IPSec 连接已成功建立。我只能 ping 远程端点,但无法 ping 整个子网

IPSec 连接已成功建立。我只能 ping 远程端点,但无法 ping 整个子网

服务器A: 在此处输入图片描述

config setup
    charondebug="all"
    uniqueids=yes 
conn home-to-aliyun
     ikelifetime=36000s
        keylife=8h
        rekeymargin=3m
        keyingtries=5
    #    mobike=no
        lifetime=8h
        left=192.168.20.6
        leftid=221.220.135.110
        leftsubnet=192.168.20.0/24
        right=182.92.125.208
        rightsubnet=172.16.73.190/20
        keyexchange=ikev2
        authby=secret
        ike=aes256-sha2_256-modp2048
        esp=aes256-sha2_256
        dpddelay=30
        dpdtimeout=120
        dpdaction=restart
        auto=start
        type=tunnel

服务器B: 在此处输入图片描述

config setup
    charondebug="all"
    #charondebug="ike 2, knl 2, cfg 2, net 2, esp 2, dmn 2"
    uniqueids=yes 
conn aliyun-to-home
        ikelifetime=36000s
        keylife=8h
        rekeymargin=3m
        keyingtries=5
#       mobike=no
        lifetime=8h
        left=172.16.73.190
        leftid=182.92.125.208
        leftsubnet=172.16.73.0/24
        right=221.220.135.110
        rightsubnet=192.168.20.190/20
        keyexchange=ikev2
        authby=secret
        ike=aes256-sha2_256-modp2048
        esp=aes256-sha2_256
        dpddelay=30
        dpdtimeout=120
        dpdaction=restart
        auto=start
        type=tunnel 

无法 ping 通整个子网。 在此处输入图片描述

相关内容