Привет всем! У меня возникла проблема с настройкой IPSec VPN между RB1100 (v4.12) и FortGate 331B (v4.0, build0342, 120227). Я уже искал информацию на форумах поддержки, но пока безуспешно. Прилагаю логи и конфигурации обоих устройств к этому посту. Все "падает" с ошибкой "invalid length of payload / malformed or expired". Я совершенно в тупике, не понимаю, что не так.
jul/18 16:48:39 ipsec respond new phase 1 negotiation: *MIKROTIK-IP*[500]<=>*FORTGATE-IP*[500]
jul/18 16:48:39 ipsec begin Identity Protection mode.
jul/18 16:48:39 ipsec received Vendor ID: RFC 3947
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-03
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
jul/18 16:48:39 ipsec
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-01
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-00
jul/18 16:48:39 ipsec received Vendor ID: DPD
jul/18 16:48:39 ipsec Selected NAT-T version: RFC 3947
jul/18 16:48:39 ipsec Hashing *MIKROTIK-IP*[500] with algo #1
jul/18 16:48:39 ipsec NAT-D payload #0 verified
jul/18 16:48:39 ipsec Hashing *FORTGATE-IP*[500] with algo #1
jul/18 16:48:39 ipsec NAT-D payload #1 verified
jul/18 16:48:39 ipsec NAT not detected
jul/18 16:48:39 ipsec Hashing *REMOTE-IP*[500] with algo #1
jul/18 16:48:39 ipsec Hashing *FORTGATE-IP*[500] with algo #1
jul/18 16:48:39 ipsec Adding remote and local NAT-D payloads.
jul/18 16:48:39 ipsec phase1 negotiation failed due to time up. f3910b0466248ffb:db0f570033e05fba
jul/18 16:48:39 ipsec invalid length of payload
Буду очень признателен за любую помощь! Спасибо большое!
fortgate_log.txt (3.8 KB)
fortgate_config.txt (3.93 KB)
mikrotik_config.txt (941 Bytes)
jul/18 16:48:39 ipsec respond new phase 1 negotiation: *MIKROTIK-IP*[500]<=>*FORTGATE-IP*[500]
jul/18 16:48:39 ipsec begin Identity Protection mode.
jul/18 16:48:39 ipsec received Vendor ID: RFC 3947
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-03
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
jul/18 16:48:39 ipsec
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-01
jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-00
jul/18 16:48:39 ipsec received Vendor ID: DPD
jul/18 16:48:39 ipsec Selected NAT-T version: RFC 3947
jul/18 16:48:39 ipsec Hashing *MIKROTIK-IP*[500] with algo #1
jul/18 16:48:39 ipsec NAT-D payload #0 verified
jul/18 16:48:39 ipsec Hashing *FORTGATE-IP*[500] with algo #1
jul/18 16:48:39 ipsec NAT-D payload #1 verified
jul/18 16:48:39 ipsec NAT not detected
jul/18 16:48:39 ipsec Hashing *REMOTE-IP*[500] with algo #1
jul/18 16:48:39 ipsec Hashing *FORTGATE-IP*[500] with algo #1
jul/18 16:48:39 ipsec Adding remote and local NAT-D payloads.
jul/18 16:48:39 ipsec phase1 negotiation failed due to time up. f3910b0466248ffb:db0f570033e05fba
jul/18 16:48:39 ipsec invalid length of payload
Буду очень признателен за любую помощь! Спасибо большое!
fortgate_log.txt (3.8 KB)
fortgate_config.txt (3.93 KB)
mikrotik_config.txt (941 Bytes)