ZyXEL Communications ZyWALL 10/10 User Manual page 297

Internet security gateway
Table of Contents

Advertisement

LOG MESSAGE
Send:<Symbol><Symbol>
Recv:<Symbol><Symbol>
Phase 1 IKE SA process done
Start Phase 2: Quick Mode
!! IKE Negotiation is in process
!! Duplicate requests with the same
cookie
!! No proposal chosen
!! Verifying Local ID failed
!! Verifying Remote ID failed
!! Local / remote IPs of incoming
request conflict with rule <#d>
!! Invalid IP <IP start>/<IP end>
!! Remote IP <IP start> / <IP end>
conflicts
!! Active connection allowed exceeded
IPSec Log
Table 28-1 Sample IKE Key Exchange Logs
ZyWALL 10/10 II/50 Internet Security Gateway
DESCRIPTION
IKE uses the ISAKMP protocol (refer to RFC2408 –
ISAKMP) to transmit data. Each ISAKMP packet
contains payloads of different types that show in the
log - see Table 28-3.
Phase 1 negotiation is finished.
Phase 2 negotiation is beginning using Quick Mode.
The ZyWALL has begun negotiation with the peer for
the connection already, but the IKE key exchange has
not finished yet.
The ZyWALL has received multiple requests from the
same peer but it is still processing the first IKE packet
from that peer.
The parameters configured for Phase 1 or Phase 2
negotiations don't match. Please check all protocols
and settings for these phases. For example, one party
may be using 3DES encryption, but the other party is
using DES encryption, so the connection will fail.
During IKE Phase 2 negotiation, both parties exchange
policy details, including local and remote IP address
ranges. If these ranges differ, then the connection fails.
If the security gateway is "0.0.0.0", the ZyWALL will
use the peer's "Local Addr" as its "Remote Addr". If this
IP (range) conflicts with a previously configured rule
then the connection is not allowed.
The peer's "Local IP Addr" range is invalid.
If the security gateway is "0.0.0.0", the ZyWALL will
use the peer's "Local Addr" as its "Remote Addr". If a
peer's "Local Addr" range conflicts with other
connections, then the ZyWALL will not accept VPN
connection requests from this peer.
The ZyWALL limits the number of simultaneous Phase
2 SA negotiations. The IKE key exchange process fails
if this limit is exceeded.
28-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall ii/50Zywall 10/10 ii/50

Table of Contents