有没有抓包看一下ISAKMP SA报文是否确实没有收到? 另外VPN peer两端的IKE和IPsec参数要设置的一致。可以参考以下说明,检查下两端的配置: Cisco Meraki devices have the following requirements for their VPN connections to non-Meraki peers: Preshared keys (no certificates). LAN static routes (no routing protocol for the VPN interface). IKEv1 (IKEv2 not supported) in Main Mode (aggressive mode not supported). Access through UDP ports 500 and 4500.
The following IKE and IPsec parameters are the default settings used by the MX: Phase 1 (IKE Policy): 3DES, SHA1, DH group 2, lifetime 8 hours (28800 seconds). Phase 2 (IPsec Rule): Any of 3DES or AES; either MD5 or SHA1; PFS disabled; lifetime 8 hours (28800 seconds).