D-Link DFL-1660 User Manual page 457

Network security firewall
Hide thumbs Also See for DFL-1660:
Table of Contents

Advertisement

9.4.5. Troubleshooting with ikesnoop
Payload data length : 8 bytes
Protocol ID
Notification : Initial contact
Explanation of Above Values
Flags: E means encryption (it is the only flag used).
ID: Identification of the client
The Notification field is given as Initial Contact to indicate this is not a re-key.
Step 6. Server ID Response
The server now responds with its own ID.
IkeSnoop: Sending IKE packet to 192.168.0.10:500 Exchange type :
Identity Protection (main mode) ISAKMP Version : 1.0
Flags
Cookies
Message ID
Packet length
# payloads
Payloads:
ID (Identification)
Payload data length : 8 bytes
ID : ipv4(any:0,[0..3]=192.168.10.20)
HASH (Hash)
Payload data length : 16 bytes
Step 7. Client Sends a List of Supported IPsec Algorithms
Now the client sends the list of supported IPsec algorithms to the server. It will also contain the
proposed host/networks that are allowed in the tunnel.
IkeSnoop: Received IKE packet from 192.168.0.10:500 Exchange type :
Quick mode ISAKMP Version : 1.0
Flags
Cookies
Message ID
Packet length
# payloads
Payloads:
HASH (Hash)
Payload data length : 16 bytes
SA (Security Association)
Payload data length : 164 bytes
DOI : 1 (IPsec DOI)
Proposal 1/1
Protocol 1/1
: ISAKMP
: E (encryption)
: 0x6098238b67d97ea6 -> 0x5e347cb76e95a
: 0x00000000
: 60 bytes
: 2
: E (encryption)
: 0x6098238b67d97ea6 -> 0x5e347cb76e95a
: 0xaa71428f
: 264 bytes
: 5
Protocol ID
SPI Size
SPI Value
Transform 1/4
Transform ID
Key length
Authentication algorithm : HMAC-MD5
: ESP
: 4
: 0x4c83cad2
: Rijndael (aes)
: 128
457
Chapter 9. VPN

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dfl-2560Dfl-2560gDfl-260eDfl-860e

Table of Contents