|
我在fedora core 4下设置setkey。可为什么一设置策略,两台机子就ping不通?包丢失100%。
setkey.conf配置如下:
flush;
spdflush;
add 218.196.195.251 218.196.195.252 ah 0x200 -A hmac-md5
0xc0291ff014dccdd03874d9e8e4cdf3e6;
add 218.196.195.252 218.196.195.251 ah 0x300 -A hmac-md5
0x96358c90783bbfa3d7b196ceabe0536b;
add 218.196.195.251 218.196.195.252 esp 0x201 -E 3des-cbc
0x7aeaca3f87d060a12f4a4487d5a5c3355920fae69a96c831;
add 218.196.195.252 218.196.195.251 esp 0x301 -E 3des-cbc
0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965df;
spdadd 218.196.195.251 218.196.195.252 any -P out ipsec
esp/transport//require
ah/transport//require;
spdadd 218.196.195.252 218.196.195.251 any -P in ipsec
esp/transport//require
ah/transport//require; |
|