《VPN故障情况.doc》由会员分享,可在线阅读,更多相关《VPN故障情况.doc(10页珍藏版)》请在得力文库 - 分享文档赚钱的网站上搜索。
1、【精品文档】如有侵权,请联系网站删除,仅供学习与交流VPN故障情况.精品文档.Juniper SSG 520 作为总公司的接入设备,同时作为VPN server。其IP地址为x.x.x.226。应用服务器的IP地址为x.x.x.227(NAT一对一)。分公司的软件需要通过VPN接入总公司的网络访问应用服务器。H3C AR18-23S-1作为分公司的接入设备,其IP地址为y.y.y.161。现在遇到的问题是分公司的PC用L2TP拨226 不正常,有时能够成功,有时不成功,成功也是经过多次连接重试之后才成功的。但在分公司之外用L2TP拨226 很正常。成功率100%,而且连接非常的迅速。如将分公司
2、的PC拿到分公司以外的网络就很正常。 以下是H3C AR18-23s-1的配置。sysSystem View: return to User View with Ctrl+Z.H3CdispH3Cdisplay currH3Cdisplay current-configuration sysname H3C clock timezone gmt+08:004 add 08:00:00 cpu-usage cycle 1min firewall enable connection-limit enable connection-limit default action deny connecti
3、on-limit default amount upper-limit 50 lower-limit 20 nat address-group 1 y.y.y.162 y.y.y.166 qos carl 1 source-ip-address range 192.168.1.10 to 192.168.1.255 per-address qos carl 2 destination-ip-address range 192.168.1.10 to 192.168.1.255 per-address DNS resolve DNS server 219.150.32.132 DNS serve
4、r 202.99.96.68 DNS-proxy enable web set-package force flash:/http.zip ip http acl 2000radius scheme systemdomain systemlocal-user admin password cipher Y54NI&IO:MLaN9G%UD&AA! service-type telnet terminal level 3 service-type ftplocal-user laso password simple laso24 service-type telnet level 3detect
5、-group 1 detect-list 1 ip address y.y.y.161 nexthop y.y.y.161detect-group 2 detect-list 1 ip address 60.28.137.9 nexthop 60.28.137.9acl number 2000 rule 0 permit source 192.168.1.0 0.0.0.255 rule 1 denyacl number 3000 rule 3 permit ip source 192.168.1.6 0 rule 100 permit ip destination 202.99.96.68
6、0 rule 100 comment Main DNS Server rule 101 permit ip destination 219.150.32.132 0 rule 101 comment Secendry DNS Server rule 102 permit ip destination 218.68.250.117 0 rule 110 permit ip destination x.x.x.229 0 rule 110 comment OA and E-email server rule 111 permit ip destination 65.55.15.122 0 rule
7、 111 comment E-email rule 112 permit ip destination 207.46.0.0 0.0.255.255 rule 112 comment MSN Server rule 113 permit ip destination 218.68.250.119 0 rule 113 comment E-email rule 114 permit ip destination 65.54.0.0 0.0.255.255 rule 114 comment rule 116 permit ip destination 202.108.5.0 0.0.0.255 r
8、ule 116 comment rule 117 permit ip destination 220.181.12.101 0 rule 118 permit ip destination 60.211.251.0 0.0.0.255 rule 118 comment rule 119 permit ip source 192.168.1.160 0 rule 120 permit ip source 192.168.1.161 0 rule 121 permit ip source 192.168.1.162 0 rule 122 permit ip source 192.168.1.163
9、 0 rule 123 permit ip source 192.168.1.164 0 rule 124 permit ip source 192.168.1.165 0 rule 125 permit ip source 192.168.1.166 0 rule 126 permit ip source 192.168.1.167 0 rule 127 permit ip source 192.168.1.168 0 rule 128 permit ip source 192.168.1.169 0 rule 129 permit ip source 192.168.1.170 0 rul
10、e 130 permit ip source 192.168.1.171 0 rule 131 permit ip source 192.168.1.172 0 rule 132 permit ip source 192.168.1.173 0 rule 133 permit ip source 192.168.1.174 0 rule 134 permit ip source 192.168.1.175 0 rule 135 permit ip source 192.168.1.176 0 rule 136 permit ip source 192.168.1.177 0 rule 137
