ZyWALL 10/10 II/50 Internet Security Gateway
IPSec Log
28-3
Table 28-1 Sample IKE Key Exchange Logs
LOG MESSAGE
DESCRIPTION
Send:<Symbol><Symbol>
Recv:<Symbol><Symbol>
IKE uses the ISAKMP protocol (refer to RFC2408 –
ISAKMP) to transmit data. Each ISAKMP packet
contains payloads of different types that show in the
log - see
Phase 1 IKE SA process done
Phase 1 negotiation is finished.
Start Phase 2: Quick Mode
Phase 2 negotiation is beginning using Quick Mode.
!! IKE Negotiation is in process
The ZyWALL has begun negotiation with the peer for
the connection already, but the IKE key exchange has
not finished yet.
!! Duplicate requests with the same
cookie
The ZyWALL has received multiple requests from the
same peer but it is still processing the first IKE packet
from that peer.
!! No proposal chosen
The parameters configured for Phase 1 or Phase 2
negotiations don’t match. Please check all protocols
and settings for these phases. For example, one party
may be using 3DES encryption, but the other party is
using DES encryption, so the connection will fail.
!! Verifying Local ID failed
!! Verifying Remote ID failed
During IKE Phase 2 negotiation, both parties exchange
policy details, including local and remote IP address
ranges. If these ranges differ, then the connection fails.
!! Local / remote IPs of incoming
request conflict with rule <#d>
If the security gateway is “0.0.0.0”, the ZyWALL will
use the peer’s “Local Addr” as its “Remote Addr”. If this
IP (range) conflicts with a previously configured rule
then the connection is not allowed.
!! Invalid IP <IP start>/<IP end>
The peer’s “Local IP Addr” range is invalid.
!! Remote IP <IP start> / <IP end>
conflicts
If the security gateway is “0.0.0.0”, the ZyWALL will
use the peer’s “Local Addr” as its “Remote Addr”. If a
peer’s “Local Addr” range conflicts with other
connections, then the ZyWALL will not accept VPN
connection requests from this peer.
!! Active connection allowed exceeded
The ZyWALL limits the number of simultaneous Phase
2 SA negotiations. The IKE key exchange process fails
if this limit is exceeded.
Summary of Contents for ZyWALL 10/10
Page 1: ...ZyWALL 10 10 II 50 Internet Security Gateway User s Guide Version 3 50 June 2002...
Page 32: ......
Page 36: ......
Page 42: ......
Page 58: ......
Page 78: ......
Page 80: ......
Page 92: ......
Page 96: ......
Page 122: ......
Page 140: ......
Page 166: ......
Page 186: ......
Page 206: ......
Page 212: ......
Page 226: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 260: ......
Page 290: ......
Page 294: ......
Page 300: ......
Page 302: ......
Page 308: ......
Page 314: ......
Page 316: ......
Page 318: ......
Page 322: ......
Page 334: ......
Page 342: ...ZyWALL 10 10 II 50 Internet Security Gateway JJ Index Introduction 10 2...