Appendix A Log Descriptions

Table 288 Application Patrol (continued)

MESSAGE

EXPLANATION

System fatal error:

The device failed to get the application patrol protocol list.

60011002.

 

System fatal error:

The device failed to initiate XML.

60011003.

 

System fatal error:

The device failed to turn application patrol off while the system was

60011004.

initiating.

Table 289 IKE Logs

LOG MESSAGE

DESCRIPTION

Peer has not announced

The remote IPSec router has not announced its dead peer detection

DPD capability

(DPD) capability to this device.

[COOKIE] Invalid

Cannot find SA according to the cookie.

cookie, no sa found

 

[DPD] No response from

The device’s DPD feature has not detected a response from the

peer. Using existing

remote IPSec router. %u is the retry time.

Phase-1 SA in %u

 

seconds. Trying with

 

Phase-1 rekey.

 

[HASH] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the exchange hash

Phase 1 hash mismatch

did not match.

[HASH] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the calculated quick

Phase 2 hash mismatch"

mode authentication hash did not match.

[ID] : Invalid ID

ID payload is not valid (in Phase-1 is local/peer ID, in Phase-2 is local/

information

remote policy).

[ID] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the local tunnel IP

Local IP mismatch

did not match the My IP in VPN gateway.

[ID] : Tunnel [%s] My

%s is the tunnel name. When negotiating Phase-1 and selecting

IP mismatch

matched proposal, My IP Address could not be resolved.

[ID] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the peer ID did not

Phase 1 ID mismatch

match.

[ID] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2 and checking IPsec

Phase 2 Local ID

SAs or the ID is IPv6 ID.

mismatch

 

[ID] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2 and checking IPsec

Phase 2 Remote ID

SAs or the ID is IPv6 ID.

mismatch

 

[ID] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the peer tunnel IP

Remote IP mismatch

did not match the secure gateway address in VPN gateway.

[SA] : Malformed IPSec

When selecting a matched proposal, some protocol was given more

SA proposal

than once.

[SA] : No proposal

When selecting a matched proposal in phase-1 or phase-2, so

chosen

proposal was selected.

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the authentication

Phase 1 authentication

algorithm did not match.

algorithm mismatch

 

782

 

ZyWALL USG 100/200 Series User’s Guide