11、permit ip source 192.168.1.178 0 rule 138 permit ip source 192.168.1.179 0 rule 139 permit ip source 192.168.1.180 0 rule 140 permit ip source 192.168.1.181 0 rule 141 permit ip source 192.168.1.182 0 rule 142 permit ip source 192.168.1.183 0 rule 143 permit ip source 192.168.1.184 0 rule 144 permit
12、 ip source 192.168.1.185 0 rule 145 permit ip source 192.168.1.198 0 rule 146 permit ip source 192.168.1.187 0 rule 147 permit ip source 192.168.1.188 0 rule 148 permit ip source 192.168.1.190 0 rule 149 permit ip source 192.168.1.191 0 rule 151 permit ip source 192.168.1.221 0 rule 152 permit ip so
13、urce 192.168.1.220 0 rule 153 permit ip source 192.168.1.241 0 rule 157 permit ip source 192.168.1.192 0 rule 158 permit ip source 192.168.1.193 0 rule 159 permit ip source 192.168.1.194 0 rule 160 permit ip source 192.168.1.235 0 rule 161 permit ip source 192.168.1.195 0 rule 162 permit ip source 1
14、92.168.1.240 0 rule 163 permit ip source 192.168.1.236 0 rule 195 permit ip source 192.168.1.33 0 destination 202.108.3.190 0 rule 196 permit ip source 192.168.1.194 0 destination 218.68.250.117 0 rule 197 permit ip source 192.168.1.33 0 destination 202.108.3.242 0 rule 201 permit ip source 192.168.
15、1.5 0 destination 211.151.252.0 0.0.0.255 rule 202 permit ip source 192.168.1.15 0 destination 211.151.252.0 0.0.0.255 rule 205 permit ip source 192.168.1.15 0 destination 123.103.65.0 0.0.0.255 rule 206 permit ip source 192.168.1.15 0 destination 60.28.183.0 0.0.0.255 rule 207 permit ip source 192.
16、168.1.5 0 destination 123.103.65.0 0.0.0.255 rule 208 permit ip source 192.168.1.5 0 destination 60.28.183.0 0.0.0.255 rule 211 permit ip source 192.168.1.5 0 destination 60.30.26.0 0.0.0.255 rule 212 permit ip source 192.168.1.15 0 destination 60.30.26.0 0.0.0.255 rule 214 permit ip source 192.168.
17、1.5 0 destination 116.213.92.205 0 rule 214 comment rule 215 permit ip source 192.168.1.15 0 destination 116.213.92.205 0 rule 217 permit ip source 192.168.1.5 0 destination 125.39.33.163 0 rule 217 comment rule 218 permit ip source 192.168.1.15 0 destination 125.39.33.163 0 rule 223 permit ip sourc
18、e 192.168.1.5 0 destination 210.192.125.29 0 rule 224 permit ip source 192.168.1.5 0 destination 60.28.124.0 0.0.0.255 rule 225 permit ip source 192.168.1.5 0 destination 61.129.48.191 0 rule 226 permit ip source 192.168.1.15 0 destination 210.192.125.29 0 rule 227 permit ip source 192.168.1.15 0 de
19、stination 60.28.124.0 0.0.0.255 rule 228 permit ip source 192.168.1.15 0 destination 61.129.48.191 0 rule 231 permit ip source 192.168.1.5 0 destination 211.99.188.0 0.0.0.255 rule 232 permit ip source 192.168.1.15 0 destination 211.99.188.0 0.0.0.255 rule 234 permit ip source 192.168.1.5 0 destinat
20、ion 60.30.83.93 0 rule 235 permit ip source 192.168.1.15 0 destination 60.30.83.93 0 rule 237 permit ip source 192.168.1.5 0 destination 61.136.19.66 0 rule 238 permit ip source 192.168.1.15 0 destination 61.136.19.66 0 rule 241 permit ip source 192.168.1.5 0 destination 60.28.158.247 0 rule 242 per
21、mit ip source 192.168.1.15 0 destination 60.28.158.247 0 rule 243 permit ip source 192.168.1.5 0 destination 222.73.161.168 0 rule 244 permit ip source 192.168.1.15 0 destination 222.73.161.168 0 rule 247 permit ip source 192.168.1.5 0 destination 61.129.52.193 0 rule 248 permit ip source 192.168.1.
