Table 201 Ipsec Logs - ZyXEL Communications VANTAGE REPORT - V3.0 User Manual

Table of Contents

Advertisement

Table 200 IKE Logs (continued)
LOG MESSAGE
Tunnel
[%s:%s:0x%x:0x%x:%s]
rekeyed successfully
Tunnel [%s:%s]
1 pre-shared key
mismatch
Tunnel [%s:%s]
Recving IKE request
Tunnel [%s:%s]
Sending IKE request
Tunnel [%s:0x%x] is
disconnected
Tunnel [%s] rekeyed
successfully

Table 201 IPSec Logs

LOG MESSAGE
Corrupt packet,
Inbound transform
operation fail
Encapsulated packet
too big with length
Get inbound transform
fail
Get outbound transform
fail
Inbound transform
operation fail
Outbound transform
operation fail
Packet too big with
Fragment Off
SPI:0x%x SEQ:0x%x
Execute transform step
fail, ret=%d
SPI:0x%x SEQ:0x%x No
rule found, Dropping
packet
SPI:0x%x SEQ:0x%x
Packet Anti-Replay
detected
Vantage Report User's Guide
DESCRIPTION
The variables represent the phase 1 name, tunnel name, old SPI, new
SPI and the xauth name (optional). The tunnel was rekeyed
successfully.
The variables represent the phase 1 name and tunnel name. When
Phase
negotiating phase-1, the pre-shared keys did not match.
The variables represent the phase 1 name and tunnel name. The
device received an IKE request.
The variables represent the phase 1 name and tunnel name. The
device sent an IKE request.
The variables represent the tunnel name and the SPI of a tunnel that
was disconnected.
%s is the tunnel name. The tunnel was rekeyed successfully.
DESCRIPTION
The device received corrupt IPsec packets and could not process
them.
An outgoing packet needed to be transformed but was longer than
65535.
When performing inbound processing for incoming IPSEC packets and
ICMPs related to them, the engine cannot obtain the transform context.
When outgoing packet need to be transformed, the engine cannot
obtain the transform context.
After encryption or hardware accelerated processing, HWAccel
dropped packet (resource shortage, corrupt packet, invalid MAC, and
so on).
After encryption or hardware accelerated processing, Hwaccel dropped
packet (e.g., resource overflow, corrupt packet, and so on).
An outgoing packet needed to be transformed, but the fragment flag
was off and the packet was too big.
The variables represent the SPI, sequence number and the error
number. When trying to perform transforming, the engine returned an
error.
The variables represent the SPI and the sequence number. The packet
did not match the tunnel policy and was dropped.
The variables represent the SPI and the sequence number. The device
received a packet again (that it had already received).
Appendix D ZyWALL 1050 Log Descriptions
391

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vantage report

Table of Contents