Prestige 202H User’s Guide
28-4
IPSec
Log
The following table shows sample log messages during packet transmission.
Table 28-2 Sample IPSec Logs During Packet Transmission
LOG MESSAGE
DESCRIPTION
!! WAN IP changed to <IP>
If the Prestige’s WAN IP changes, all configured “My IP Addr” are
changed to b “0.0.0.0”.. If this field is configured as 0.0.0.0, then
the Prestige will use the current Prestige WAN IP address (static or
dynamic) to set up the VPN tunnel.
!! Cannot find Phase 2 SA
The Prestige cannot find a phase 2 SA that corresponds with the
SPI of an inbound packet (from the peer); the packet is dropped.
!! Discard REPLAY packet
If the Prestige receives a packet with the wrong sequence number
it will discard it.
!! Inbound packet authentication failed The authentication configuration settings are incorrect. Please
check them.
!! Inbound packet decryption failed
The decryption configuration settings are incorrect. Please check
them.
Rule <#d> idle time out, disconnect
If an SA has no packets transmitted for a period of time
(configurable via CI command), the Prestige drops the connection.
The following table shows RFC-2408 ISAKMP payload types that the log displays. Please refer to the RFC
for detailed information on each type.
Table 28-3 RFC-2408 ISAKMP Payload Types
LOG DISPLAY
PAYLOAD TYPE
SA Security
Association
PROP Proposal
TRANS Transform
KE Key
Exchange
ID Identification
CER Certificate
CER_REQ Certificate
Request
HASH Hash
SIG Signature
Содержание Prestige 202H Series
Страница 1: ...Prestige 202H ISDN Router User s Guide Version 3 40 August 2003...
Страница 28: ......
Страница 36: ......
Страница 40: ......
Страница 52: ......
Страница 88: ......
Страница 92: ......
Страница 144: ......
Страница 148: ......
Страница 160: ......
Страница 184: ......
Страница 206: ......
Страница 224: ......
Страница 242: ......
Страница 258: ......
Страница 296: ...Appendices and Index V Part V Appendices and Index This part provides appendices and an index of key terms...
Страница 297: ......