H3C MSR Series Troubleshooting Manual page 25

Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

//A matching IKE profile was found.
.........
*Nov
6 17:03:05:528 2014 ROUTER IKE/7/Event: Found pre-shared key in keychain 1
matching address 10.1.1.1.
//A matching keychain was found.
..........
*Nov
6 17:03:05:535 2014 ROUTER IKE/7/Event: IKE SA state changed from
IKE_P1_STATE_INIT to IKE_P1_STATE_SEND2.
*Nov 6 17:03:05:535 2014 ROUTER IKE/7/Packet: Sending packet to 10.1.1.1 remote port
500, local port 500.
//The device sent a packet to the peer (the second packet for negotiation).
...........
*Nov 6 17:03:05:739 2014 ROUTER IKE/7/Packet: Received packet from 10.1.1.1 source
port 500 destination port 500.
//The device received a packet from the peer (the third packet for negotiation).
..........
*Nov
6 17:03:05:741 2014 ROUTER IKE/7/Event: IKE SA state changed from
IKE_P1_STATE_SEND2 to IKE_P1_STATE_ESTABLISHED.
//Phase 1 negotiation finished.
*Nov
6 17:03:05:741 2014 ROUTER IKE/7/Event: Add tunnel, alloc new tunnel with ID
[1].
*Nov 6 17:03:05:983 2014 ROUTER IKE/7/Packet: Received packet from 10.1.1.1 source
port 500 destination port 500.
//The device received the first packet for phase 2 negotiation.
.............
*Nov
6 17:03:05:984 2014 ROUTER IKE/7/Event: IPsec SA state changed from
IKE_P2_STATE_INIT to IKE_P2_STATE_GETSP.
*Nov
6 17:03:05:985 2014 ROUTER IKE/7/Error: Failed to get IPsec policy for phase
2 responder. Delete IPsec SA.
*Nov
6 17:03:05:985 2014 ROUTER IKE/7/Error: Failed to negotiate IPsec SA.
//No matching IPsec policy was found. IPsec SA negotiation failed.
*Nov
6 17:03:05:985 2014 ROUTER IKE/7/Event: Delete IPsec SA.
*Nov
6 17:03:05:985 2014 ROUTER IKE/7/Packet: Encrypt the packet.
*Nov
6 17:03:05:985 2014 ROUTER IKE/7/Packet: Construct notification packet:
INVALID_ID_INFORMATION.
*Nov 6 17:03:05:985 2014 ROUTER IKE/7/Packet: Sending packet to 10.1.1.1 remote port
500, local port 500.
//The device notified the peer of the failure.
The previous debugging information shows that the IPsec SA negotiation failed because no
matching IPsec policy was found on the receiver. So we need to examine the IPsec policy
configuration.
23

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr 810Msr 2600Msr 3600Msr 5600

Table of Contents