Table 286 Ike Logs - ZyXEL Communications ZyWALL USG 300 User Manual

Unified security gateway
Hide thumbs Also See for ZyWALL USG 300:
Table of Contents

Advertisement

Appendix A Log Descriptions
Table 285 Application Patrol (continued)
MESSAGE
System fatal error:
60011002.
System fatal error:
60011003.
System fatal error:
60011004.

Table 286 IKE Logs

LOG MESSAGE
Peer has not announced
DPD capability
[COOKIE] Invalid
cookie, no sa found
[DPD] No response from
peer. Using existing
Phase-1 SA in %u
seconds. Trying with
Phase-1 rekey.
[HASH] : Tunnel [%s]
Phase 1 hash mismatch
[HASH] : Tunnel [%s]
Phase 2 hash mismatch"
[ID] : Invalid ID
information
[ID] : Tunnel [%s]
Local IP mismatch
[ID] : Tunnel [%s] My
IP mismatch
[ID] : Tunnel [%s]
Phase 1 ID mismatch
[ID] : Tunnel [%s]
Phase 2 Local ID
mismatch
[ID] : Tunnel [%s]
Phase 2 Remote ID
mismatch
[ID] : Tunnel [%s]
Remote IP mismatch
[SA] : Malformed IPSec
SA proposal
[SA] : No proposal
chosen
[SA] : Tunnel [%s]
Phase 1 authentication
algorithm mismatch
770
EXPLANATION
The device failed to get the application patrol protocol list.
The device failed to initiate XML.
The device failed to turn application patrol off while the system was
initiating.
DESCRIPTION
The remote IPSec router has not announced its dead peer detection
(DPD) capability to this device.
Cannot find SA according to the cookie.
The device's DPD feature has not detected a response from the
remote IPSec router. %u is the retry time.
%s is the tunnel name. When negotiating Phase-1, the exchange hash
did not match.
%s is the tunnel name. When negotiating Phase-2, the calculated quick
mode authentication hash did not match.
ID payload is not valid (in Phase-1 is local/peer ID, in Phase-2 is local/
remote policy).
%s is the tunnel name. When negotiating Phase-1, the local tunnel IP
did not match the My IP in VPN gateway.
%s is the tunnel name. When negotiating Phase-1 and selecting
matched proposal, My IP Address could not be resolved.
%s is the tunnel name. When negotiating Phase-1, the peer ID did not
match.
%s is the tunnel name. When negotiating Phase-2 and checking IPsec
SAs or the ID is IPv6 ID.
%s is the tunnel name. When negotiating Phase-2 and checking IPsec
SAs or the ID is IPv6 ID.
%s is the tunnel name. When negotiating Phase-1, the peer tunnel IP
did not match the secure gateway address in VPN gateway.
When selecting a matched proposal, some protocol was given more
than once.
When selecting a matched proposal in phase-1 or phase-2, so
proposal was selected.
%s is the tunnel name. When negotiating Phase-1, the authentication
algorithm did not match.
ZyWALL USG 300 User's Guide

Advertisement

Table of Contents
loading

Table of Contents