22、15 0 destination 61.129.52.193 0 rule 250 permit ip source 192.168.1.5 0 destination 61.155.43.203 0 rule 251 permit ip source 192.168.1.15 0 destination 61.155.43.203 0 rule 256 permit ip destination 124.40.42.126 0 rule 257 permit ip source 192.168.1.15 0 destination 202.108.22.0 0.0.0.255 rule 25
23、8 permit ip source 192.168.1.5 0 destination 202.108.22.0 0.0.0.255 rule 260 permit ip source 192.168.1.4 0 destination 202.108.3.242 0 rule 261 permit ip source 192.168.1.4 0 destination 202.108.3.190 0 rule 262 permit ip source 192.168.1.35 0 destination 202.108.3.0 0.0.0.255 rule 264 permit ip so
24、urce 192.168.1.15 0 destination 202.108.3.0 0.0.0.255 rule 265 permit ip source 192.168.1.4 0 destination 202.165.103.162 0 rule 265 comment rule 266 permit ip source 192.168.1.29 0 destination 202.165.103.162 0 rule 267 permit ip source 192.168.1.29 0 destination 203.209.228.241 0 rule 270 permit i
25、p source 192.168.1.4 0 destination 221.12.118.2 0 rule 270 comment rule 271 permit ip source 192.168.1.4 0 destination 61.156.39.35 0 rule 271 comment rule 272 permit ip source 192.168.1.4 0 destination 210.51.168.13 0 rule 272 comment rule 273 permit ip source 192.168.1.4 0 destination 221.194.137.
26、0 0.0.0.255 rule 273 comment rule 274 permit ip source 192.168.1.52 0 destination 221.12.118.2 0 rule 275 permit ip source 192.168.1.52 0 destination 61.156.39.35 0 rule 276 permit ip source 192.168.1.52 0 destination 210.51.168.13 0 rule 277 permit ip source 192.168.1.4 0 destination 202.99.102.30
27、0 rule 279 permit ip source 192.168.1.41 0 destination 202.99.102.0 0.0.0.255 rule 280 permit ip source 192.168.1.5 0 destination 204.2.0.0 0.0.255.255 rule 280 comment hotmail rule 281 permit ip source 192.168.1.5 0 destination 64.4.0.0 0.0.255.255 rule 281 comment hotmail rule 282 permit ip source
28、 192.168.1.5 0 destination 221.192.148.58 0 rule 282 comment hotmail rule 283 permit ip source 192.168.1.42 0 destination 202.99.102.0 0.0.0.255 rule 283 comment rule 293 permit ip source 192.168.1.5 0 destination 65.55.15.0 0.0.0.255 rule 293 comment hotmail rule 294 permit ip source 192.168.1.5 0
29、destination 157.238.197.0 0.0.0.255 rule 294 comment hotmail rule 295 permit ip source 192.168.1.5 0 destination 60.28.252.0 0.0.0.255 rule 295 comment hotmail rule 296 permit ip source 192.168.1.46 0 destination 202.99.102.0 0.0.0.255 rule 300 permit ip destination 210.13.74.67 0 rule 300 comment r
30、ule 301 permit ip destination 210.51.39.165 0 rule 301 comment rule 302 permit ip destination 161.165.206.20 0 rule 302 comment https:/retaillink.wal- rule 303 permit ip destination 203.86.31.113 0 rule 303 comment rule 304 permit ip destination 202.106.132.7 0 rule 304 comment http:/bjvrm.wu- rule
31、305 permit ip destination 218.69.108.188 0 rule 305 comment rule 306 permit ip destination 210.51.45.242 0 rule 306 comment rule 307 permit ip destination 211.152.35.5 0 rule 307 comment rule 308 permit ip destination 164.139.14.245 0 rule 308 comment https:/www.metrocc- rule 309 permit ip destinati
32、on 211.95.120.4 0 rule 309 comment https:/supplier.rt- rule 310 permit ip destination 210.51.21.247 0 rule 310 comment http:/www.b2b.trust- rule 311 permit ip destination 203.187.169.228 0 rule 311 comment rule 312 permit ip destination 222.68.247.52 0 rule 312 comment rule 313 permit ip destination
33、 210.21.231.20 0 rule 313 comment http:/www.sf- rule 314 permit ip destination 119.48.17.106 0 rule 314 comment http:/changchun.beijing- rule 315 permit ip destination 210.51.45.174 0 rule 315 comment https:/210.51.45.174/exchange rule 316 permit ip destination 203.166.160.179 0 rule 316 comment htt
