322
Appendix J Log descriptions
NN47923-501
Table 85
Sample IKE key exchange logs
Log Message
Description
Send <Symbol> Mode request to
<IP>Send <Symbol> Mode
request to <IP>
The Business Secure Router has started negotiation
with the peer.
Recv <Symbol> Mode request
from <IP>Recv <Symbol> Mode
request from <IP>
The Business Secure Router has received an IKE
negotiation request from the peer.
Recv:<Symbol>
IKE uses the ISAKMP protocol (refer to RFC2408 –
ISAKMP) to transmit data. Each ISAKMP packet
contains payloads of different types that show in the
log (see
Table 87
).
Phase 1 IKE SA process done
Phase 1 negotiation is finished.
Start Phase 2: Quick Mode
Phase 2 negotiation is beginning using Quick Mode.
!! IKE Negotiation is in
process
The Business Secure Router has begun negotiation
with the peer for the connection already, but the IKE
key exchange is not finished yet.
!! Duplicate requests with
the same cookie
The Business Secure Router has received multiple
requests from the same peer but it is still processing
the first IKE packet from that peer.
!! No proposal chosen
The parameters configured for Phase 1 or Phase 2
negotiations do not match. Check all protocols and
settings for these phases. For example, one party is
using 3DES encryption, but the other party is using
DES encryption, so the connection fails.
!! Verifying Local ID
failed!! Verifying Remote ID
failed
During IKE Phase 2 negotiation, both parties
exchange policy details, including local and remote
IP address ranges. If these ranges differ, the
connection fails.
!! Local / remote IPs of
incoming request conflict
with rule <#d>
If the security gateway is 0.0.0.0, the Business
Secure Router uses the peer Local Addr as its
Remote Addr. If this IP (range) conflicts with a
previously configured rule then the connection is not
allowed.
!! Invalid IP <IP start>/<IP
end>
The Local IP Addr range for the peer is invalid.
!! Remote IP <IP start> / <IP
end> conflicts
If the security gateway is 0.0.0.0, the Business
Secure Router uses Local Addr for the peer as its
Remote Addr. If a peer Local Addr range conflicts
with other connections, the Business Secure Router
does not accept VPN connection requests from this
peer.
Summary of Contents for 252
Page 14: ...14 Contents NN47923 501 ...
Page 20: ...20 Figures NN47923 501 ...
Page 24: ...24 Tables NN47923 501 ...
Page 30: ...30 Preface NN47923 501 ...
Page 42: ...42 Chapter 1 Getting to know your Nortel Business Secure Router 252 NN47923 501 ...
Page 48: ...48 Chapter 2 Introducing the SMT NN47923 501 SMT menus at a glance Figure 6 SMT overview ...
Page 72: ...72 Chapter 3 WAN and Dial Backup Setup NN47923 501 ...
Page 80: ...80 Chapter 4 LAN setup NN47923 501 ...
Page 84: ...84 Chapter 5 Internet access NN47923 501 ...
Page 98: ...98 Chapter 6 Remote Node setup NN47923 501 ...
Page 102: ...102 Chapter 7 IP Static Route Setup NN47923 501 ...
Page 130: ...130 Chapter 9 Network Address Translation NAT NN47923 501 ...
Page 156: ...156 Chapter 12 SNMP Configuration NN47923 501 ...
Page 178: ...178 Chapter 14 System information and diagnosis NN47923 501 ...
Page 198: ...198 Chapter 15 Firmware and configuration file maintenance NN47923 501 ...
Page 212: ...212 Chapter 17 Remote Management NN47923 501 ...
Page 232: ...232 Appendix B Triangle Route NN47923 501 ...
Page 252: ...252 Appendix D PPPoE NN47923 501 ...
Page 256: ...256 Appendix E Hardware specifications NN47923 501 ...
Page 266: ...266 Appendix F IP subnetting NN47923 501 ...
Page 308: ...308 Appendix H NetBIOS filter commands NN47923 501 ...
Page 332: ...332 Appendix K Brute force password guessing protection NN47923 501 ...