Prestige 652 ADSL Security Router

The following table shows sample log messages during packet transmission.

Table 27-2 Sample IPSec Logs During Packet Transmission

LOG MESSAGE

DESCRIPTION

!! WAN IP changed to <IP>

If the Prestige’s WAN IP changes, all configured “My IP Addr” are

 

changed to b “0.0.0.0”.. If this field is configured as 0.0.0.0, then

 

the Prestige will use the current Prestige WAN IP address (static or

 

dynamic) to set up the VPN tunnel.

!! Cannot find Phase 2 SA

The Prestige cannot find a phase 2 SA that corresponds with the

 

SPI of an inbound packet (from the peer); the packet is dropped.

!! Discard REPLAY packet

If the Prestige receives a packet with the wrong sequence number

 

it will discard it.

!! Inbound packet

The authentication configuration settings are incorrect. Please

authentication failed

check them.

!! Inbound packet decryption

The decryption configuration settings are incorrect. Please check

failed

them.

Rule <#d> idle time out,

If an SA has no packets transmitted for a period of time

disconnect

(configurable via CI command), the Prestige drops the connection.

The following table shows RFC-2408 ISAKMP payload types that the log displays. Please refer to the RFC for detailed information on each type.

Table 27-3 RFC-2408 ISAKMP Payload Types

LOG DISPLAY

PAYLOAD TYPE

SA

Security Association

PROP

Proposal

TRANS

Transform

KE

Key Exchange

ID

Identification

CER

Certificate

CER_REQ

Certificate Request

HASH

Hash

SIG

Signature

27-4

IPSec Log