NETGEAR SRX5308 Reference Manual page 335

Prosafe gigabit quad wan ssl vpn firewall
Hide thumbs Also See for SRX5308:
Table of Contents

Advertisement

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Table 99. System logs: IPSec VPN tunnel, SA lifetime (150 sec in phase 1;
300 sec in phase 2), VPN tunnel not reestablished
Message
2000 Jan 1 04:52:33 [SRX5308] [IKE] Using IPSec SA configuration:
192.168.11.0/24<->192.168.10.0/24_
2000 Jan 1 04:52:33 [SRX5308] [IKE] Configuration found for 20.0.0.1._
2000 Jan 1 04:52:59 [SRX5308] [IKE] Phase 1 negotiation failed due to time up for
20.0.0.1[500]. b73efd188399b7f2:0000000000000000_
2000 Jan 1 04:53:04 [SRX5308] [IKE] Phase 2 negotiation failed due to time up
waiting for phase 1. ESP 20.0.0.1->20.0.0.2 _
2000 Jan 1 04:53:05 [SRX5308] [IKE] Using IPSec SA configuration:
192.168.11.0/24<->192.168.10.0/24_
2000 Jan 1 04:53:05 [SRX5308] [IKE] Configuration found for 20.0.0.1._
2000 Jan 1 04:53:05 [SRX5308] [IKE] Initiating new phase 1 negotiation:
20.0.0.2[500]<=>20.0.0.1[500]_
2000 Jan 1 04:53:05 [SRX5308] [IKE] Beginning Identity Protection mode._
2000 Jan 1 04:53:05 [SRX5308] [IKE] Setting DPD Vendor ID_
2000 Jan 1 04:53:36 [SRX5308] [IKE] Phase 2 negotiation failed due to time up
waiting for phase 1. ESP 20.0.0.1->20.0.0.2 _
Explanation
Phase 1 and phase 2 negotiations failed because of a mismatch of the WAN IP
address in the IPSec VPN policy and the WAN IP address of the remote host
attempting to establish the IPSec VPN tunnel.
Recommended action
None
Table 100. System logs: IPSec VPN tunnel, Dead Peer Detection and keep-alive (default 30 sec)
Messages 1 through 4
2000 Jan 1 04:13:39 [SRX5308] [IKE] Received request for new phase 1
negotiation: 20.0.0.2[500]<=>20.0.0.1[500]_
2000 Jan 1 04:13:39 [SRX5308] [IKE] Beginning Identity Protection mode._
2000 Jan 1 04:13:39 [SRX5308] [IKE] Received Vendor ID: RFC XXXX_
2000 Jan 1 04:13:39 [SRX5308] [IKE] Received Vendor ID: DPD_
Message 5
2000 Jan 1 04:13:39 [SRX5308] [IKE] DPD is Enabled_
Message 6
2000 Jan 1 04:13:39 [SRX5308] [IKE] For 20.0.0.1[500], Selected NAT-T version:
RFC XXXX_
Message 7
2000 Jan 1 04:13:39 [SRX5308] [IKE] Setting DPD Vendor ID_
Explanation
Message 1–4: After receiving a request for phase 1 negotiation, a Dead Peer
Detection Vendor ID is received.
Message 5: DPD is enabled.
Message 7: The DPD vendor ID is set.
Recommended action
None
System Logs and Error Messages
335

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents