修复“192-SHA1(2)_160 pfsgroup=no-pfs” 报错

这是与 openswan 配置相关的错误。

启动并运行 ipsec 后,在尝试连接到 vpn 时,我们可能会收到此错误。

002 "sonicwall" #2: initiating Quick Mode
PSK+ENCRYPT+TUNNEL+UP+AGGRESSIVE+IKEv2ALLOW+SAREFTRACK {using isakmp#1 msgid:a0d6gf93 proposal=3DES(3)_192-SHA1(2)_160 pfsgroup=no-pfs}
117 "sonicwall" #2: STATE_QUICK_I1: initiate
010 "sonicwall" #2: STATE_QUICK_I1: retransmission; will wait 20s for response

解决方案:

检查 ipsec.conf 文件并确保 pfs=yes

# vi /etc/ipsec.conf
pfs=yes

重新启动 ipsec 服务

# service ipsec restart
# ipsec auto --replace sonicwall
# ipsec whack --name sonicwall --initiate

如果连接成功,它应该显示如下内容

004 "sonicwall" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0x85c33bdf <0xa66ae231 xfrm=3DES_0-HMAC_SHA1 NATOA=none NATD=none DPD=none}
日期:2020-06-02 22:16:46 来源:oir作者:oir