This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site-to-Site Tunnel mit IPSec - Durchsatz nur 4 kB/s

Hallo zusammen,

ich habe zwischen zwei Standorten mit einer SG115 und SG135 eine IPSec Verbindung über IPv6 eingerichtet. Ein Anschluß hat 100Mbit/s Down/Up und der andere hat 200Mbit down/up. Ein ping zwischen beiden UTM's dauert ca. 8ms. Das Einbinden von Freigaben und anschließende Kopieren dauert ewig. Es werden nur 4 kB/s angezeigt.

Leider habe ich keine Idee mehr, wo ich ansetzen soll.

 

Übersicht der IPSec VErbindung in der Site-to-Site Übersicht:

SA: 192.168.30.0/24=2a00:xxxxx   2a00:xxxxx=192.168.1.0/24
VPN ID: 2a00:xxxxxx
IKE: Auth PSK / Enc AES_CBC_256 / Hash HMAC_MD5 / Lifetime 7800s / DPD
ESP: Enc AES_CBC_256 / Hash HMAC_MD5 / Lifetime 3600s
 
   

 

 

Danke!



This thread was automatically locked due to age.
Parents
  • Im Logfile ipsec.log steht noch folgendes

    <pre>

    2018:07:17-20:36:12 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1441: starting keying attempt 1392 of an unlimited number
    2018:07:17-20:36:12 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1442: initiating Quick Mode PSK+ENCRYPT+TUNNEL+UP to replace #1441 {using isakmp#13
    43}
    2018:07:17-20:36:12 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1343: ignoring informational payload, type INVALID_ID_INFORMATION
    2018:07:17-20:36:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1343: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: initiating Main Mode to replace #1343
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [strongSwan]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring Vendor ID payload [Cisco-Unity]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [XAUTH]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [Dead Peer Detection]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [RFC 3947]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: enabling possible NAT-traversal with method 3
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: NAT-Traversal: Result using RFC 3947: no NAT detected
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: Peer ID is ID_IPV6_ADDR: 'xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx'
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: Dead Peer Detection (RFC 3706) enabled
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ISAKMP SA established
    2018:07:17-20:36:42 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1343: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1442: max number of retransmissions (2) reached STATE_QUICK_I1.  No acceptable resp
    onse to our first Quick Mode message: perhaps peer likes no proposal
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1442: starting keying attempt 1393 of an unlimited number
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1444: initiating Quick Mode PSK+ENCRYPT+TUNNEL+UP to replace #1442 {using isakmp#14
    43}
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring informational payload, type INVALID_ID_INFORMATION
    2018:07:17-20:37:32 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:37:52 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:38:32 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1444: max number of retransmissions (2) reached STATE_QUICK_I1.  No acceptable resp
    onse to our first Quick Mode message: perhaps peer likes no proposal

    </pre>

Reply
  • Im Logfile ipsec.log steht noch folgendes

    <pre>

    2018:07:17-20:36:12 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1441: starting keying attempt 1392 of an unlimited number
    2018:07:17-20:36:12 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1442: initiating Quick Mode PSK+ENCRYPT+TUNNEL+UP to replace #1441 {using isakmp#13
    43}
    2018:07:17-20:36:12 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1343: ignoring informational payload, type INVALID_ID_INFORMATION
    2018:07:17-20:36:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1343: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: initiating Main Mode to replace #1343
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [strongSwan]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring Vendor ID payload [Cisco-Unity]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [XAUTH]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [Dead Peer Detection]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: received Vendor ID payload [RFC 3947]
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: enabling possible NAT-traversal with method 3
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: NAT-Traversal: Result using RFC 3947: no NAT detected
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: Peer ID is ID_IPV6_ADDR: 'xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx'
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: Dead Peer Detection (RFC 3706) enabled
    2018:07:17-20:36:37 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ISAKMP SA established
    2018:07:17-20:36:42 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1343: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1442: max number of retransmissions (2) reached STATE_QUICK_I1.  No acceptable resp
    onse to our first Quick Mode message: perhaps peer likes no proposal
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1442: starting keying attempt 1393 of an unlimited number
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1444: initiating Quick Mode PSK+ENCRYPT+TUNNEL+UP to replace #1442 {using isakmp#14
    43}
    2018:07:17-20:37:22 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring informational payload, type INVALID_ID_INFORMATION
    2018:07:17-20:37:32 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:37:52 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1443: ignoring informational payload, type INVALID_MESSAGE_ID
    2018:07:17-20:38:32 sg115 pluto[16946]: "S_REF_IpsSitAtoB_0" #1444: max number of retransmissions (2) reached STATE_QUICK_I1.  No acceptable resp
    onse to our first Quick Mode message: perhaps peer likes no proposal

    </pre>

Children