Relevant Alarms and Logs
Relevant Alarms
None.
Relevant Logs
None.
12.2.3 IPSec Fails to Be Configured by Using an IPSec Policy
Template
Common Causes
This fault is commonly caused by one of the following:
l
The link is faulty.
l
Data flows are not forwarded from a specified interface.
l
Data flows do not match the ACL.
l
The settings of IPSec proposals at both ends of the IPSec tunnel are different.
l
IKE negotiation is not initiated by the remote device.
l
The settings of IPSec policies at both ends of the IPSec tunnel do not match. For example,
the PFS configurations are different.
l
The ACLs referenced by IPSec policies at both ends do not mirror each other.
l
The settings of IKE proposals at both ends of the IPSec tunnel are different.
l
The settings of IKE peers at both ends of the IPSec tunnel are different. For example, IKE
negotiation modes are different, IKE versions are incorrect, IP addresses of IKE peers do
not match, or names of IKE peers do not match.
Troubleshooting Flowchart
After IPSec is configured by using an IPSec policy template, IPSec cannot protect data.
shows the troubleshooting flowchart.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
12 VPN
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
358