StrongSwan与AWS VPN单方向连通故障排查请求(客户端无法ping通目标端)
StrongSwan与AWS VPN单方向连通故障排查请求(客户端无法ping通目标端)
我最近在AWS环境里搭了个StrongSwan VPN:一端是运行StrongSwan的EC2实例(账号A),另一端是绑定VPN网关的AWS VPN连接,用的是动态BGP路由。现在隧道已经UP了,但奇怪的是只能从目标EC2 ping通客户端EC2,反过来客户端ping目标端就超时,折腾了好久没找到原因,求各位帮忙排查下!
网络拓扑
- EC2 CLIENT(StrongSwan,账号A):
10.136.54.20 - AWS VPN网关(客户网关):
34.230.165.13 - EC2 DEST(目标端,账号B):
10.132.8.106
连通路径:EC2 CLIENT => VPN AWS => EC2 DEST
连通性现象
客户端(10.136.54.20)ping目标端(10.132.8.106)超时
root@ip-10-136-54-20:~# ping 10.132.8.106 PING 10.132.8.106 (10.132.8.106) 56(84) bytes of data. # 无响应,最终超时
同时在目标端抓包发现:请求源是客户端侧的BGP对等IP 169.254.48.98,且目标端已经回复了ICMP包,但客户端没收到:
root@ip-10-132-8-106:~# tcpdump -ni eth0 icmp 12:50:45.641604 IP 169.254.48.98 > 10.132.8.106: ICMP echo request, id 88, seq 113, length 64 12:50:45.641636 IP 10.132.8.106 > 169.254.48.98: ICMP echo reply, id 88, seq 113, length 64
目标端(10.132.8.106)ping客户端(10.136.54.20)正常
root@ip-10-132-8-106:~# ping 10.136.54.20 PING 10.136.54.20 (10.136.54.20) 56(84) bytes of data. 64 bytes from 10.136.54.20: icmp_seq=1 ttl=64 time=82.9 ms
StrongSwan配置(/etc/swanctl/swanctl.conf)
connections { aws_tun1 { local_addrs = 10.136.54.20 remote_addrs = 34.230.165.13 # The following is for the XFRM interface ID if_id_out = 42 if_id_in = 42 local { auth = psk id = 13.36.171.2 } remote { auth = psk id = 34.230.165.13 } children { aws_tun1 { # This allows arbitrary traffic in the tunnel from both ends local_ts = 0.0.0.0/0 remote_ts = 0.0.0.0/0 esp_proposals = aes256gcm128-modp4096 start_action = trap } } # IKE V2 -- remember this when you download the config file. version = 2 proposals = aes256-sha256-modp4096 } } secrets { ike-awstun1 { id = 34.230.165.13 secret =******* } }
IPsec状态信息
root@ip-10-136-54-20:~# ipsec statusall Status of IKE charon daemon (strongSwan 5.8.2, Linux 5.15.0-1051-aws, x86_64): uptime: 19 minutes, since Dec 15 12:37:54 2023 malloc: sbrk 2129920, mmap 0, used 1194480, free 935440 worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 3 loaded plugins: charon test-vectors ldap pkcs11 tpm aesni aes rc2 sha2 sha1 md5 mgf1 rdrand random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl gcrypt af-alg fips-prf gmp curve25519 agent chapoly xcbc cmac hmac ctr ccm gcm ntru drbg curl attr kernel-netlink resolve socket-default connmark farp stroke vici updown eap-identity eap-aka eap-md5 eap-gtc eap-mschapv2 eap-dynamic eap-radius eap-tls eap-ttls eap-peap eap-tnc xauth-generic xauth-eap xauth-pam tnc-tnccs dhcp lookip error-notify certexpire led addrblock unity counters Listening IP addresses: 10.136.54.20 10.136.54.20 169.254.48.98 Connections: aws_tun1: 10.136.54.20...34.230.165.13 IKEv2 aws_tun1: local: [13.36.171.2] uses pre-shared key authentication aws_tun1: remote: [34.230.165.13] uses pre-shared key authentication aws_tun1: child: 0.0.0.0/0 === 0.0.0.0/0 TUNNEL Routed Connections: aws_tun1{1}: ROUTED, TUNNEL, reqid 1 aws_tun1{1}: 0.0.0.0/0 === 0.0.0.0/0 Security Associations (1 up, 0 connecting): aws_tun1[1]: ESTABLISHED 19 minutes ago, 10.136.54.20[13.36.171.2]...34.230.165.13[34.230.165.13] aws_tun1[1]: IKEv2 SPIs: e5613fe092565676_i* baf6f0d76ad729c7_r, rekeying in 3 hours aws_tun1[1]: IKE proposal: AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096 aws_tun1{2}: INSTALLED, TUNNEL, reqid 1, ESP in UDP SPIs: c785164f_i c7d20def_o aws_tun1{2}: AES_GCM_16_256, 15495 bytes_i (254 pkts, 1s ago), 29445 bytes_o (416 pkts, 1s ago), rekeying in 35 minutes aws_tun1{2}: 0.0.0.0/0 === 0.0.0.0/0
