Table 153 Ipsec Logs; Table 154 Ike Logs - ZyXEL Communications P-660H-D Series User Manual

Adsl 2+ gateway
Hide thumbs Also See for P-660H-D Series:
Table of Contents

Advertisement

Table 153 IPSec Logs

LOG MESSAGE
Discard REPLAY packet
Inbound packet
authentication failed
Receive IPSec packet,
but no corresponding
tunnel exists
Rule <%d> idle time out,
disconnect
WAN IP changed to <IP>

Table 154 IKE Logs

LOG MESSAGE
Active connection allowed
exceeded
Start Phase 2: Quick Mode
Verifying Remote ID failed:
Verifying Local ID failed:
IKE Packet Retransmit
Failed to send IKE Packet
Too many errors! Deleting SA
Phase 1 IKE SA process done
Duplicate requests with the
same cookie
IKE Negotiation is in process The router has already started negotiating with the peer for
No proposal chosen
Local / remote IPs of
incoming request conflict
with rule <%d>
Appendix M Log Descriptions
DESCRIPTION
The router received and discarded a packet with an incorrect
sequence number.
The router received a packet that has been altered. A third party may
have altered or tampered with the packet.
The router dropped an inbound packet for which SPI could not find a
corresponding phase 2 SA.
The router dropped a connection that had outbound traffic and no
inbound traffic for a certain time period. You can use the "ipsec timer
chk_conn" CI command to set the time period. The default value is 2
minutes.
The router dropped all connections with the "MyIP" configured as
"0.0.0.0" when the WAN IP address changed.
DESCRIPTION
The IKE process for a new connection failed because the limit
of simultaneous phase 2 SAs has been reached.
Phase 2 Quick Mode has started.
The connection failed during IKE phase 2 because the router
and the peer's Local/Remote Addresses don't match.
The connection failed during IKE phase 2 because the router
and the peer's Local/Remote Addresses don't match.
The router retransmitted the last packet sent because there
was no response from the peer.
An Ethernet error stopped the router from sending IKE
packets.
An SA was deleted because there were too many errors.
The phase 1 IKE SA process has been completed.
The router received multiple requests from the same peer
while still processing the first IKE packet from the peer.
the connection, but the IKE process has not finished yet.
Phase 1 or phase 2 parameters don't match. Please check all
protocols / settings. Ex. One device being configured for
3DES and the other being configured for DES causes the
connection to fail.
The security gateway is set to "0.0.0.0" and the router used
the peer's "Local Address" as the router's "Remote Address".
This information conflicted with static rule #d; thus the
connection is not allowed.
P-660R/H-D Series User's Guide
402

Advertisement

Table of Contents
loading

Table of Contents