Frage:
Es fiel auf, dass in der Anzeige der Phase 2 der Status von Resp to Init wechselt, warum? Harmlos? Bei Neuaufbau des Tunnels?
user@PAC1(active)> show vpn ike-sa gateway T004_PH_AR
IKEv1 phase-1 SAs
GwID/client IP Peer-Address Gateway Name Role Mode Algorithm Established Expiration V ST Xt Phase2
-------------- ------------ ------------ ---- ---- --------- ----------- ---------- - -- -- ------
14 193.158.105.154 T004_PH_AR Resp Main PSK/ DH5/A256/SHA256 Nov.24 08:14:35 Nov.24 16:14:35 v1 12 4 6
Show IKEv1 IKE SA: Total 19 gateways found. 1 ike sa found.
IKEv1 phase-2 SAs
GwID/client IP Peer-Address Gateway Name Role Algorithm SPI(in) SPI(out) MsgID ST Xt
-------------- ------------ ------------ ---- --------- ------- -------- ----- -- --
14 193.158.105.154 T004_PH_AR Resp ESP/ DH5/tunl/SHA2 B2A89D16 89E5F86D 15D0A4D6 9 1
Show IKEv1 phase2 SA: Total 19 gateways found. 1 ike sa found.
user@PAC1(active)> show vpn ike-sa gateway T004_PH_AR
IKEv1 phase-1 SAs
GwID/client IP Peer-Address Gateway Name Role Mode Algorithm Established Expiration V ST Xt Phase2
-------------- ------------ ------------ ---- ---- --------- ----------- ---------- - -- -- ------
14 193.158.105.154 T004_PH_AR Resp Main PSK/ DH5/A256/SHA256 Nov.24 08:14:35 Nov.24 16:14:35 v1 12 4 5
Show IKEv1 IKE SA: Total 19 gateways found. 1 ike sa found.
IKEv1 phase-2 SAs
GwID/client IP Peer-Address Gateway Name Role Algorithm SPI(in) SPI(out) MsgID ST Xt
-------------- ------------ ------------ ---- --------- ------- -------- ----- -- --
14 193.158.105.154 T004_PH_AR Init ESP/ DH5/tunl/SHA2 CAC3C692 89E5F86C 5E70B6B5 9 1
Show IKEv1 phase2 SA: Total 19 gateways found. 1 ike sa found.