 (I) QM_IDLE 2d21h: ISAKMP (0:1): Node -1644677681, Input = IKE_MESG_INTERNAL, IKE_INIT_QM Old State = IKE_QM_READY New State = IKE_QM_I_QM1 2d21h: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 2d21h: ISAKMP (0:1): received packet from 172.16.172.69 (I) QM_IDLE 2d21h: ISAKMP (0:1): processing HASH payload. message ID = -1644677681 2d21h: ISAKMP (0:1): processing SA payload. message ID = -1644677681 2d21h: ISAKMP (0:1): Checking IPSec proposal 1 2d21h: ISAKMP: transform 1, ESP_DES 2d21h: ISAKMP: attributes in transform: 2d21h: ISAKMP: encaps is 1 2d21h: ISAKMP: SA life type in seconds 2d21h: ISAKMP: SA life duration (basic) of 3600 2d21h: ISAKMP: SA life type in kilobytes 2d21h: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0 2d21h: ISAKMP: authenticator is HMAC-MD5 2d21h: ISAKMP (0:1): atts are acceptable. 2d21h: IPSEC(validate_proposal_request): proposal part #1, (key eng. msg.) dest= 172.16.172.69, src= 172.16.172.10, dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 0s and 0kb, spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x4 2d21h: ISAKMP (0:1): processing NONCE payload. message ID = -1644677681 2d21h: ISAKMP (0:1): processing ID payload. message ID = -1644677681 2d21h: ISAKMP (0:1): processing ID payload. message ID = -1644677681 2d21h: ISAKMP (0:1): Creating IPSec SAs 2d21h: inbound SA from 172.16.172.69 to 172.16.172.10 (proxy 20.1.1.0 to 10.1.1.0) 2d21h: has spi 0xE8559075 and conn_id 2029 and flags 4 2d21h: lifetime of 3600 seconds 2d21h: lifetime of 4608000 kilobytes 2d21h: outbound SA from 172.16.172.10 to 172.16.172.69 (proxy 10.1.1.0 to 20.1.1.0 ) 2d21h: has spi -889328648 and conn_id 2030 and flags 4 2d21h: lifetime of 3600 seconds 2d21h: lifetime of 4608000 kilobytes 2d21h: IPSEC(key_engine): got a queue event... 2d21h: IPSEC(initialize_sas): , (key eng. msg.) dest= 172.16.172.10, src= 172.16.172.69, dest_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xE8559075(3897921653), conn_id= 2029, keysize= 0, flags= 0x4 2d21h: IPSEC(initialize_sas): , (key eng. msg.) src= 172.16.172.10, dest= 172.16.172.69, src_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xCAFDEBF8(3405638648), conn_id= 2030, keysize= 0, flags= 0x4 2d21h: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.10, sa_prot= 50, sa_spi= 0xE8559075(3897921653), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2029 2d21h: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.69, sa_prot= 50, sa_spi= 0xCAFDEBF8(3405638648), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2030 2d21h: ISAKMP (0:1): sending packet to 172.16.172.69 (I) QM_IDLE 2d21h: ISAKMP (0:1): deleting node -1644677681 error FALSE reason "" 2d21h: ISAKMP (0:1): Node -1644677681, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH Old State = IKE_QM_I_QM1 New State = IKE_QM_PHASE2_COMPLETE SJPKI# 2d22h: ISAKMP (0:1): received packet from 172.16.172.69 (I) QM_IDLE 2d22h: ISAKMP (0:1): processing HASH payload. message ID = -2115263482 2d22h: ISAKMP (0:1): processing NOTIFY ITS_ALIVE protocol 1 spi 0, message ID = -2115263482, sa = 6335D814 2d22h: ISAKMP (0:1): deleting node -2115263482 error FALSE reason "informational (in) state 1" 2d22h: ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 2d22h: ISAKMP (0:1): sending packet to 172.16.172.69 (I) QM_IDLE 2d22h: ISAKMP (0:1): purging node -1850875331 2d22h: ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE SJPKI#Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
