Table 243 Ipsec Logs - ZyXEL Communications Unified Security Gateway ZyWALL 1000 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 1000:
Table of Contents

Advertisement

Table 242 IKE Logs (continued)
LOG MESSAGE
Tunnel [%s:%s]
Sending IKE request
Tunnel [%s:0x%x] is
disconnected
Tunnel [%s] rekeyed
successfully

Table 243 IPSec Logs

LOG MESSAGE
Corrupt packet,
Inbound transform
operation fail
Encapsulated packet
too big with length
Get inbound transform
fail
Get outbound transform
fail
Inbound transform
operation fail
Outbound transform
operation fail
Packet too big with
Fragment Off
SPI:0x%x SEQ:0x%x
Execute transform step
fail, ret=%d
SPI:0x%x SEQ:0x%x No
rule found, Dropping
packet
SPI:0x%x SEQ:0x%x
Packet Anti-Replay
detected
VPN connection %s was
disabled.
VPN connection %s was
enabled.
ZyWALL USG 1000 User's Guide
DESCRIPTION
The variables represent the phase 1 name and tunnel name. The
device sent an IKE request.
The variables represent the tunnel name and the SPI of a tunnel that
was disconnected.
%s is the tunnel name. The tunnel was rekeyed successfully.
DESCRIPTION
The device received corrupt IPsec packets and could not process
them.
An outgoing packet needed to be transformed but was longer than
65535.
When performing inbound processing for incoming IPSEC packets and
ICMPs related to them, the engine cannot obtain the transform
context.
When outgoing packet need to be transformed, the engine cannot
obtain the transform context.
After encryption or hardware accelerated processing, HWAccel
dropped packet (resource shortage, corrupt packet, invalid MAC, and
so on).
After encryption or hardware accelerated processing, Hwaccel
dropped packet (e.g., resource overflow, corrupt packet, and so on).
An outgoing packet needed to be transformed, but the fragment flag
was off and the packet was too big.
The variables represent the SPI, sequence number and the error
number. When trying to perform transforming, the engine returned an
error.
The variables represent the SPI and the sequence number. The
packet did not match the tunnel policy and was dropped.
The variables represent the SPI and the sequence number. The device
received a packet again (that it had already received).
%s is the VPN connection name. An administrator disabled the VPN
connection.
%s is the VPN connection name. An administrator enabled the VPN
connection.
Appendix B Log Descriptions
679

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents