Table 76 Sample Ipsec Logs During Packet Transmission; Table 77 Rfc-2408 Isakmp Payload Types - Nortel BCM50a Configuration Manual

Integrated router
Table of Contents

Advertisement

302 Appendix J Log descriptions
Table 76

Table 76 Sample IPSec logs during packet transmission

LOG MESSAGE
!! WAN IP changed to <IP>
!! Cannot find IPSec SA
!! Cannot find outbound SA for
rule <%d>
!! Discard REPLAY packet
!! Inbound packet authentication
failed
!! Inbound packet decryption
failed
Rule <#d> idle time out,
disconnect
Table 77
the RFC for detailed information on each type.

Table 77 RFC-2408 ISAKMP payload types

Log Display
SA
PROP
TRANS
KE
ID
N0115791
shows sample log messages during packet transmission.
shows RFC-2408 ISAKMP payload types that the log displays. Refer to
Payload Type
Security Association
Proposal
Transform
Key Exchange
Identification
DESCRIPTION
If the BCM50a Integrated Router's WAN IP
changes, all configured "My IP Addr" are
changed to "0.0.0.0". If this field is configured as
0.0.0.0, the BCM50a Integrated Router uses the
current BCM50a Integrated Router WAN IP
address (static or dynamic) to set up the VPN
tunnel.
The BCM50a Integrated Router cannot find a
phase 2 SA that corresponds with the SPI of an
inbound packet (from the peer); the packet is
dropped.
The packet matches the rule index number (#d),
but Phase 1 or Phase 2 negotiation for outbound
(from the VPN initiator) traffic is not finished yet.
If the BCM50a Integrated Router receives a
packet with the wrong sequence number it
discards it.
The authentication configuration settings are
incorrect. Check them.
The decryption configuration settings are
incorrect. Check them.
If an SA has no packets transmitted for a period
of time (configurable via CI command), the
BCM50a Integrated Router drops the
connection.

Advertisement

Table of Contents
loading

Table of Contents