SJhub# 00:07:26: ISAKMP (0:0): received packet from 172.16.172.10 (N) NEW SA 00:07:26: ISAKMP: local port 500, remote port 500 00:07:26: ISAKMP (0:3): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_READY New State = IKE_R_MM1 00:07:26: ISAKMP (0:3): processing SA payload. message ID = 0 00:07:26: ISAKMP (0:3): Checking ISAKMP transform 1 against priority 1 policy 00:07:26: ISAKMP: encryption DES-CBC 00:07:26: ISAKMP: hash MD5 00:07:26: ISAKMP: default group 1 00:07:26: ISAKMP: auth RSA sig 00:07:26: ISAKMP: life type in seconds 00:07:26: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80 00:07:26: ISAKMP (0:3): atts are acceptable. Next payload is 3 00:07:26: ISAKMP (0:3): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_R_MM1 New State = IKE_R_MM1 00:07:26: ISAKMP (0:3): SA is doing RSA signature authentication using id type ID_FQDN 00:07:26: ISAKMP (0:3): sending packet to 172.16.172.10 (R) MM_SA_SETUP 00:07:26: ISAKMP (0:3): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_R_MM1 New State = IKE_R_MM2 00:07:26: ISAKMP (0:3): received packet from 172.16.172.10 (R) MM_SA_SETUP 00:07:26: ISAKMP (0:3): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_R_MM2 New State = IKE_R_MM3 00:07:26: ISAKMP (0:3): processing KE payload. message ID = 0 00:07:26: ISAKMP (0:3): processing NONCE payload. message ID = 0 00:07:26: ISAKMP (0:3): SKEYID state generated 00:07:26: ISAKMP (0:3): processing CERT_REQ payload. message ID = 0 00:07:26: ISAKMP (0:3): peer wants a CT_X509_SIGNATURE cert 00:07:26: ISAKMP (0:3): peer want cert issued by CN = SJPKICA, OU = SJPKI, O = SJTAC, L = SAN JOSE, ST = CA, C = US 00:07:26: ISAKMP (0:3): processing vendor id payload 00:07:26: ISAKMP (0:3): speaking to another IOS box! 00:07:26: ISAKMP (0:3): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_R_MM3 New State = IKE_R_MM3 00:07:26: ISAKMP (0:3): sending packet to 172.16.172.10 (R) MM_KEY_EXCH 00:07:26: ISAKMP (0:3): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_R_MM3 New State = IKE_R_MM4 00:07:26: ISAKMP (0:3): received packet from 172.16.172.10 (R) MM_KEY_EXCH 00:07:26: ISAKMP (0:3): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH Old State = IKE_R_MM4 New State = IKE_R_MM5 00:07:26: ISAKMP (0:3): processing ID payload. message ID = 0 00:07:26: ISAKMP (0:3): processing CERT payload. message ID = 0 00:07:26: ISAKMP (0:3): processing a CT_X509_SIGNATURE cert 00:07:26: CRYPTO_PKI: status = 0: crl check ignored 00:07:26: CRYPTO_PKI: WARNING: Certificate, private key or CRL was not found while selecting CRL 00:07:26: CRYPTO_PKI: cert revocation status unknown. 00:07:26: ISAKMP (0:3): cert approved with warning 00:07:26: ISAKMP (0:3): processing SIG payload. message ID = 0 00:07:26: ISAKMP (3): sa->peer.name = , sa->peer_id.id.id_fqdn.fqdn = SJPKI.sjtac 00:07:26: ISAKMP:received payload type 14 00:07:26: ISAKMP (0:3): processing keep alive: proposal=10/2 sec., actual=10/2 sec. 00:07:26: ISAKMP (0:3): peer knows about the keepalive extension mechanism. 