ZyWALL 10/50 Internet Security Gateway

Chapter 28

IPSec Log

This chapter interprets common IPSec log messages.

28.1 VPN Initiator IPSec Log

To view the IPSec and IKE connection log, type 3 in menu 27 and press [ENTER] to display the IPSec log as shown next. The following figure shows a typical log from the initiator of a VPN connection.

Index:

 

Date/Time:

Log:

------------------------------------------------------------

001

01

Jan 08:02:22

Send Main Mode request to <192.168.100.101>

002

01

Jan 08:02:22

Send:<SA>

003

01

Jan 08:02:22

Recv:<SA>

004

01

Jan 08:02:24

Send:<KE><NONCE>

005

01

Jan 08:02:24

Recv:<KE><NONCE>

006

01

Jan 08:02:26

Send:<ID><HASH>

007

01

Jan 08:02:26

Recv:<ID><HASH>

008

01

Jan 08:02:26

Phase 1 IKE SA process done

009

01

Jan 08:02:26

Start Phase 2: Quick Mode

010

01

Jan 08:02:26

Send:<HASH><SA><NONCE><ID><ID>

011

01

Jan 08:02:26

Recv:<HASH><SA><NONCE><ID><ID>

012

01

Jan 08:02:26

Send:<HASH>

Clear IPSec Log (y/n):

Figure 28-1 Example VPN Initiator IPSec Log

IPSec Log

28-1