发布修改后的配置。
在屏幕允许的范围内打开命令行窗口/tool sniffer quick ip-protocol=icmp ip-address=192.168.0.0/16在其中,并尝试从一个microtik ping到另一个的局域网地雷竞技网站址。如果ping请求逃过了IPsec策略,您应该可以看到源Mikrotik上的ping请求,如果它雷竞技网站们被策略捕获,则不会被看到。在目标Mikrotik上,如果请求是通雷竞技网站过IPsec隧道来的,您应该看到请求,但是如果策略捕获了它们,则不会看到响应。
所以它似乎到达了对面的路由器,也可能到达了远端的设备,却没有得到回复。参考嗅探器回复
位于(192.168.20.1)
从192.168.20.254 Ping到192.168.60.250 -错误无应答
> tool sniffer quick ip协议=icmp ip地址=192.168.0.0/16
接口时间序号dir src-mac dst-mac vlan src-address dst-address协议大小CPU fp
以太3 5.86 1 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no . 0
网桥5.86 2 <- BC:5F:F4:D7:6D: 252c:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
以太3 10.374 3 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no . 0
网桥10.374 4 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
以太3 15.376 5 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no . 0
网桥15.376 6 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
以太3 20.374 7 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no . 0
网桥20.374 8 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
从192.168.20.254 Ping到192.168.60.21 -成功
> tool sniffer quick ip协议=icmp ip地址=192.168.0.0/16
接口时间序号dir src-mac dst-mac vlan src-address dst-address协议大小CPU fp
以太3 2.051 1 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
<- BC:5F:F4:D7:6D: 252c:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太1 2.118 3 <- 88:F8:72:22:74:54 2C:C8:1B:78:53:89 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥2.118 4 -> 2C:C8:1B:78:53:8A BC:5F:F4:D7:6D:25 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
以太3 3.068 5 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no .0
网桥3.068 6 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太1 3.133 7 <- 88:F8:72:22:74:54 2C:C8:1B:78:53:89 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥3.133 8 -> 2C:C8:1B:78:53:8A BC:5F:F4:D7:6D:25 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
以太3 4.076 9 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no .0
网桥4.076 10 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太1 4.15 11 <- 88:F8:72:22:74:54 2C:C8:1B:78:53:89 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥4.15 12 -> 2C:C8:1B:78:53:8A BC:5F:F4:D7:6D:25 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
以太3 5.082 13 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no .0
网桥5.082 14 <- BC:5F:F4:D7:6D:25 2C:C8:1B:78:53:8A 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太1 5.145 15 <- 88:F8:72:22:74:54 2C:C8:1B:78:53:89 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
bridge 5.145 16 -> 2C:C8:1B:78:53:8A BC:5F:F4:D7:6D:25 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
ROUTER2 (192.168.60.1)
从192.168.20.254 Ping到192.168.60.250 -错误无应答
> tool sniffer quick ip协议=icmp ip地址=192.168.0.0/16
接口时间序号dir src-mac dst-mac vlan src-address dst-address协议大小CPU fp
网桥2.652 1 -> 48:8F:5A: 35:41:22 f 1C:69:7A:02:33:40 192.168.8.101 192.168.60.4 ip:icmp 149 0 no
2 <- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
网桥4.139 3 -> 48:8F:5A:35:41:2F 00:01:6C:D6:95:97 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
以太1 8.647 4 <- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
网桥8.647 5 -> 48:8F:5A:35:41:2F 00:01:6C:D6:95:97 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
网桥12.802 6 -> 48:8F:5A:35:41:2F 1C:69:7A:02:33:40 192.168.8.101 192.168.60.4 ip:icmp 149 0 no
网桥13.262 7 -> 48:8F:5A: 35:41:22 f 1C:69:7A:02:B2:86 192.168.8.101 192.168.60.5 ip:icmp 149 0 no
以太1 13.658 8 <- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
网桥13.658 9 -> 48:8F:5A:35:41:2F 00:01:6C:D6:95:97 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
以太1 18.656 10 <- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
网桥18.656 11 -> 48:8F:5A:35:41:2F 00:01:6C:D6:95:97 192.168.20.254 192.168.60.250 ip:icmp 74 0 no
网桥24.172 12 -> 48:8F:5A: 35:41:22 f 1C:69:7A:02:B2:86 192.168.8.101 192.168.60.5 ip:icmp 149 0 no
从192.168.20.254 Ping到192.168.60.21 -成功
> tool sniffer quick ip协议=icmp ip地址=192.168.0.0/16
接口时间序号dir src-mac dst-mac vlan src-address dst-address协议大小CPU fp
网桥3.561 1 -> 48:8F:5A:35:41:2F 1C:69:7A:02:33:40 192.168.8.101 192.168.60.4 ip:icmp 149 0 no
<- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
网桥3.756 3 -> 48:8F:5A:35:41:2F 50:57:9C:62:7E:B1 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太2 3.758 4 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥3.758 5 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
以太1 4.787 6 <- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
网桥4.787 7 -> 48:8F:5A:35:41:2F 50:57:9C:62:7E:B1 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太2 4.79 8 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥4.79 9 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
以太1 5.793 10 <- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
网桥5.793 11 -> 48:8F:5A:35:41:2F 50:57:9C:62:7E:B1 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太2 5.797 12 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥5.797 13 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
<- 24:31:54:16:6A:59 48:8F:5A:35:41:2E 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
网桥6.793 15 -> 48:8F:5A:35:41:2F 50:57:9C:62:7E:B1 192.168.20.254 192.168.60.21 ip:icmp 74 0 no
以太2 6.796 16 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥6.796 17 <- 50:57:9C:62:7E:B1 48:8F:5A:35:41:2F 192.168.60.21 192.168.20.254 ip:icmp 74 0 no
网桥13.811 18 -> 48:8F:5A:35:41:2F 1C:69:7A:02:33:40 192.168.8.101 192.168.60.4 ip:icmp 149 0 no
从192.168.60.1 Ping到192.168.60.250 -成功
> tool sniffer quick ip协议=icmp ip地址=192.168.0.0/16
接口时间序号dir src-mac dst-mac vlan src-address dst-address协议大小CPU fp
网桥2.851 3 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥3.855 4 -> 48:8F:5A:35:41:2F 00:01:6C:D6:95:97 192.168.60.1 192.168.60.250 ip:icmp 70 0 no
以太2 3.856 5 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥3.856 6 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥4.861 7 -> 48:8F:5A: 35:41:20 f 00:01:6C:D6:95:97 192.168.60.1 192.168.60.250 ip:icmp 70 0 no
以太2 4.861 8 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥4.861 9 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥5.864 10 -> 48:8F:5A: 35:41:20 f 00:01:6C:D6:95:97 192.168.60.1 192.168.60.250 ip:icmp 70 0 no
ether2 5.864 11 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥5.864 12 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
网桥6.868 13 -> 48:8F:5A: 35:41:20 f 00:01:6C:D6:95:97 192.168.60.1 192.168.60.250 ip:icmp 70 0 no
以太2 6.868 14 <- 00:01:6C:D6:95:97 48:8F:5A:35:41:2F 192.168.60.250 192.168.60.1 ip:icmp 70 0 no
谢谢你的帮助。