{"id":40,"date":"2009-02-10T07:12:24","date_gmt":"2009-02-10T07:12:24","guid":{"rendered":"http:\/\/www.houquner.com\/?p=101"},"modified":"2009-02-10T07:12:24","modified_gmt":"2009-02-10T07:12:24","slug":"juniper%e9%98%b2%e7%81%ab%e5%a2%99-untrust%e5%ad%90%e6%8e%a5%e5%8f%a3%e4%b8%8a%e5%81%9avpn","status":"publish","type":"post","link":"https:\/\/www.houquner.com\/index.php\/archives\/40","title":{"rendered":"Juniper\u9632\u706b\u5899 untrust\u5b50\u63a5\u53e3\u4e0a\u505aVPN"},"content":{"rendered":"<p>\u5728\u4e24\u8fb9\u90fd\u4f7f\u7528\u7b56\u7565VPN\u7684\u60c5\u51b5\u4e0b\u4e0d\u901a,DEBUG\u7ed3\u679c\u5982\u4e0b<br \/>\n****** 05955.0: &lt;Trust\/ethernet1&gt; packet received [60]******<br \/>\n ipid = 4765(129d), @d7816110<br \/>\n packet passed sanity check.<br \/>\n ethernet1:1.1.1.93\/7425-&gt;2.2.2.1\/768,1(8\/0)&lt;Root&gt;<br \/>\n no session found<br \/>\n flow_first_sanity_check: in &lt;ethernet1&gt;, out &lt;N\/A&gt;<br \/>\n chose interface ethernet1 as incoming nat if.<br \/>\n flow_first_routing: in &lt;ethernet1&gt;, out &lt;N\/A&gt;<br \/>\n search route to (ethernet1, 1.1.1.93-&gt;2.2.2.1) in vr trust-vr for vsd-0\/flag-0\/ifp-null<br \/>\nno route to (1.1.1.93-&gt;2.2.2.1) in vr trust-vr\/0<br \/>\n packet dropped, no route<br \/>\n****** 05960.0: &lt;Trust\/ethernet1&gt; packet received [60]******<br \/>\n ipid = 4766(129e), @d7816910<br \/>\n packet passed sanity check.<br \/>\n ethernet1:1.1.1.93\/7681-&gt;2.2.2.1\/768,1(8\/0)&lt;Root&gt;<br \/>\n no session found<br \/>\n flow_first_sanity_check: in &lt;ethernet1&gt;, out &lt;N\/A&gt;<br \/>\n chose interface ethernet1 as incoming nat if.<br \/>\n flow_first_routing: in &lt;ethernet1&gt;, out &lt;N\/A&gt;<br \/>\n search route to (ethernet1, 1.1.1.93-&gt;2.2.2.1) in vr trust-vr for vsd-0\/flag-0\/ifp-null<br \/>\nno route to (1.1.1.93-&gt;2.2.2.1) in vr trust-vr\/0<br \/>\n packet dropped, no route<\/p>\n<p>\u4ee5\u4e0a\u4fe1\u606f\u8bf4\u660e,\u8fd9\u79cd\u60c5\u51b5\u4e0b\u9632\u706b\u5899\u67e5\u627e\u8def\u7531,\u8fd8\u6ca1\u6709\u5230\u67e5\u627e\u7b56\u7565\u7684\u6b65\u9aa4.<\/p>\n<p>\u5728\u4e24\u8fb9\u90fd\u4f7f\u7528tunnel\u65b9\u5f0f,VPN\u901a,DEBUG\u7ed3\u679c\u5982\u4e0b<br \/>\n****** 11040.0: &lt;Trust\/ethernet1&gt; packet received [60]******<br \/>\n ipid = 21354(536a), @d7812910<br \/>\n packet passed sanity check.<br \/>\n ethernet1:1.1.1.93\/61956-&gt;2.2.2.1\/768,1(8\/0)&lt;Root&gt;<br \/>\n no session found<br \/>\n flow_first_sanity_check: in &lt;ethernet1&gt;, out &lt;N\/A&gt;<br \/>\n chose interface ethernet1 as incoming nat if.<br \/>\n flow_first_routing: in &lt;ethernet1&gt;, out &lt;N\/A&gt;<br \/>\n search route to (ethernet1, 1.1.1.93-&gt;2.2.2.1) in vr trust-vr for vsd-0\/flag-0\/ifp-null<br \/>\n [ Dest] 16.route 2.2.2.1-&gt;2.2.2.1, to tunnel.1<br \/>\n routed (x_dst_ip 2.2.2.1) from ethernet1 (ethernet1 in 0) to tunnel.1<br \/>\n? policy search from zone 2-&gt; zone 1<br \/>\npolicy_flow_search? policy search nat_crt from zone 2-&gt; zone 1<br \/>\n RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip 2.2.2.1, port 22615, proto 1)<br \/>\n No SW RPC rule match, search HW rule<br \/>\n Permitted by policy 1<br \/>\n No src xlate NHTB entry search no found: vpn none tif tunnel.1 nexthop 2.2.2.1<br \/>\n choose interface tunnel.1 as outgoing phy if<br \/>\n no loop on ifp tunnel.1.