You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

StrongSwan与AWS VPN单方向连通故障排查请求(客户端无法ping通目标端)

StrongSwan与AWS VPN单方向连通故障排查请求(客户端无法ping通目标端)

我最近在AWS环境里搭了个StrongSwan VPN:一端是运行StrongSwan的EC2实例(账号A),另一端是绑定VPN网关的AWS VPN连接,用的是动态BGP路由。现在隧道已经UP了,但奇怪的是只能从目标EC2 ping通客户端EC2,反过来客户端ping目标端就超时,折腾了好久没找到原因,求各位帮忙排查下!

网络拓扑

  • EC2 CLIENT(StrongSwan,账号A):10.136.54.20
  • AWS VPN网关(客户网关):34.230.165.13
  • EC2 DEST(目标端,账号B):10.132.8.106
    连通路径:EC2 CLIENT => VPN AWS => EC2 DEST

连通性现象

客户端(10.136.54.20)ping目标端(10.132.8.106)超时

root@ip-10-136-54-20:~# ping 10.132.8.106
PING 10.132.8.106 (10.132.8.106) 56(84) bytes of data.
# 无响应,最终超时

同时在目标端抓包发现:请求源是客户端侧的BGP对等IP 169.254.48.98,且目标端已经回复了ICMP包,但客户端没收到:

root@ip-10-132-8-106:~# tcpdump -ni eth0 icmp
12:50:45.641604 IP 169.254.48.98 > 10.132.8.106: ICMP echo request, id 88, seq 113, length 64
12:50:45.641636 IP 10.132.8.106 > 169.254.48.98: ICMP echo reply, id 88, seq 113, length 64

目标端(10.132.8.106)ping客户端(10.136.54.20)正常

root@ip-10-132-8-106:~# ping 10.136.54.20
PING 10.136.54.20 (10.136.54.20) 56(84) bytes of data.
64 bytes from 10.136.54.20: icmp_seq=1 ttl=64 time=82.9 ms

StrongSwan配置(/etc/swanctl/swanctl.conf)

connections {
    aws_tun1 {
        local_addrs = 10.136.54.20
        remote_addrs = 34.230.165.13
        # The following is for the XFRM interface ID
        if_id_out = 42
        if_id_in = 42
        local {
            auth = psk
            id = 13.36.171.2
        }
        remote {
            auth = psk
            id = 34.230.165.13
        }
        children {
            aws_tun1 {
                # This allows arbitrary traffic in the tunnel from both ends
                local_ts = 0.0.0.0/0
                remote_ts = 0.0.0.0/0
                esp_proposals = aes256gcm128-modp4096
                start_action = trap
            }
        }
        # IKE V2 -- remember this when you download the config file.
        version = 2
        proposals = aes256-sha256-modp4096
    }
}
secrets {
    ike-awstun1 {
        id = 34.230.165.13
        secret =*******
    }
}

IPsec状态信息

root@ip-10-136-54-20:~# ipsec statusall
Status of IKE charon daemon (strongSwan 5.8.2, Linux 5.15.0-1051-aws, x86_64):
uptime: 19 minutes, since Dec 15 12:37:54 2023
malloc: sbrk 2129920, mmap 0, used 1194480, free 935440
worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 3
loaded plugins: charon test-vectors ldap pkcs11 tpm aesni aes rc2 sha2 sha1 md5 mgf1 rdrand random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl gcrypt af-alg fips-prf gmp curve25519 agent chapoly xcbc cmac hmac ctr ccm gcm ntru drbg curl attr kernel-netlink resolve socket-default connmark farp stroke vici updown eap-identity eap-aka eap-md5 eap-gtc eap-mschapv2 eap-dynamic eap-radius eap-tls eap-ttls eap-peap eap-tnc xauth-generic xauth-eap xauth-pam tnc-tnccs dhcp lookip error-notify certexpire led addrblock unity counters
Listening IP addresses:
10.136.54.20
10.136.54.20
169.254.48.98
Connections:
aws_tun1:  10.136.54.20...34.230.165.13  IKEv2
aws_tun1:   local:  [13.36.171.2] uses pre-shared key authentication
aws_tun1:   remote: [34.230.165.13] uses pre-shared key authentication
aws_tun1:   child:  0.0.0.0/0 === 0.0.0.0/0 TUNNEL
Routed Connections:
aws_tun1{1}:  ROUTED, TUNNEL, reqid 1
aws_tun1{1}:   0.0.0.0/0 === 0.0.0.0/0
Security Associations (1 up, 0 connecting):
aws_tun1[1]: ESTABLISHED 19 minutes ago, 10.136.54.20[13.36.171.2]...34.230.165.13[34.230.165.13]
aws_tun1[1]: IKEv2 SPIs: e5613fe092565676_i* baf6f0d76ad729c7_r, rekeying in 3 hours
aws_tun1[1]: IKE proposal: AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096
aws_tun1{2}:  INSTALLED, TUNNEL, reqid 1, ESP in UDP SPIs: c785164f_i c7d20def_o
aws_tun1{2}:  AES_GCM_16_256, 15495 bytes_i (254 pkts, 1s ago), 29445 bytes_o (416 pkts, 1s ago), rekeying in 35 minutes
aws_tun1{2}:   0.0.0.0/0 === 0.0.0.0/0

