Изменил настройки srx на policy based. тунели стали подыматься, но теперь вижу вот такую картину(т.е. я вижу как пакеты идут по тунели, и вижу icmp ответ, но я не вижу icmp запроса).13:56:15.734788 IP 1.1.1.1 > 2.2.2.2: ESP(spi=0xf940ed0a,seq=0x6), length 116
13:56:15.746447 IP 2.2.2.2 > 1.1.1.1: ESP(spi=0x0ee3a0c8,seq=0x6), length 116
13:56:15.746447 IP 192.168.2.55 > 192.168.99.11: ICMP echo reply, id 19396, seq 1, length 64
13:56:16.734317 IP 1.1.1.1 > 2.2.2.2: ESP(spi=0xf940ed0a,seq=0x7), length 116
13:56:16.738489 IP 2.2.2.2 > 1.1.1.1: ESP(spi=0x0ee3a0c8,seq=0x7), length 116
13:56:16.738489 IP 192.168.2.55 > 192.168.99.11: ICMP echo reply, id 19396, seq 2, length 64
13:56:17.734317 IP 1.1.1.1 > 2.2.2.2: ESP(spi=0xf940ed0a,seq=0x8), length 116
13:56:17.738459 IP 2.2.2.2 > 1.1.1.1: ESP(spi=0x0ee3a0c8,seq=0x8), length 116
13:56:17.738459 IP 192.168.2.55 > 192.168.99.11: ICMP echo reply, id 19396, seq 3, length 64
setkey.conf
flush;
spdflush;
spdadd 192.168.99.0/24 192.168.1.0/24 any -P out ipsec
esp/tunnel/1.1.1.1-217.10.42.121/require;
spdadd 192.168.1.0/24 192.168.99.0/24 any -P in ipsec
esp/tunnel/217.10.42.121-1.1.1.1/require;
setkey -D
1.1.1.1 2.2.2.2
esp mode=tunnel spi=4181781770(0xf940ed0a) reqid=0(0x00000000)
E: 3des-cbc 7b9b0e6e a3bba5a0 2f0e52fd 91717f52 7f032adc d238f2b5
A: hmac-sha1 21bb31f4 48899140 278e5fbc 78d2fe89 132bf71b
seq=0x00000000 replay=4 flags=0x00000000 state=dying
created: Jul 27 13:08:47 2011 current: Jul 27 14:01:50 2011
diff: 3183(s) hard: 3600(s) soft: 2880(s)
last: Jul 27 13:40:25 2011 hard: 0(s) soft: 0(s)
current: 672(bytes) hard: 0(bytes) soft: 0(bytes)
allocated: 8 hard: 0 soft: 0
sadb_seq=5 pid=19440 refcnt=0
2.2.2.2 1.1.1.1
esp mode=tunnel spi=249798856(0x0ee3a0c8) reqid=0(0x00000000)
E: 3des-cbc 177dd4cf ae881962 f1179963 2ca65a07 3931788c 85d9c63b
A: hmac-sha1 d96b321a 28883a68 28a94099 5caacbee a0d06ff1
seq=0x00000000 replay=4 flags=0x00000000 state=dying
created: Jul 27 13:08:47 2011 current: Jul 27 14:01:50 2011
diff: 3183(s) hard: 3600(s) soft: 2880(s)
last: Jul 27 13:40:25 2011 hard: 0(s) soft: 0(s)
current: 672(bytes) hard: 0(bytes) soft: 0(bytes)
allocated: 8 hard: 0 soft: 0
sadb_seq=6 pid=19440 refcnt=0
ifconfig
[root@d142 ~]# ifconfig
eth0 Link encap:Ethernet HWaddr 00:25:90:04:71:D4
inet addr:1.1.1.1 Bcast:188.93.209.255 Mask:255.255.254.0
inet6 addr: fe80::225:90ff:fe04:71d4/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:6277950 errors:0 dropped:0 overruns:0 frame:0
TX packets:241614 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3132455022 (2.9 GiB) TX bytes:32370004 (30.8 MiB)
Interrupt:16 Memory:fb5e0000-fb600000
eth0:1 Link encap:Ethernet HWaddr 00:25:90:04:71:D4
inet addr:188.93.209.6 Bcast:188.93.209.255 Mask:255.255.254.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
Interrupt:16 Memory:fb5e0000-fb600000
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:309701 errors:0 dropped:0 overruns:0 frame:0
TX packets:309701 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:64353374 (61.3 MiB) TX bytes:64353374 (61.3 MiB)
tap0 Link encap:Ethernet HWaddr B2:88:14:2C:0C:B0
inet addr:192.168.99.11 Bcast:192.168.99.255 Mask:255.255.255.0
inet6 addr: fe80::b088:14ff:fe2c:cb0/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:10950 errors:0 dropped:0 overruns:0 frame:0
TX packets:10 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1231929 (1.1 MiB) TX bytes:700 (700.0 b)