Figure 210 Example Vpn Responder Ipsec Log; Table 106 Sample Ike Key Exchange Logs - ZyXEL Communications P-202H V2 User Manual

Isdn internet access router
Hide thumbs Also See for P-202H V2:
Table of Contents

Advertisement

P-202H Plus v2 User's Guide

Figure 210 Example VPN Responder IPSec Log

Index:
------------------------------------------------------------
001
002
003
004
005
006
007
008
009
010
011
012
Clear IPSec Log (y/n):
This menu is useful for troubleshooting. A log index number, the date and time the log was
created and a log message are displayed.
Note: Double exclamation marks (!!) denote an error or warning message.
The following table shows sample log messages during IKE key exchange.

Table 106 Sample IKE Key Exchange Logs

LOG MESSAGE
Cannot find outbound SA for rule <#d>
Send Main Mode request to <IP>
Send Aggressive Mode request to <IP>
Recv Main Mode request from <IP>
Recv Aggressive Mode request from <IP>
Send:<Symbol><Symbol>
Recv:<Symbol><Symbol>
Phase 1 IKE SA process done
Start Phase 2: Quick Mode
!! IKE Negotiation is in process
!! Duplicate requests with the same
cookie
315
Date/Time:
01 Jan 08:08:07
Recv Main Mode request from <192.168.100.100>
01 Jan 08:08:07
Recv:<SA>
01 Jan 08:08:08
Send:<SA>
01 Jan 08:08:08
Recv:<KE><NONCE>
01 Jan 08:08:10
Send:<KE><NONCE>
01 Jan 08:08:10
Recv:<ID><HASH>
01 Jan 08:08:10
Send:<ID><HASH>
01 Jan 08:08:10
Phase 1 IKE SA process done
01 Jan 08:08:10
Recv:<HASH><SA><NONCE><ID><ID>
01 Jan 08:08:10
Start Phase 2: Quick Mode
01 Jan 08:08:10
Send:<HASH><SA><NONCE><ID><ID>
01 Jan 08:08:10
Recv:<HASH>
Log:
DESCRIPTION
The packet matches the rule index number (#d), but
Phase 1 or Phase 2 negotiation for outbound (from the
VPN initiator) traffic is not finished yet.
The ZyXEL Device has started negotiation with the peer.
The ZyXEL Device has received an IKE negotiation
request from the peer.
IKE uses the ISAKMP protocol (refer to RFC2408 -
ISAKMP) to transmit data. Each ISAKMP packet contains
payloads of different types that show in the log - see
Table 108 on page
317.
Phase 1 negotiation is finished.
Phase 2 negotiation is beginning using Quick Mode.
The ZyXEL Device has begun negotiation with the peer for
the connection already, but the IKE key exchange has not
finished yet.
The ZyXEL Device has received multiple requests from
the same peer but it is still processing the first IKE packet
from that peer.
Chapter 35 IPSec Log

Advertisement

Table of Contents
loading

This manual is also suitable for:

P-202u

Table of Contents