Table 127 Ike Logs - ZyXEL Communications ZYWALL P1 User Manual

Internet security appliance
Hide thumbs Also See for ZYWALL P1:
Table of Contents

Advertisement

Chapter 22 Logs
Table 126 IPSec Logs (continued)
LOG MESSAGE
Rule [%s] sends an echo
request to peer
Rule [%s] receives an
echo reply from peer

Table 127 IKE Logs

LOG MESSAGE
Active connection allowed
exceeded
Start Phase 2: Quick Mode
Verifying Remote ID failed:
Verifying Local ID failed:
IKE Packet Retransmit
Failed to send IKE Packet
Too many errors! Deleting SA
Phase 1 IKE SA process done
Duplicate requests with the
same cookie
IKE Negotiation is in
process
No proposal chosen
Local / remote IPs of
incoming request conflict
with rule <%d>
Cannot resolve Secure
Gateway Addr for rule <%d>
Peer ID: <peer id> <My remote
type> -<My local type>
vs. My Remote <My remote> -
<My remote>
vs. My Local <My local>-<My
local>
Send <packet>
354
DESCRIPTION
The device sent a ping packet to check the specified VPN tunnel's
connectivity.
The device received a ping response when checking the specified
VPN tunnel's connectivity.
DESCRIPTION
The IKE process for a new connection failed because the limit
of simultaneous phase 2 SAs has been reached.
Phase 2 Quick Mode has started.
The connection failed during IKE phase 2 because the router
and the peer's Local/Remote Addresses don't match.
The connection failed during IKE phase 2 because the router
and the peer's Local/Remote Addresses don't match.
The router retransmitted the last packet sent because there
was no response from the peer.
An Ethernet error stopped the router from sending IKE
packets.
An SA was deleted because there were too many errors.
The phase 1 IKE SA process has been completed.
The router received multiple requests from the same peer
while still processing the first IKE packet from the peer.
The router has already started negotiating with the peer for
the connection, but the IKE process has not finished yet.
Phase 1 or phase 2 parameters don't match. Please check all
protocols / settings. Ex. One device being configured for
3DES and the other being configured for DES causes the
connection to fail.
The security gateway is set to "0.0.0.0" and the router used
the peer's "Local Address" as the router's "Remote Address".
This information conflicted with static rule #d; thus the
connection is not allowed.
The router couldn't resolve the IP address from the domain
name that was used for the secure gateway address.
The displayed ID information did not match between the two
ends of the connection.
The displayed ID information did not match between the two
ends of the connection.
The displayed ID information did not match between the two
ends of the connection.
A packet was sent. IKE uses ISAKMP to transmit data. Each
ISAKMP packet contains many different types of payloads. All
of them show in the log. Refer to
list of ISAKMP payload types.
Table 135 on page 364
for a
ZyWALL P1 User's Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents