ZyXEL NBG-460N User Guide - Page 270

Table 102, Table 101

Page 270 highlights

Chapter 21 Logs Table 101 IKE Logs (continued) LOG MESSAGE DESCRIPTION Rule [%d] phase 1 mismatch The listed rule's IKE phase 1 did not match between the router and the peer. Rule [%d] phase 2 mismatch The listed rule's IKE phase 2 did not match between the router and the peer. Rule [%d] Phase 2 key length mismatch The listed rule's IKE phase 2 key lengths (with the AES encryption algorithm) did not match between the router and the peer. Table 102 PKI Logs LOG MESSAGE Enrollment successful Enrollment failed Failed to resolve Enrollment successful Enrollment failed Failed to resolve Rcvd ca cert: Rcvd user cert: Rcvd CRL : Rcvd ARL : Failed to decode the received ca cert Failed to decode the received user cert DESCRIPTION The SCEP online certificate enrollment was successful. The Destination field records the certification authority server IP address and port. The SCEP online certificate enrollment failed. The Destination field records the certification authority server's IP address and port. The SCEP online certificate enrollment failed because the certification authority server's address cannot be resolved. The CMP online certificate enrollment was successful. The Destination field records the certification authority server's IP address and port. The CMP online certificate enrollment failed. The Destination field records the certification authority server's IP address and port. The CMP online certificate enrollment failed because the certification authority server's IP address cannot be resolved. The router received a certification authority certificate, with subject name as recorded, from the LDAP server whose IP address and port are recorded in the Source field. The router received a user certificate, with subject name as recorded, from the LDAP server whose IP address and port are recorded in the Source field. The router received a CRL (Certificate Revocation List), with size and issuer name as recorded, from the LDAP server whose IP address and port are recorded in the Source field. The router received an ARL (Authority Revocation List), with size and issuer name as recorded, from the LDAP server whose address and port are recorded in the Source field. The router received a corrupted certification authority certificate from the LDAP server whose address and port are recorded in the Source field. The router received a corrupted user certificate from the LDAP server whose address and port are recorded in the Source field. 270 NBG-460N User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370

Chapter 21 Logs
NBG-460N User’s Guide
270
Rule [%d] phase 1 mismatch
The listed rule’s IKE phase 1 did not match between
the router and the peer.
Rule [%d] phase 2 mismatch
The listed rule’s IKE phase 2 did not match between
the router and the peer.
Rule [%d] Phase 2 key length
mismatch
The listed rule’s IKE phase 2 key lengths (with the
AES encryption algorithm) did not match between the
router and the peer.
Table 102
PKI Logs
LOG MESSAGE
DESCRIPTION
Enrollment successful
The SCEP online certificate enrollment was successful. The
Destination field records the certification authority server IP
address and port.
Enrollment failed
The SCEP online certificate enrollment failed. The Destination
field records the certification authority server’s IP address
and port.
Failed to resolve
<SCEP CA server url>
The SCEP online certificate enrollment failed because the
certification authority server’s address cannot be resolved.
Enrollment successful
The CMP online certificate enrollment was successful. The
Destination field records the certification authority server’s IP
address and port.
Enrollment failed
The CMP online certificate enrollment failed. The Destination
field records the certification authority server’s IP address
and port.
Failed to resolve <CMP
CA server url>
The CMP online certificate enrollment failed because the
certification authority server’s IP address cannot be resolved.
Rcvd ca cert: <subject
name>
The router received a certification authority certificate, with
subject name as recorded, from the LDAP server whose IP
address and port are recorded in the Source field.
Rcvd user cert:
<subject name>
The router received a user certificate, with subject name as
recorded, from the LDAP server whose IP address and port
are recorded in the Source field.
Rcvd CRL <size>:
<issuer name>
The router received a CRL (Certificate Revocation List), with
size and issuer name as recorded, from the LDAP server
whose IP address and port are recorded in the Source field.
Rcvd ARL <size>:
<issuer name>
The router received an ARL (Authority Revocation List), with
size and issuer name as recorded, from the LDAP server
whose address and port are recorded in the Source field.
Failed to decode the
received ca cert
The router received a corrupted certification authority
certificate from the LDAP server whose address and port are
recorded in the Source field.
Failed to decode the
received user cert
The router received a corrupted user certificate from the
LDAP server whose address and port are recorded in the
Source field.
Table 101
IKE Logs (continued)
LOG MESSAGE
DESCRIPTION