00:07:26: ISAKMP (0:3): read keepalive extended attribute VPI: /0x2/0x4 00:07:26: ISAKMP (0:3): peer keepalives capabilities: 0x1 00:07:26: ISAKMP (0:3): SA has been authenticated with 172.16.172.10 00:07:26: ISAKMP (0:3): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE Old State = IKE_R_MM5 New State = IKE_R_MM5 00:07:26: ISAKMP (3): ID payload next-payload : 6 type : 2 protocol : 17 port : 500 length : 19 00:07:26: ISAKMP (3): Total payload length: 23 00:07:26: ISKAMP: growing send buffer from 1024 to 3072 00:07:26: ISAKMP (0:3): sending packet to 172.16.172.10 (R) QM_IDLE 00:07:26: ISAKMP (0:3): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE Old State = IKE_R_MM5 New State = IKE_P1_COMPLETE 00:07:26: ISAKMP (0:3): received packet from 172.16.172.10 (R) QM_IDLE 00:07:26: ISAKMP (0:3): processing HASH payload. message ID = -1644677681 00:07:26: ISAKMP (0:3): processing SA payload. message ID = -1644677681 00:07:26: ISAKMP (0:3): Checking IPSec proposal 1 00:07:26: ISAKMP: transform 1, ESP_DES 00:07:26: ISAKMP: attributes in transform: 00:07:26: ISAKMP: encaps is 1 00:07:26: ISAKMP: SA life type in seconds 00:07:26: ISAKMP: SA life duration (basic) of 3600 00:07:26: ISAKMP: SA life type in kilobytes 00:07:26: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0 00:07:26: ISAKMP: authenticator is HMAC-MD5 00:07:26: ISAKMP (0:3): atts are acceptable. 00:07:26: IPSEC(validate_proposal_request): proposal part #1, (key eng. msg.) dest= 172.16.172.69, src= 172.16.172.10, dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 0s and 0kb, spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x4 00:07:26: ISAKMP (0:3): processing NONCE payload. message ID = -1644677681 00:07:26: ISAKMP (0:3): processing ID payload. message ID = -1644677681 00:07:26: ISAKMP (3): ID_IPV4_ADDR_SUBNET src 10.1.1.0/255.255.255.0 prot 0 port 0 00:07:26: ISAKMP (0:3): processing ID payload. message ID = -1644677681 00:07:26: ISAKMP (3): ID_IPV4_ADDR_SUBNET dst 20.1.1.0/255.255.255.0 prot 0 port 0 00:07:26: ISAKMP (0:3): asking for 1 spis from ipsec 00:07:26: ISAKMP (0:3): Node -1644677681, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH Old State = IKE_QM_READY New State = IKE_QM_SPI_STARVE 00:07:26: IPSEC(key_engine): got a queue event... 00:07:26: IPSEC(spi_response): getting spi 3405638648 for SA from 172.16.172.10 to 172.16.172.69 for prot 3 00:07:26: ISAKMP: received ke message (2/1) 00:07:27: ISAKMP (0:3): sending packet to 172.16.172.10 (R) QM_IDLE 00:07:27: ISAKMP (0:3): Node -1644677681, Input = IKE_MESG_FROM_IPSEC, IKE_SPI_REPLY Old State = IKE_QM_SPI_STARVE New State = IKE_QM_R_QM2 00:07:27: ISAKMP (0:3): received packet from 172.16.172.10 (R) QM_IDLE 00:07:27: ISAKMP (0:3): Creating IPSec SAs 00:07:27: inbound SA from 172.16.172.10 to 172.16.172.69 (proxy 10.1.1.0 to 20.1.1.0) 00:07:27: has spi 0xCAFDEBF8 and conn_id 2002 and flags 4 00:07:27: lifetime of 3600 seconds 00:07:27: lifetime of 4608000 kilobytes 00:07:27: outbound SA from 172.16.172.69 to 172.16.172.10 (proxy 20.1.1.0 to 10.1.1.0 ) 00:07:27: has spi -397045643 and conn_id 2003 and flags 4 00:07:27: lifetime of 3600 seconds 00:07:27: lifetime of 4608000 kilobytes 00:07:27: ISAKMP (0:3): deleting node -1644677681 error FALSE reason "quick mode done (await()" 00:07:27: ISAKMP (0:3): Node -1644677681, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH Old State = IKE_QM_R_QM2 New State = IKE_QM_PHASE2_COMPLETE 00:07:27: IPSEC(key_engine): got a queue event... 