客户端(10.136.54.20)IP配置

root@ip-10-136-54-20:~# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9001 qdisc fq_codel state UP group default qlen 1000
link/ether 06:d5:c4:9b:be:f8 brd ff:ff:ff:ff:ff:ff
inet 10.136.54.20/27 brd 10.136.54.31 scope global dynamic eth0
valid_lft 3594sec preferred_lft 3594sec
inet6 fe80::4d5:c4ff:fe9b:bef8/64 scope link
valid_lft forever preferred_lft forever
3: ipsec0@eth0: <NOARP,UP,LOWER_UP> mtu 1436 qdisc noqueue state UNKNOWN group default qlen 1000
link/none
inet 10.136.54.20 peer 169.254.171.1/30 scope global ipsec0
valid_lft forever preferred_lft forever
inet 169.254.48.98 peer 169.254.48.97/30 scope global ipsec0
valid_lft forever preferred_lft forever
inet6 fe80::d0be:a6a1:9c8e:8574/64 scope link stable-privacy
valid_lft forever preferred_lft forever

客户端(10.136.54.20)路由表

root@ip-10-136-54-20:~# ip route
default via 10.136.54.1 dev eth0 proto dhcp src 10.136.54.20 metric 100
10.132.8.0/24 via 169.254.48.97 dev ipsec0 proto bird metric 32
10.136.54.0/27 dev eth0 proto kernel scope link src 10.136.54.20
10.136.54.0/27 dev eth0 proto bird scope link metric 32
10.136.54.1 dev eth0 proto dhcp scope link src 10.136.54.20 metric 100
10.136.54.20/30 dev ipsec0 proto bird scope link metric 32
169.254.48.96/30 dev ipsec0 proto kernel scope link src 169.254.48.98
169.254.48.96/30 dev ipsec0 proto bird scope link metric 32
169.254.48.97 dev ipsec0 scope link
169.254.171.0/30 dev ipsec0 proto kernel scope link src 10.136.54.20

AWS侧路由配置

  • 目标端子网路由表已添加路由:10.136.54.0/27 -> vgw-04ed836a1baf7acd0,状态Active

目标端(10.132.8.106)路由表

root@ip-10-132-8-106:~# netstat -arn
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
0.0.0.0         10.132.8.97     0.0.0.0         UG        0 0          0 eth0
10.132.8.2      10.132.8.97     255.255.255.255 UGH       0 0          0 eth0
10.132.8.96     0.0.0.0         255.255.255.240 U         0 0          0 eth0
10.132.8.97     0.0.0.0         255.255.255.255 UH        0 0          0 eth0

IPsec XFRM状态与策略

XFRM状态

root@ip-10-136-54-20:~# ip xfrm state
src 10.136.54.20 dst 34.230.165.13
proto esp spi 0xc7d20def reqid 1 mode tunnel
replay-window 0 flag af-unspec
aead rfc4106(gcm(aes)) 0x0a76aa479ecbb2483c815c39bf7ea45caebf87c952cbe55ab861569008afdab1d38918e8 128
encap type espinudp sport 4500 dport 4500 addr 0.0.0.0
anti-replay context: seq 0x0, oseq 0x17a, bitmap 0x00000000
if_id 0x2a
src 34.230.165.13 dst 10.136.54.20
proto esp spi 0xc785164f reqid 1 mode tunnel
replay-window 32 flag af-unspec
aead rfc4106(gcm(aes)) 0xd97714f93418e817983e5b99aa1df8b8f9354e20217b1f622785ca6752eef8089527d6f0 128
encap type espinudp sport 4500 dport 4500 addr 0.0.0.0
anti-replay context: seq 0xd8, oseq 0x0, bitmap 0xffffffff
if_id 0x2a

XFRM策略

root@ip-10-136-54-20:~# ip xfrm policy
src 10.136.54.20 dst 34.230.165.13
proto esp spi 0xc7d20def reqid 1 mode tunnel
replay-window 0 flag af-unspec
aead rfc4106(gcm(aes)) 0x0a76aa479ecbb2483c815c39bf7ea45caebf87c952cbe55ab861569008afdab1d38918e8 128
encap type espinudp sport 4500 dport 4500 addr 0.0.0.0
anti-replay context: seq 0x0, oseq 0x16e, bitmap 0x00000000
if_id 0x2a
src 34.230.165.13 dst 10.136.54.20
proto esp spi 0xc785164f reqid 1 mode tunnel
replay-window 32 flag af-unspec
aead rfc4106(gcm(aes)) 0xd97714f93418e817983e5b99aa1df8b8f9354e20217b1f622785ca6752eef8089527d6f0 128
enc
相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 12:53:11