Toshiba E-Studio 2330c Troubleshooting Manual page 104

Multifunctional digital color systems
Hide thumbs Also See for E-Studio 2330c:
Table of Contents

Advertisement

7 CHECKING THE EQUIPMENT STATUS WITH TopAccess
TopAccess Message
Active Directory Domain - Clock Skew error due to difference in
Time between Server and MFP
Active Directory Domain - Kerberos Ticket has expired and cannot
be used for Authentication
Active Directory Domain - Verification of the Ticket has failed
Active Directory Domain-The Domain specified could not be found Please enter the correct domain name in network settings. If the
Information Failed User Authentication
SNTP Server - Connect Error has occurred
No IKE proposal chosen
IKE Certificate Authentication failed
IKE Pre-shared key Authentication failed
Invalid Certificate
Certificate Type unsupported
Invalid certificate authority
Certificate unavailable
No ISAKMP SA established
Invalid Signature
No IKEv2 proposal chosen
IKEv2 Certificate Authentication Failed
IKEv2 Secret key Authentication failed
Falling Back to IKEv1
ISAKMP SA unusable (deleted)
Crypto operation failed
Invalid key information
CA not trusted
102
Error Messages
Corrective Action
The clocks need to be synchronized. Please check whether SNTP
is configured correctly on the equipment.
Please confirm the validity period of the ticket set by the Kerberos
server. Please retry again after the fresh ticket is issued.
Please verify the user name and password and retry again. If the
problem persists please contact the administrator.
problem persists please contact the administrator for the correct
realm name for your server.
Check Domain Name/User Name/Password
The equipment could not connect to the SNTP Server. Check the
SNTP settings.
Check the IKEv1/IPsec proposal parameters
(like encryption/authentication algorithms, DH group,
authentication methods) in MFP and peer machine.
Check
1. CA and user certificate in both MFP and remote peer -
certificate timestamp and IPsec Certificate template should be
valid.
2. CRL DP server name is mapped in MFP's host table or DNS
entry.
3. Certificate against CRL.
Mismatch in IKEv1 Pre Shared Key. Check the PSK in MFP and
remote machine.
Check the CA and user certificate in MFP and peer machine.
Check the user certificate type. Supported type is ".pfx" file only.
Check the CA certificate in MFP and peer machine.
Certificate has been deleted from Certificate store. Re-upload the
corresponding certificates using Security Services.
Check the IKEv1/IPsec proposal parameters
(like encryption/authentication algorithms, DH group,
authentication methods) in MFP and peer machine.
Check
1. CA and user certificate in both MFP and remote peer -
certificate timestamp and IPsec Certificate template should be
valid.
2. CRL DP server name is mapped in MFP's host table or DNS
entry.
3. Certificate against CRL.
Mismatch in Signature payload (MAC or IV). Check the CA and
user certificate in MFP and peer machine.
Check the IKEv2/IPsec proposal parameters
(encryption/authentication algorithms, DH group, authentication
methods) in MFP and peer machine.
Check
1. CA and user certificate in both MFP and remote peer -
certificate timestamp and IPsec Certificate template should be
valid.
2. CRL DP server name is mapped in MFP's host table or DNS
entry.
3. Certificate against CRL.
Mismatch in IKEv2 Pre Shared Key. Check the PSK in MFP and
peer machine.
Remote machine is not supporting IKEv2. Going back to use
IKEv1.
Restart IPsec service on Peer and retry.
If Certificates are being used, re-upload the corresponding
certificates using Security Services. Restart IPsec Service on
MFP.
Check IKE settings in MFP and peer.
Check the CA certificate in MFP and peer machine.
Check the CA certificate timestamp.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents