Virtual Private Networking
145
o
The tunnel has not been configured.
o
The Phase 1 proposals do not match.
o
The secrets do not match.
o
The RSA key signatures have been incorrectly configured.
o
The Distinguished Name of the remote party has not be configured correctly.
o
The Endpoint IDs do not match.
o
The remote IP address or DNS hostname has been incorrectly entered.
o
The certificates do not authenticate correctly against the CA certificate.
Solution:
Ensure that the tunnel settings for the SnapGear appliance and the remote
party are configured correctly. Also ensure that both have IPSec enabled and have
Internet IP addresses. Check that the CA has signed the certificates.
•
Symptom:
Tunnel is always Negotiating Phase 2
Possible Cause:
The Phase 2 proposals set for the SnapGear appliance and the
remote party do not match.
The local and remote subnets do not match.
Solution:
Ensure that the tunnel settings for the SnapGear appliance and the remote
party are configured correctly.
•
Symptom:
Large packets don't seem to get transmitted
Possible Cause:
The MTU of the IPSec interface is too large.
Solution:
Reduce the MTU of the IPSec interface.
•
Symptom:
Tunnel goes down after a while
Possible Cause:
The remote party has gone down.
The remote party has disabled IPSec.
The remote party has disabled the tunnel.
The tunnel on the SnapGear appliance has been configured not to rekey the tunnel.
The remote party is not rekeying correctly with the SnapGear
Содержание SnapGear
Страница 56: ...Dialin Setup 52 The following figure shows the user maintenance screen Figure 4 3...
Страница 178: ...174...