ZyWALL 50 Internet Security Gateway

 

 

Table 25-1 Sample IKE Key Exchange Logs

 

 

 

 

 

 

LOG MESSAGE

DESCRIPTION

 

 

 

 

 

 

!! Local / remote IPs of incoming

If the security gateway is “0.0.0.0”, the ZyWALL will

 

 

request conflict with rule <#d>

use the peer’s “Local Addr” as its “Remote Addr”. If this

 

 

 

IP (range) conflicts with a previously configured rule

 

 

 

then the connection is not allowed.

 

 

 

 

 

 

!! Invalid IP <IP start>/<IP end>

The peer’s “Local IP Addr” range is invalid.

 

 

 

 

 

 

!! Remote IP <IP start> / <IP end>

If the security gateway is “0.0.0.0”, the ZyWALL will

 

 

conflicts

use the peer’s “Local Addr” as its “Remote Addr”. If a

 

 

 

peer’s “Local Addr” range conflicts with other

 

 

 

connections, then the ZyWALL will not accept VPN

 

 

 

connection requests from this peer.

 

 

!! Active connection allowed exceeded

The ZyWALL limits the number of simultaneous Phase

 

 

 

2 SA negotiations. The IKE key exchange process fails

 

 

 

if this limit is exceeded.

 

 

!! IKE Packet Retransmit

The ZyWALL did not receive a response from the peer

 

 

 

and so retransmits the last packet sent.

 

 

!! Failed to send IKE Packet

The ZyWALL cannot send IKE packets due to a

 

 

 

network error.

 

 

 

 

 

 

!! Too many errors! Deleting SA

The ZyWALL deletes an SA when too many errors

 

 

 

occur.

 

 

 

 

 

The following table shows sample log messages during packet transmission.

Table 25-2 Sample IPSec Logs During Packet Transmission

LOG MESSAGE

DESCRIPTION

 

 

!! WAN IP changed to <IP>

If the ZyWALL’s WAN IP changes, all configured “My IP Addr” are

 

changed to b “0.0.0.0”.. If this field is configured as 0.0.0.0, then

 

the ZyWALL will use the current ZyWALL WAN IP address (static

 

or dynamic) to set up the VPN tunnel.

!! Cannot find Phase 2 SA

The ZyWALL cannot find a phase 2 SA that corresponds with the

 

SPI of an inbound packet (from the peer); the packet is dropped.

 

 

!! Discard REPLAY packet

If the ZyWALL receives a packet with the wrong sequence number

 

it will discard it.

!! Inbound packet

The authentication configuration settings are incorrect. Please

authentication failed

check them.

 

 

IPSec Log

25-3