აუ მოდერმა ჩაასწოროს სათაურშI რაა ვპნ-ს პრობლემა უნდა ეწეროს

ანუ მაქვს სისცო 871w
დავაყენე ვიპიენი, კლიენტები უნდა შემოვიდნენ სისკო ვპნ კლიენტი-თ ჩვენს ქსელში
პროგრამა კონექტდება, აიპის იღებს მაგრამ მერე უკვე შიგნით ქსელის რესურსებთან წვდომა არაა
რაუტერზე მიწერს ამას:
%CRYPTO-4-RECVD_PKT_NOT_IPSEC: Rec'd packet not an IPSEC packet.
ესეც კონფიგი
აიპიები შეცვლილი მაქვს

თუ რამე ისეთი გამომრჩა არ შეიმჩნიოთ

Current configuration : 6211 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname jjj
!
boot-start-marker
boot-end-marker
!
logging buffered 51200 warnings
!
aaa new-model
!
!
aaa authentication login default local
aaa authentication login userlist local
aaa authentication login VPN_AUTHEN local
aaa authorization network VPN_AUTHOR local
!
aaa session-id common
!
resource policy
!
ip subnet-zero
ip cef
!
!
ip domain name fff
ip name-server 213.131.32.34
ip name-server 213.131.34.2
ip name-server X.x.x.x
ip name-server x.x.x.y
ip name-server c.c.c.c
ip ssh authentication-retries 2
ip ssh version 2
ip ddns update method sdm_ddns1
DDNS both
!
!
!
crypto pki trustpoint TP-self-signed-2188427757
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2188427757
revocation-check none
rsakeypair TP-self-signed-2188427757
!
!
crypto pki certificate chain TP-self-signed-2188427757
certificate self-signed 01
30820254 308201BD A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32313838 34323737 3537301E 170D3032 30333034 32323038
35385A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 31383834
32373735 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100A112 A717B312 7A669E95 1F3B287F B1CE2C79 818102FA 5E766E53 336EAECD
39B90898 A9A6DAB0 218ED3CA 3693284C AA406D3C 9D468C5D C33C6CBB AC415DD4
3EAE594D 1556AD98 96CE3DAE D9865F6A 0F8B3050 770F11BB 95E90ABB 67BC6759
28F01085 E107962A 592BE7EE E9C10B3A 1E54319A 4E628AA4 9A4B7DA4 36EF7950
A2E90203 010001A3 7C307A30 0F060355 1D130101 FF040530 030101FF 30270603
551D1104 20301E82 1C6E617A 616C6164 6576692E 73746174 69737469 63732E67
6F762E67 65301F06 03551D23 04183016 80146049 E47EE7CE 0334A658 571D6088
2C678255 14D4301D 0603551D 0E041604 146049E4 7EE7CE03 34A65857 1D60882C
67825514 D4300D06 092A8648 86F70D01 01040500 03818100 8C7B22C9 DBBD2E08
916CFCA3 3879A03B 76D5E8D5 5C4F1F83 52C29B96 62FF3127 CD156227 8724CAA1
7B1C1395 64669EDD 75E09024 A6DA64A3 AE2DAF0F 7E5DDA88 0461861A A0BD8105
FF78A9BC 3B7CAAF4 1FD7D356 A13F749F A91E6546 024AC7AF D5026FE1 4AB72CC7
0F2A4424 0C329D23 3EEBD133 17130339 F74077C4 72F7C7A7
quit
username 333 privilege 15 secret 5 $1$0/4n$BCF7Dxoy5dfsdShix.Q3p0
username 33 privilege 15 secret 5 $1$rZv6$J8uQFxe/yTtDYFBB.3xa..
username 3 privilege 15 secret 5 $1$S.n0$zH6apFZJBgeTTZExMGOH2/
username 33 privilege 15 secret 5 $1$d0Zv$oecq8mgY89qKvs6/JRIRL.
!
!
!
crypto isakmp policy 30
encr aes
authentication pre-share
group 2
lifetime 3600
!
crypto isakmp client configuration group VPN_GROUP
key XXX
dns 213.131.32.34 213.131.34.2
domain reload
pool VPN_POOL
acl 130
!
!
crypto ipsec transform-set vpn esp-aes esp-sha-hmac
!
crypto dynamic-map VPN_DYNAMIC 100
set transform-set vpn
reverse-route
!
!
crypto map CM 65535 ipsec-isakmp dynamic VPN_DYNAMIC
!
crypto map VPN_CM client authentication list VPN_AUTHEN
crypto map VPN_CM isakmp authorization list VPN_AUTHOR
crypto map VPN_CM client configuration address respond
crypto map VPN_CM 10 ipsec-isakmp dynamic VPN_DYNAMIC
!
!
!
interface Tunnel0
ip address ssss
keepalive 5 4
tunnel source ssss
tunnel destination ssss
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
description $ETH-WAN$
ip address ssss
ip access-group SMTP_IN in
ip access-group SMTP_IN out
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
crypto map VPN_CM
!
interface Dot11Radio0
no ip address
shutdown
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$
ip address ssss
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1452
!
ip local pool VPN_POOL 192.168.1.1 192.168.1.99
ip classless
ip route 0.0.0.0 0.0.0.0 ssss
ip route ssss Tunnel0
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 120 interface FastEthernet4 overload
ip nat inside source list naz_nat interface FastEthernet4 overload
e
ip dns server
!
ip access-list extended naz_nat
remark SDM_ACL Category=2
permit tcp any any
permit udp any any
permit ip any any
!
access-list 120 deny ip qselis_subnet vpn-is subnet
access-list 120 permit ip qselis_subnet any
access-list 130 permit ip qselis subnet vpn-is subnet
route-map vpn permit 10
match ip address 120
!
!
ველი ფორუმის ძალის დახმარებას
* * *
უპპპპპპპპპპპპპპპ

)))
=-------------------
This post has been edited by sandroia on 10 Oct 2013, 11:28