Table 75 Sample Ike Key Exchange Logs - Nortel BCM50a Configuration Manual

Integrated router
Table of Contents

Advertisement

300 Appendix J Log descriptions

Table 75 Sample IKE key exchange logs

Log Message
Send <Symbol> Mode request to
<IP>Send <Symbol> Mode
request to <IP>
Recv <Symbol> Mode request
from <IP>Recv <Symbol> Mode
request from <IP>
Recv:<Symbol>
Phase 1 IKE SA process done
Start Phase 2: Quick Mode
!! IKE Negotiation is in
process
!! Duplicate requests with
the same cookie
!! No proposal chosen
!! Verifying Local ID
failed!! Verifying Remote ID
failed
!! Local / remote IPs of
incoming request conflict
with rule <#d>
!! Invalid IP <IP start>/<IP
end>
!! Remote IP <IP start> / <IP
end> conflicts
N0115791
Description
The BCM50a Integrated Router has started
negotiation with the peer.
The BCM50a Integrated Router has received an IKE
negotiation request from the peer.
IKE uses the ISAKMP protocol (refer to RFC2408 –
ISAKMP) to transmit data. Each ISAKMP packet
contains payloads of different types that show in the
log (see
Table
77).
Phase 1 negotiation is finished.
Phase 2 negotiation is beginning using Quick Mode.
The BCM50a Integrated Router has begun
negotiation with the peer for the connection already,
but the IKE key exchange is not finished yet.
The BCM50a Integrated Router has received
multiple requests from the same peer but it is still
processing the first IKE packet from that peer.
The parameters configured for Phase 1 or Phase 2
negotiations do not match. Check all protocols and
settings for these phases. For example, one party is
using 3DES encryption, but the other party is using
DES encryption, so the connection fails.
During IKE Phase 2 negotiation, both parties
exchange policy details, including local and remote
IP address ranges. If these ranges differ, the
connection fails.
If the security gateway is 0.0.0.0, the BCM50a
Integrated Router uses the peer Local Addr as its
Remote Addr. If this IP (range) conflicts with a
previously configured rule then the connection is not
allowed.
The Local IP Addr range for the peer is invalid.
If the security gateway is 0.0.0.0, the BCM50a
Integrated Router uses Local Addr for the peer as its
Remote Addr. If a peer Local Addr range conflicts
with other connections, the BCM50a Integrated
Router does not accept VPN connection requests
from this peer.

Advertisement

Table of Contents
loading

Table of Contents