<br \/>\n session application type 0, name None, nas_id 0, timeout 60sec<br \/>\n service lookup identified service 0.<br \/>\n flow_first_final_check: in &lt;ethernet1&gt;, out &lt;tunnel.1&gt;<br \/>\n existing vector list 5-66597e0.<br \/>\n Session (id:128058) created for first pak 5<br \/>\n flow_first_install_session======&gt;<br \/>\n cache mac in the session<br \/>\n make_nsp_ready_no_resolve()<br \/>\n search route to (tunnel.1, 2.2.2.1-&gt;1.1.1.93) in vr trust-vr for vsd-0\/flag-3000\/ifp-ethernet1<br \/>\n [ Dest] 14.route 1.1.1.93-&gt;1.1.1.93, to ethernet1<br \/>\n route to 1.1.1.93<br \/>\n flow got session.<br \/>\n flow session id 128058<br \/>\n skipping pre-frag<br \/>\n going into tunnel 40000005.<br \/>\n flow_encrypt: pipeline.<br \/>\nchip info: DMA. Tunnel id 00000005<br \/>\n(vn2)? doing ESP encryption and size =64<br \/>\nipsec encrypt prepare engine done<br \/>\nipsec encrypt set engine done<br \/>\nipsec encrypt engine released<br \/>\nipsec encrypt done<br \/>\n put packet(557d210) into flush queue.<br \/>\n remove packet(557d210) out from flush queue.<br \/>\n**** jump to packet:30.0.0.1-&gt;30.0.0.254<br \/>\n out encryption tunnel 40000005 gw:30.0.0.254<br \/>\n no more encapping needed<br \/>\n send out through normal path.<br \/>\n flow_ip_send: 55f7:30.0.0.1-&gt;30.0.0.254,50 =&gt; ethernet3.3(112) flag 0x0, vlan 30<br \/>\n mac 001bc05dbc06 in session<br \/>\n packet send out to 001bc05dbc06 through ethernet3.3<br \/>\n **** pak processing end.<\/p>\n<p>\u7ed3\u8bba:\u4f7f\u7528untrust\u5b50\u63a5\u53e3\u4f5c\u4e3avpn\u7684\u63a5\u53e3\u7684\u9632\u706b\u5899\u9700\u8981\u4f7f\u7528tunnel\u65b9\u5f0f,\u5bf9\u7aef\u53ef\u4ee5\u4e3a\u7b56\u7565VPN.<\/p>\n<p>\u914d\u7f6e\u89c1\u9644\u4ef6:<\/p>\n<p>\u6587\u4ef6:<br \/>\nnetscreen.zip<\/p>\n<p>\u5927\u5c0f:<br \/>\n2KB<\/p>\n<p>\u4e0b\u8f7d:<br \/>\n\u4e0b\u8f7d<\/p>\n<p>\u8f6c\u8f7d\u8bf7\u6ce8\u660e\uff1a<a href=\"https:\/\/www.houquner.com\">Kermit\u7684\u7f51\u7ad9<\/a> &raquo; <a href=\"https:\/\/www.houquner.com\/index.php\/archives\/40\">Juniper\u9632\u706b\u5899 untrust\u5b50\u63a5\u53e3\u4e0a\u505aVPN<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>\u5728\u4e24\u8fb9\u90fd\u4f7f\u7528\u7b56\u7565VPN\u7684\u60c5\u51b5\u4e0b\u4e0d\u901a,DEBUG\u7ed3\u679c\u5982\u4e0b ****** 05955.0: &lt;Trust\/ethernet1&gt; packet received [60]****** ipid = 4765(129d), @d7816110 p [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-40","post","type-post","status-publish","format-standard","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/posts\/40"}],"collection":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/comments?post=40"}],"version-history":[{"count":0,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/posts\/40\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/media?parent=40"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/categories?post=40"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/tags?post=40"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}