ZyXEL P-202U User Guide - Page 317

P-202H Plus v2 User's Guide, IPSec Log, Sample IPSec Logs During Packet Transmission,

Page 317 highlights

P-202H Plus v2 User's Guide Table 106 Sample IKE Key Exchange Logs LOG MESSAGE DESCRIPTION !! No proposal chosen The parameters configured for Phase 1 or Phase 2 negotiations don't match. Please check all protocols and settings for these phases. For example, one party may be using 3DES encryption, but the other party is using DES encryption, so the connection will fail. !! Verifying Local ID failed !! Verifying Remote ID failed During IKE Phase 2 negotiation, both parties exchange policy details, including local and remote IP address ranges. If these ranges differ, then the connection fails. !! Local / remote IPs of incoming request conflict with rule If the security gateway is "0.0.0.0", the ZyXEL Device will use the peer's "Local Addr" as its "Remote Addr". If this IP (range) conflicts with a previously configured rule then the connection is not allowed. !! Invalid IP / The peer's "Local IP Addr" range is invalid. !! Remote IP / conflicts If the security gateway is "0.0.0.0", the ZyXEL Device will use the peer's "Local Addr" as its "Remote Addr". If a peer's "Local Addr" range conflicts with other connections, then the ZyXEL Device will not accept VPN connection requests from this peer. !! Active connection allowed exceeded The ZyXEL Device limits the number of simultaneous Phase 2 SA negotiations. The IKE key exchange process fails if this limit is exceeded. !! IKE Packet Retransmit The ZyXEL Device did not receive a response from the peer and so retransmits the last packet sent. !! Failed to send IKE Packet The ZyXEL Device cannot send IKE packets due to a network error. !! Too many errors! Deleting SA The ZyXEL Device deletes an SA when too many errors occur. The following table shows sample log messages during packet transmission. Table 107 Sample IPSec Logs During Packet Transmission LOG MESSAGE !! WAN IP changed to !! Cannot find Phase 2 SA !! Discard REPLAY packet !! Inbound packet authentication failed !! Inbound packet decryption failed Rule idle time out, disconnect DESCRIPTION If the ZyXEL Device's WAN IP changes, all configured "My IP Addr" are changed to b "0.0.0.0".. If this field is configured as 0.0.0.0, then the ZyXEL Device will use the current ZyXEL Device WAN IP address (static or dynamic) to set up the VPN tunnel. The ZyXEL Device cannot find a phase 2 SA that corresponds with the SPI of an inbound packet (from the peer); the packet is dropped. If the ZyXEL Device receives a packet with the wrong sequence number it will discard it. The authentication configuration settings are incorrect. Please check them. The decryption configuration settings are incorrect. Please check them. If an SA has no packets transmitted for a period of time (configurable via CI command), the ZyXEL Device drops the connection. Chapter 35 IPSec Log 316

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375

P-202H Plus v2 User’s Guide
Chapter 35 IPSec Log
316
The following table shows sample log messages during packet transmission.
!! No proposal chosen
The parameters configured for Phase 1 or Phase 2
negotiations don't match. Please check all protocols and
settings for these phases. For example, one party may be
using 3DES encryption, but the other party is using DES
encryption, so the connection will fail.
!! Verifying Local ID failed
!! Verifying Remote ID failed
During IKE Phase 2 negotiation, both parties exchange
policy details, including local and remote IP address
ranges. If these ranges differ, then the connection fails.
!! Local / remote IPs of incoming request
conflict with rule <#d>
If the security gateway is
"0.0.0.0", the ZyXEL Device will
use the peer's "Local Addr" as its "Remote Addr". If this IP
(range) conflicts with a previously configured rule then the
connection is not allowed.
!! Invalid IP <IP start>/<IP end>
The peer's "Local IP Addr" range is invalid.
!! Remote IP <IP start> / <IP end>
conflicts
If the security gateway is
"0.0.0.0", the ZyXEL Device will
use the peer's "Local Addr" as its "Remote Addr". If a
peer's "Local Addr" range conflicts with other connections,
then the ZyXEL Device will not accept VPN connection
requests from this peer.
!! Active connection allowed exceeded
The ZyXEL Device limits the number of simultaneous
Phase 2 SA negotiations. The IKE key exchange process
fails if this limit is exceeded.
!! IKE Packet Retransmit
The ZyXEL Device did not receive a response from the
peer and so retransmits the last packet sent.
!! Failed to send IKE Packet
The ZyXEL Device cannot send IKE packets due to a
network error.
!! Too many errors! Deleting SA
The ZyXEL Device deletes an SA when too many errors
occur.
Table 107
Sample IPSec Logs During Packet Transmission
LOG MESSAGE
DESCRIPTION
!! WAN IP changed to <IP>
If the ZyXEL Device's WAN IP changes, all configured "My
IP Addr" are changed to b "0.0.0.0".. If this field is
configured as 0.0.0.0, then the ZyXEL Device will use the
current ZyXEL Device WAN IP address (static or dynamic)
to set up the VPN tunnel.
!! Cannot find Phase 2 SA
The ZyXEL Device cannot find a phase 2 SA that
corresponds with the SPI of an inbound packet (from the
peer); the packet is dropped.
!! Discard REPLAY packet
If the ZyXEL Device receives a packet with the wrong
sequence number it will discard it.
!! Inbound packet authentication failed
The authentication configuration settings are incorrect.
Please check them.
!! Inbound packet decryption failed
The decryption configuration settings are incorrect.
Please check them.
Rule <#d> idle time out, disconnect
If an SA has no packets transmitted for a period of time
(configurable via CI command), the ZyXEL Device drops
the connection.
Table 106
Sample IKE Key Exchange Logs
LOG MESSAGE
DESCRIPTION