Chapter 7 VPN

Table 7–1: IPSec Status Details (Continued)

Column

Description

 

 

 

 

Status

The current status of the connection:

 

Phase 1: Idle — Phase 1 negotiation has not started, or it has started but the

 

connection subsequently timed out, or did not complete successfully

 

Phase 1: Negotiating — the X family device is in the process of authenticating

 

a Phase 1 of the IPSec VPN connection

 

Phase 1: Failed — the negotiation failed

 

Phase 1: Established — the X family device has successfully completed Phase

 

1 negotiation.

 

Phase 2: Idle — Phase 2 negotiation has not started, or it has started but the

 

connection subsequently timed out, or did not complete successfully

 

Phase 2: Negotiating — the X family device is in the process of establishing a

 

Phase 2 of the IPSec VPN connection.

 

Phase 2: Established — a remote device is successfully connected

 

Phase 2: Failed — the negotiation failed

 

Note If you have selected the Enable Verbose messages in the VPN Log

 

option in the IPSec Configuration, you can view more detailed information

 

on the status of the Phase 1 and Phase 2 negotiation in the VPN Log

 

(Events > Logs > VPN Log).

 

 

Function(s)

The functions available to manage the IPSec SA VPN connection:

 

• Renegotiate a Phase 1 or Phase 2 connection for the IPSec SA.

 

 

186 X Family LSM User’s Guide V 2.5.1