Table 25-1 Sample Ike Key Exchange Logs - ZyXEL Communications ZyXEL ZyWALL 50 User Manual

Internet security gateway
Hide thumbs Also See for ZyXEL ZyWALL 50:
Table of Contents

Advertisement

ZyWALL 50 Internet Security Gateway
This menu is useful for troubleshooting. A log index number, the date and time the log was created and a log
message are displayed.
Double exclamation marks (!!) denote an error or warning message.
The following table shows sample log messages during IKE key exchange.
LOG MESSAGE
Cannot find outbound SA for rule <#d>
Send Main Mode request to <IP>
Send Aggressive Mode request to <IP>
Recv Main Mode request from <IP>
Recv Aggressive Mode request from <IP>
Send:<Symbol><Symbol>
Recv:<Symbol><Symbol>
Phase 1 IKE SA process done
Start Phase 2: Quick Mode
!! IKE Negotiation is in process
!! Duplicate requests with the same
cookie
!! No proposal chosen
!! Verifying Local ID failed
!! Verifying Remote ID failed
25-2

Table 25-1 Sample IKE Key Exchange Logs

The packet matches the rule index number (#d), but
Phase 1 or Phase 2 negotiation for outbound (from the
VPN initiator) traffic is not finished yet.
The ZyWALL has started negotiation with the peer.
The ZyWALL has received an IKE negotiation request
from the peer.
IKE uses the ISAKMP protocol (refer to RFC2408 –
ISAKMP) to transmit data. Each ISAKMP packet
contains payloads of different types that show in the
log - see Table 25-3.
Phase 1 negotiation is finished.
Phase 2 negotiation is beginning using Quick Mode.
The ZyWALL has begun negotiation with the peer for
the connection already, but the IKE key exchange has
not finished yet.
The ZyWALL has received multiple requests from the
same peer but it is still processing the first IKE packet
from that peer.
The parameters configured for Phase 1 or Phase 2
negotiations don't match. Please check all protocols
and settings for these phases. For example, one party
may be using 3DES encryption, but the other party is
using DES encryption, so the connection will fail.
During IKE Phase 2 negotiation, both parties exchange
policy details, including local and remote IP address
ranges. If these ranges differ, then the connection fails.
DESCRIPTION
IPSec Log

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zw50

Table of Contents