客户端(10.136.54.20)IP配置
root@ip-10-136-54-20:~# ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9001 qdisc fq_codel state UP group default qlen 1000 link/ether 06:d5:c4:9b:be:f8 brd ff:ff:ff:ff:ff:ff inet 10.136.54.20/27 brd 10.136.54.31 scope global dynamic eth0 valid_lft 3594sec preferred_lft 3594sec inet6 fe80::4d5:c4ff:fe9b:bef8/64 scope link valid_lft forever preferred_lft forever 3: ipsec0@eth0: <NOARP,UP,LOWER_UP> mtu 1436 qdisc noqueue state UNKNOWN group default qlen 1000 link/none inet 10.136.54.20 peer 169.254.171.1/30 scope global ipsec0 valid_lft forever preferred_lft forever inet 169.254.48.98 peer 169.254.48.97/30 scope global ipsec0 valid_lft forever preferred_lft forever inet6 fe80::d0be:a6a1:9c8e:8574/64 scope link stable-privacy valid_lft forever preferred_lft forever
客户端(10.136.54.20)路由表
root@ip-10-136-54-20:~# ip route default via 10.136.54.1 dev eth0 proto dhcp src 10.136.54.20 metric 100 10.132.8.0/24 via 169.254.48.97 dev ipsec0 proto bird metric 32 10.136.54.0/27 dev eth0 proto kernel scope link src 10.136.54.20 10.136.54.0/27 dev eth0 proto bird scope link metric 32 10.136.54.1 dev eth0 proto dhcp scope link src 10.136.54.20 metric 100 10.136.54.20/30 dev ipsec0 proto bird scope link metric 32 169.254.48.96/30 dev ipsec0 proto kernel scope link src 169.254.48.98 169.254.48.96/30 dev ipsec0 proto bird scope link metric 32 169.254.48.97 dev ipsec0 scope link 169.254.171.0/30 dev ipsec0 proto kernel scope link src 10.136.54.20
AWS侧路由配置
- 目标端子网路由表已添加路由:
10.136.54.0/27->vgw-04ed836a1baf7acd0,状态Active
目标端(10.132.8.106)路由表
root@ip-10-132-8-106:~# netstat -arn Kernel IP routing table Destination Gateway Genmask Flags MSS Window irtt Iface 0.0.0.0 10.132.8.97 0.0.0.0 UG 0 0 0 eth0 10.132.8.2 10.132.8.97 255.255.255.255 UGH 0 0 0 eth0 10.132.8.96 0.0.0.0 255.255.255.240 U 0 0 0 eth0 10.132.8.97 0.0.0.0 255.255.255.255 UH 0 0 0 eth0
IPsec XFRM状态与策略
XFRM状态
root@ip-10-136-54-20:~# ip xfrm state src 10.136.54.20 dst 34.230.165.13 proto esp spi 0xc7d20def reqid 1 mode tunnel replay-window 0 flag af-unspec aead rfc4106(gcm(aes)) 0x0a76aa479ecbb2483c815c39bf7ea45caebf87c952cbe55ab861569008afdab1d38918e8 128 encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 anti-replay context: seq 0x0, oseq 0x17a, bitmap 0x00000000 if_id 0x2a src 34.230.165.13 dst 10.136.54.20 proto esp spi 0xc785164f reqid 1 mode tunnel replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xd97714f93418e817983e5b99aa1df8b8f9354e20217b1f622785ca6752eef8089527d6f0 128 encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 anti-replay context: seq 0xd8, oseq 0x0, bitmap 0xffffffff if_id 0x2a
XFRM策略
root@ip-10-136-54-20:~# ip xfrm policy src 10.136.54.20 dst 34.230.165.13 proto esp spi 0xc7d20def reqid 1 mode tunnel replay-window 0 flag af-unspec aead rfc4106(gcm(aes)) 0x0a76aa479ecbb2483c815c39bf7ea45caebf87c952cbe55ab861569008afdab1d38918e8 128 encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 anti-replay context: seq 0x0, oseq 0x16e, bitmap 0x00000000 if_id 0x2a src 34.230.165.13 dst 10.136.54.20 proto esp spi 0xc785164f reqid 1 mode tunnel replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xd97714f93418e817983e5b99aa1df8b8f9354e20217b1f622785ca6752eef8089527d6f0 128 enc
相关产品推荐
相关产品推荐