00:07:27: IPSEC(initialize_sas): , (key eng. msg.) dest= 172.16.172.69, src= 172.16.172.10, dest_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), src_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xCAFDEBF8(3405638648), conn_id= 2002, keysize= 0, flags= 0x4 00:07:27: IPSEC(initialize_sas): , (key eng. msg.) src= 172.16.172.69, dest= 172.16.172.10, src_proxy= 20.1.1.0/255.255.255.0/0/0 (type=4), dest_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4), protocol= ESP, transform= esp-des esp-md5-hmac , lifedur= 3600s and 4608000kb, spi= 0xE8559075(3897921653), conn_id= 2003, keysize= 0, flags= 0x4 00:07:27: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.69, sa_prot= 50, sa_spi= 0xCAFDEBF8(3405638648), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2002 00:07:27: IPSEC(create_sa): sa created, (sa) sa_dest= 172.16.172.10, sa_prot= 50, sa_spi= 0xE8559075(3897921653), sa_trans= esp-des esp-md5-hmac , sa_conn_id= 2003 00:07:30: ISAKMP (0:2): sending packet to 172.16.172.52 (R) QM_IDLE 00:07:30: ISAKMP (0:2): purging node -652282805 00:07:30: ISAKMP (0:2): Input = IKE_MESG_FROM_TIMER, IKE_TIMER_IM_ALIVE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:07:30: ISAKMP (0:2): received packet from 172.16.172.52 (R) QM_IDLE 00:07:30: ISAKMP (0:2): processing HASH payload. message ID = 564680579 00:07:30: ISAKMP (0:2): processing NOTIFY ITS_ALIVE_ACK protocol 1 spi 0, message ID = 564680579, sa = 62DF5324 00:07:30: ISAKMP (0:2): peer 172.16.172.52 is alive! 00:07:30: ISAKMP (0:2): deleting node 564680579 error FALSE reason "informational (in) state 1" 00:07:30: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:07:32: ISAKMP (0:2): purging node 1414513005 00:07:36: ISAKMP (0:3): sending packet to 172.16.172.10 (R) QM_IDLE 00:07:36: ISAKMP (0:3): purging node -2115263482 00:07:36: ISAKMP (0:3): Input = IKE_MESG_FROM_TIMER, IKE_TIMER_IM_ALIVE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:07:36: ISAKMP (0:3): received packet from 172.16.172.10 (R) QM_IDLE 00:07:36: ISAKMP (0:3): processing HASH payload. message ID = -1850875331 00:07:36: ISAKMP (0:3): processing NOTIFY ITS_ALIVE_ACK protocol 1 spi 0, message ID = -1850875331, sa = 63338630 00:07:36: ISAKMP (0:3): peer 172.16.172.10 is alive! 00:07:36: ISAKMP (0:3): deleting node -1850875331 error FALSE reason "informational (in) state 1" 00:07:36: ISAKMP (0:3): Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:07:40: ISAKMP (0:2): received packet from 172.16.172.52 (R) QM_IDLE 00:07:40: ISAKMP (0:2): processing HASH payload. message ID = 2075099983 00:07:40: ISAKMP (0:2): processing NOTIFY ITS_ALIVE protocol 1 spi 0, message ID = 2075099983, sa = 62DF5324 00:07:40: ISAKMP (0:2): deleting node 2075099983 error FALSE reason "informational (in) state 1" 00:07:40: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE 00:07:40: ISAKMP (0:2): sending packet to 172.16.172.52 (R) QM_IDLE 00:07:40: ISAKMP (0:2): purging node 1356214450 00:07:40: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
Sie können den Befehl show crypto ipsec als Befehl verwenden, um die ISAKMP- und IPSec-Sicherheitszuordnungen auf den Routern zu überprüfen, nachdem die Tunnel erfolgreich ausgehandelt wurden. Nachfolgend finden Sie eine Beispielausgabe.