34、p:/emart- rule 317 permit ip destination 123.127.50.158 0 rule 317 comment rule 318 permit ip destination 211.152.13.7 0 rule 318 comment http:/211.152.13.7/jkl/login.jsp rule 319 permit ip destination 211.155.30.59 0 rule 319 comment rule 440 permit ip source 192.168.1.5 0 destination 65.55.0.0 0.0
35、.255.255 rule 441 permit ip source 192.168.1.5 0 destination 124.40.0.0 0.0.255.255 rule 442 permit ip source 192.168.1.5 0 destination 64.4.32.7 0 rule 443 permit ip source 192.168.1.5 0 destination 61.129.0.0 0.0.255.255 rule 444 permit ip source 192.168.1.5 0 destination 77.67.126.0 0.0.0.255 rul
36、e 500 permit ip source 192.168.1.4 0 destination 222.173.194.29 0 rule 500 comment rule 501 permit ip source 192.168.1.4 0 destination 222.173.194.27 0 rule 501 comment rule 502 permit ip source 192.168.1.4 0 destination 60.195.249.76 0 rule 502 comment rule 503 permit ip source 192.168.1.4 0 destin
37、ation 220.194.5.210 0 rule 503 comment rule 504 permit ip source 192.168.1.4 0 destination 123.127.76.13 0 rule 504 comment rule 505 permit ip source 192.168.1.4 0 destination 220.181.27.0 0.0.0.255 rule 506 permit ip source 192.168.1.4 0 destination 125.35.6.30 0 rule 506 comment rule 507 permit ip
38、 source 192.168.1.4 0 destination 61.181.81.98 0 rule 507 comment rule 510 permit ip source 192.168.1.53 0 destination 210.51.168.13 0 rule 511 permit ip source 192.168.1.57 0 destination 210.51.168.13 0 rule 512 permit ip source 192.168.1.53 0 destination 222.173.194.29 0 rule 513 permit ip source
39、192.168.1.57 0 destination 222.173.194.29 0 rule 514 permit ip source 192.168.1.53 0 destination 222.173.194.27 0 rule 515 permit ip source 192.168.1.57 0 destination 222.173.194.27 0 rule 516 permit ip source 192.168.1.53 0 destination 60.195.249.76 0 rule 517 permit ip source 192.168.1.57 0 destin
40、ation 60.195.249.76 0 rule 518 permit ip source 192.168.1.53 0 destination 220.194.5.210 0 rule 519 permit ip source 192.168.1.57 0 destination 220.194.5.210 0 rule 520 permit ip source 192.168.1.53 0 destination 123.127.76.13 0 rule 521 permit ip source 192.168.1.57 0 destination 123.127.76.13 0 ru
41、le 523 permit ip source 192.168.1.57 0 destination 220.181.27.0 0.0.0.255 rule 524 permit ip source 192.168.1.57 0 destination 125.35.6.30 0 rule 525 permit ip destination 161.165.206.59 0 rule 526 permit ip destination 208.73.210.21 0 rule 527 permit ip destination 60.190.216.103 0 rule 528 permit
42、ip destination 61.129.48.158 0 rule 529 permit ip destination 164.139.34.245 0 rule 530 permit ip destination 202.75.211.40 0 rule 531 permit ip destination 218.68.250.118 0 rule 532 permit ip source x.x.x.229 0 rule 533 permit ip destination 206.125.101.12 0 rule 534 permit ip destination 202.108.2
43、2.43 0 rule 535 permit ip destination 164.61.205.245 0 rule 536 permit ip destination 218.61.204.68 0 rule 537 permit ip destination 221.194.137.193 0 rule 538 permit ip destination 207.46.16.252 0 rule 539 permit ip destination 219.153.72.222 0 rule 540 permit ip destination 61.135.208.120 0 rule 5
44、41 permit ip destination 220.194.69.150 0 rule 542 permit ip destination 220.194.69.140 0 rule 543 permit ip destination 125.90.204.85 0 rule 544 permit ip destination 151.211.198.240 0 rule 545 permit ip destination 65.55.15.243 0 rule 546 permit ip destination 125.211.198.240 0 rule 547 permit ip
45、destination 60.28.252.227 0 rule 548 permit ip source 221.238.255.149 0 rule 549 permit ip destination 218.30.115.107 0 rule 550 permit ip destination 202.108.3.190 0 rule 551 permit ip destination x.x.x.226 0 rule 552 permit ip destination 124.238.254.44 0 rule 553 permit ip destination 222.186.16.178 0 rule 554 permit ip source x.x.x.226 0 rule 2025 permit ip destination 210.72.46.28 0 rule 2026 permit ip destination 60.29