- होम
- मल्टी-क्लाउड नेटवर्किंग
- Customer Edge diagnostics
- Command reference
- Network commands
- IPsec
IPsec
CE, F5 क्षेत्रीय एजों पर IPsec टनल बनाता है। यदि वे डाउन हैं, तो साइट वैश्विक नेटवर्क से अलग हो जाती है, चाहे स्थानीय रूप से वह कितनी भी स्वस्थ दिखे।
ipsec-status
Section titled “ipsec-status”{"command":["ipsec-status"]}Security Associations (2 up, 0 connecting):ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io]ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: INSTALLED, TUNNEL, reqid 65542, ESP in UDP SPIs: ffff1700_i ffffce10_over.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: 10.0.1.4/32 === <public-ip>/32ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io]ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: INSTALLED, TUNNEL, reqid 65541, ESP in UDP SPIs: ffff1160_i ffff1e70_over.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: 10.0.1.4/32 === <public-ip>/32पहली पंक्ति ही उत्तर है: Security Associations (2 up, 0 connecting)। connecting
में जो भी है, वह एक ऐसा टनल है जो प्रयास कर रहा है और विफल हो रहा है।
प्रत्येक SA उस क्षेत्रीय एज का नाम देता है जिस पर वह समाप्त होता है — ny8-nyc, dc12-ash
F5 POP कोड हैं — इसलिए यह आपको यह भी बताता है कि साइट किन एजों से जुड़ी है।
किसी आयु के साथ ESTABLISHED, और उसके बाद INSTALLED, TUNNEL, एक स्वस्थ जोड़ी है:
पहला IKE सत्र है, दूसरा चाइल्ड SA जो वास्तव में ट्रैफ़िक वहन करता है। बिना
किसी स्थापित चाइल्ड SA के स्थापित IKE सत्र एक उल्लेखनीय विफलता है।
ipsec-statusall
Section titled “ipsec-statusall”वही जानकारी साथ में प्रति-SA बाइट और पैकेट काउंटर, रीकी टाइमर और परक्राम्य एल्गोरिदम के साथ।
{"command":["ipsec-statusall"]}Status of IKE charon daemon (strongSwan 5.9.13, Linux 5.14.0-687.20.1.el9_8.x86_64, x86_64): uptime: 78 minutes, since Aug 03 15:12:39 2026 malloc: sbrk 3428352, mmap 0, used 2019536, free 1408816 worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 20 loaded plugins: charon aes des rc2 sha2 sha1 mgf1 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs12 pgp dnskey sshkey pem openssl pkcs8 fips-prf gmp curve25519 xcbc cmac hmac kdf gcm drbg attr kernel-pb kernel-netlink resolve socket-default stroke vici updown xauth-generic error-notify countersListening IP addresses: 10.0.2.4 10.0.3.4 100.64.255.1 10.0.1.4 169.254.100.1 169.254.10.13 169.254.254.103Connections:ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: 10.0.1.4[4500]...<public-ip>[4500] IKEv1/2, dpddelay=3sver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: local: [ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io] uses any authenticationver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: cert: "O=Volterra, OU=ves-system, CN=ike"ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: remote: [ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io] uses any authenticationver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: child: dynamic === 0.0.0.0/0 TUNNEL, dpdaction=startver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: 10.0.1.4[4500]...<public-ip>[4500] IKEv1/2, dpddelay=3sver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: local: [ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io] uses any authenticationver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: cert: "O=Volterra, OU=ves-system, CN=ike"ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: remote: [ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io] uses any authenticationver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: child: dynamic === 0.0.0.0/0 TUNNEL, dpdaction=startSecurity Associations (2 up, 0 connecting):ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io]ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: IKEv2 SPIs: 82b18316b81c76c1_i* 4a79a978d19b3304_r, any reauthentication in 2 hoursver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: IKE proposal: AES_GCM_16_128/PRF_HMAC_SHA2_256/MODP_3072ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: INSTALLED, TUNNEL, reqid 65542, ESP in UDP SPIs: ffff1700_i ffffce10_over.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: AES_GCM_16_128, 0 bytes_i, 0 bytes_o, rekeying disabledver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: 10.0.1.4/32 === <public-ip>/32ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io]ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: IKEv2 SPIs: 7ec7d8a8178881fb_i* e683f63a81425ff5_r, any reauthentication in 2 hoursver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: IKE proposal: AES_GCM_16_128/PRF_HMAC_SHA2_256/MODP_3072ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: INSTALLED, TUNNEL, reqid 65541, ESP in UDP SPIs: ffff1160_i ffff1e70_over.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: AES_GCM_16_128, 0 bytes_i, 0 bytes_o, rekeying disabledver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: 10.0.1.4/32 === <public-ip>/32इसका उपयोग “टनल चालू है” और “टनल ट्रैफ़िक वहन कर रहा है” के बीच अंतर करने के लिए करें। घंटों से स्थापित टनल जिसमें लगभग शून्य बाइट हैं, वह चालू तो है लेकिन अप्रयुक्त है, जिसका सामान्यतः अर्थ है कि समस्या टनल की बजाय रूटिंग में है।