SJhub#show crypto isakmp sa dst src state conn-id slot 172.16.172.69 172.16.172.10 QM_IDLE 3 0 172.16.172.69 172.16.172.52 QM_IDLE 2 0 SJhub#show crypto ipsec sa interface: Ethernet4/0 Crypto map tag: vpn, local addr. 172.16.172.69 local ident (addr/mask/prot/port): (20.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) current_peer: 172.16.172.10 PERMIT, flags={origin_is_acl,} #pkts encaps: 4, #pkts encrypt: 4, #pkts digest 4 #pkts decaps: 4, #pkts decrypt: 4, #pkts verify 4 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 172.16.172.69, remote crypto endpt.: 172.16.172.10 path mtu 1500, media mtu 1500 current outbound spi: E8559075 inbound esp sas: spi: 0xCAFDEBF8(3405638648) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2002, flow_id: 3, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607998/3434) IV size: 8 bytes replay detection support: Y inbound ah sas: inbound pcp sas: outbound esp sas: spi: 0xE8559075(3897921653) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2003, flow_id: 4, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607999/3434) IV size: 8 bytes replay detection support: Y outbound ah sas: outbound pcp sas: local ident (addr/mask/prot/port): (20.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (50.1.1.0/255.255.255.0/0/0) current_peer: 172.16.172.52 PERMIT, flags={origin_is_acl,} #pkts encaps: 2, #pkts encrypt: 2, #pkts digest 2 #pkts decaps: 2, #pkts decrypt: 2, #pkts verify 2 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 172.16.172.69, remote crypto endpt.: 172.16.172.52 path mtu 1500, media mtu 1500 current outbound spi: FA8261EB inbound esp sas: spi: 0xC526D02(206728450) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2000, flow_id: 1, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607999/3108) IV size: 8 bytes replay detection support: Y inbound ah sas: inbound pcp sas: outbound esp sas: spi: 0xFA8261EB(4202848747) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2001, flow_id: 2, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607999/3108) IV size: 8 bytes replay detection support: Y outbound ah sas: outbound pcp sas: SJVPN#show crypto isakmp sa dst src state conn-id slot 172.16.172.69 172.16.172.52 QM_IDLE 2 0 SJVPN#show crypto ipsec sa interface: Ethernet1/0 Crypto map tag: vpn, local addr. 172.16.172.52 local ident (addr/mask/prot/port): (50.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (20.1.1.0/255.255.255.0/0/0) current_peer: 172.16.172.69 PERMIT, flags={origin_is_acl,} #pkts encaps: 2, #pkts encrypt: 2, #pkts digest 2 #pkts decaps: 2, #pkts decrypt: 2, #pkts verify 2 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0 #send errors 3, #recv errors 0 local crypto endpt.: 172.16.172.52, remote crypto endpt.: 172.16.172.69 path mtu 1500, media mtu 1500 current outbound spi: C526D02 inbound esp sas: spi: 0xFA8261EB(4202848747) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2029, flow_id: 1, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607999/3398) IV size: 8 bytes replay detection support: Y inbound ah sas: inbound pcp sas: outbound esp sas: spi: 0xC526D02(206728450) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2030, flow_id: 2, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607999/3389) IV size: 8 bytes replay detection support: Y outbound ah sas: outbound pcp sas: SJPKI#show crypto isa sa dst src state conn-id slot 172.16.172.69 172.16.172.10 QM_IDLE 1 0 SJPKI#show crypto ipsec sa interface: Ethernet1/0 Crypto map tag: vpn, local addr. 172.16.172.10 local ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (20.1.1.0/255.255.255.0/0/0) current_peer: 172.16.172.69 PERMIT, flags={origin_is_acl,} #pkts encaps: 7, #pkts encrypt: 7, #pkts digest 7 #pkts decaps: 7, #pkts decrypt: 7, #pkts verify 7 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0 #send errors 3, #recv errors 0 local crypto endpt.: 172.16.172.10, remote crypto endpt.: 172.16.172.69 path mtu 1500, media mtu 1500 current outbound spi: CAFDEBF8 inbound esp sas: spi: 0xE8559075(3897921653) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2029, flow_id: 1, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607998/3308) IV size: 8 bytes replay detection support: Y inbound ah sas: inbound pcp sas: outbound esp sas: spi: 0xCAFDEBF8(3405638648) transform: esp-des esp-md5-hmac , in use settings ={Tunnel, } slot: 0, conn id: 2030, flow_id: 2, crypto map: vpn sa timing: remaining key lifetime (k/sec): (4607999/3308) IV size: 8 bytes replay detection support: Y outbound ah sas: outbound pcp sas:
Überarbeitung | Veröffentlichungsdatum | Kommentare |
---|---|---|
1.0 |
04-May-2004 |
Erstveröffentlichung |