ZyWALL 10/10 II/50 Internet Security Gateway
28-4
IPSec
Log
Table 28-1 Sample IKE Key Exchange Logs
LOG MESSAGE
DESCRIPTION
!! IKE Packet Retransmit
The ZyWALL did not receive a response from the peer
and so retransmits the last packet sent.
!! Failed to send IKE Packet
The ZyWALL cannot send IKE packets due to a
network error.
!! Too many errors! Deleting SA
The ZyWALL deletes an SA when too many errors
occur.
The following table shows sample log messages during packet transmission.
Table 28-2 Sample IPSec Logs During Packet Transmission
LOG MESSAGE
DESCRIPTION
!! WAN IP changed to <IP>
If the ZyWALL’s WAN IP changes, all configured “My IP Addr” are
changed to b “0.0.0.0”.. If this field is configured as 0.0.0.0, then
the ZyWALL will use the current ZyWALL WAN IP address (static
or dynamic) to set up the VPN tunnel.
!! Cannot find Phase 2 SA
The ZyWALL cannot find a phase 2 SA that corresponds with the
SPI of an inbound packet (from the peer); the packet is dropped.
!! Discard REPLAY packet
If the ZyWALL receives a packet with the wrong sequence number
it will discard it.
!! Inbound packet
authentication failed
The authentication configuration settings are incorrect. Please
check them.
!! Inbound packet decryption
failed
The decryption configuration settings are incorrect. Please check
them.
Rule <#d> idle time out,
disconnect
If an SA has no packets transmitted for a period of time
(configurable via CI command), the ZyWALL drops the connection.
The following table shows RFC-2408 ISAKMP payload types that the log displays. Please refer to the RFC
for detailed information on each type.
Table 28-3 RFC-2408 ISAKMP Payload Types
LOG DISPLAY
PAYLOAD TYPE
SA
Security Association
PROP
Proposal
Summary of Contents for ZyWALL 10/10
Page 1: ...ZyWALL 10 10 II 50 Internet Security Gateway User s Guide Version 3 50 June 2002...
Page 32: ......
Page 36: ......
Page 42: ......
Page 58: ......
Page 78: ......
Page 80: ......
Page 92: ......
Page 96: ......
Page 122: ......
Page 140: ......
Page 166: ......
Page 186: ......
Page 206: ......
Page 212: ......
Page 226: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 260: ......
Page 290: ......
Page 294: ......
Page 300: ......
Page 302: ......
Page 308: ......
Page 314: ......
Page 316: ......
Page 318: ......
Page 322: ......
Page 334: ......
Page 342: ...ZyWALL 10 10 II 50 Internet Security Gateway JJ Index Introduction 10 2...