在MSR的debug中,有如下提示
*Oct 12 23:11:41:078 2015 MSR3610 IKE/7/Error: Failed to get IPsec policy for phase 2 responder. Delete IPsec SA.
*Oct 12 23:11:41:078 2015 MSR3610 IKE/7/Error: Failed to negotiate IPsec SA.
*Oct 12 23:11:41:078 2015 MSR3610 IKE/7/Event: Delete IPsec SA.
*Oct 12 23:11:41:078 2015 MSR3610 IKE/7/Packet: Encrypt the packet.
*Oct 12 23:11:41:078 2015 MSR3610 IKE/7/Packet: Construct notification packet: INVALID_ID_INFORMATION.
提示通过第二阶段响应者的信息查找IPSEC POLICY失败。
因此怀疑是配置问题。
检查MSR3620上关于IPSEC的配置,发现IPSEC POLICY中未指定local-address、remote-address 。
增加该配置后,IPSEC建立成功。
非模板方式时ipsec策略下必须配置remote-address
在MSR3620的IPSEC POLICY中指定local-address、remote-address 。